Best Detection of 2026 Series: Quishing QR Phishing Credential Harvest

This rule detects potential 'Quishing' (QR code phishing) attempts by identifying email-based phishing detection or malicious URL indicators followed by a user clicking the URL and subsequently authenticating to a corporate system from a mobile device (Android or iOS) within a 30-minute window. This behavior often suggests an adversary successfully harvesting credentials via a QR code link and then using them to gain unauthorized access.