IC3-Impersonation Spoofed Portal Access (icc3.gov / ic3a.gov)

This rule detects network communication, email interaction, or identity logon events related to known spoofed IC3 (Internet Crime Complaint Center) domains used in business email compromise (BEC) campaigns. The detection covers multiple telemetry sources including email URL information, device network events, and identity logon logs to identify attempts to interact with fraudulent portals.