Sandboxed iframe embedded in blob-rendered phishing page
This rule detects browser activity where a page rendered via a data blob loads a sandboxed iframe containing cross-origin content originating from cdn.bloom.io. This pattern is consistent with known phishing delivery mechanisms often used in DocuSign or Teams-themed phishing campaigns to facilitate credential theft or secondary payloads.
Microsoft Sentinel (KQL)

