feat(ttp): E.3.8 R0041-R0048 email cohort
8 YAMLs for the email cohort per Appendix B: open-relay abuse, mass phishing, phishing-kit X-Mailer signatures, IDN/punycode URLs, sender masquerade, malicious attachment, BEC, encoded payload in body. EmailLifter (E.3.12) consumes by rule_id. test_email_rules.py: YAML-present + inert-in-v0 + xfail(strict) precision case gated on E.3.12.
This commit is contained in:
23
rules/ttp/R0044.yaml
Normal file
23
rules/ttp/R0044.yaml
Normal file
@@ -0,0 +1,23 @@
|
||||
rule_id: R0044
|
||||
rule_version: 1
|
||||
name: idn_homoglyph_url
|
||||
description: |
|
||||
IDN / Punycode (xn--) URL in email body. Two emits: masquerade
|
||||
(T1036.005) and credential-harvest landing-page (T1566.002).
|
||||
applies_to:
|
||||
- email
|
||||
match:
|
||||
kind: lifter:email_idn_url
|
||||
punycode_prefix: 'xn--'
|
||||
emits:
|
||||
- tactic: TA0005
|
||||
technique_id: T1036
|
||||
sub_technique_id: T1036.005
|
||||
confidence: 0.9
|
||||
- tactic: TA0001
|
||||
technique_id: T1566
|
||||
sub_technique_id: T1566.002
|
||||
confidence: 0.9
|
||||
evidence_fields:
|
||||
- matched_url
|
||||
- decoded_idn
|
||||
Reference in New Issue
Block a user