Phishing Series 2026: Punycode & Homoglyph Lookalike Domain Impersonation
Detects inbound emails where the sender domain or embedded URLs use Punycode (xn--) or homoglyph-based lookalikes of trusted brand domains (e.g., Microsoft, Google, DocuSign). The rule further prioritizes alerts where the email subject contains urgency-based social engineering language typically used in credential harvesting campaigns.
Microsoft Sentinel (KQL)

