Message Headers
headers (collection)
#Description
Message Data Model attribute: headers
Fields #
| Name | Description |
|---|---|
| domains | All domains found in the Received headers |
| hops | List of hops the message took from Sender to Recipient |
| in_reply_to | In-Reply-To header value which identifies its parent message if exists |
| ips | All IP addresses found in the Received headers |
| mailer | X-Mailer or User-Agent extracted from headers |
| message_id | Message-ID extracted from the header |
| references | The Message-IDs of the other messages within this chain |
| references[] | The Message-IDs of the other messages within this chain |
| reply_to | Where replies should be delivered to |
Example Message Record #
{
"headers": {
"date": "2021-02-03T12:09:40Z",
"date_original_offset": "-5",
"domains": [
{
"domain": "vps.server.com",
"root_domain": "server.com",
"sld": "server",
"subdomain": "vps",
"tld": "com",
"valid": true
},
{
"domain": "tyrellcorp.io",
"root_domain": "tyrellcorp.io",
"sld": "tyrellcorp",
"tld": "io",
"valid": true
},
{
"domain": "esa2.hc2528-13.iphmx.com",
"root_domain": "iphmx.com",
"sld": "iphmx",
"subdomain": "esa2.hc2528-13",
"tld": "com",
"valid": true
},
{
"domain": "bn8nam11ft049.mail.protection.outlook.com",
"root_domain": "outlook.com",
"sld": "outlook",
"subdomain": "bn8nam11ft049.mail.protection",
"tld": "com",
"valid": true
},
{
"domain": "bn8nam11ft049.eop-nam11.prod.protection.outlook.com",
"root_domain": "outlook.com",
"sld": "outlook",
"subdomain": "bn8nam11ft049.eop-nam11.prod.protection",
"tld": "com",
"valid": true
},
{
"domain": "bn9pr03ca0612.outlook.office365.com",
"root_domain": "office365.com",
"sld": "office365",
"subdomain": "bn9pr03ca0612.outlook",
"tld": "com",
"valid": true
},
{
"domain": "bn9pr03ca0612.namprd03.prod.outlook.com",
"root_domain": "outlook.com",
"sld": "outlook",
"subdomain": "bn9pr03ca0612.namprd03.prod",
"tld": "com",
"valid": true
},
{
"domain": "byapr08mb5527.namprd08.prod.outlook.com",
"root_domain": "outlook.com",
"sld": "outlook",
"subdomain": "byapr08mb5527.namprd08.prod",
"tld": "com",
"valid": true
},
{
"domain": "mn2pr08mb6239.namprd08.prod.outlook.com",
"root_domain": "outlook.com",
"sld": "outlook",
"subdomain": "mn2pr08mb6239.namprd08.prod",
"tld": "com",
"valid": true
}
],
"hops": [
{
"fields": [
{
"name": "Mime-Version",
"position": 0,
"value": "1.0"
},
{
"name": "X-Microsoft-Antispam-Zap-Message-Info",
"position": 1,
"value": "rgqHu3DAQR/FhPR57j7aP9aOEcW2Q269mMMv61bqeZz57oV0wu+9jx4Tx0vnwSBMWYh7sJs3CTWMtlZfUrrOyiRlVpyzwJnqXMuE3SW29PvM7lMZAJsuh0jQPz0Y0lc8YW3yCIHyFwtgdwx0lFwppQrj+m9MMFhD7tt0im9FP1kAP6EEpyoPEBWEy1D7fMoF5GDjNsIyfoacYPy+lRcrFgsLq0aq6P94BTxGkyvQkmdKbt61oQ/gbcN+/xcyJrpjfbjs0wt949ZRMiDT6OkzTQpJQMzH3zDggeMHhoNjfbT7Hu2ljcBf18tO4++9e7CnfuvQ8Cqv4asBdDmSZ9o0xzq2ara+4Z57pHRcoIMZ1ldVxCXEXg2XAjXcRBa+h1/OkNDI9Xr7qi0vNbnJhuwXDkHe6BQCYaw5WYvzpHKm7nAZL/RNDDcZ2di0JdE0i0XIf4VJOh86SKhpgIeyL3ZgqneFEtbEuJ/O83nI+CYffsZqTbvEC+45iyutLfQhF5g462YO62KtBaGHwre8PLYnURJLAxumd9W5qHBIrdmqilwAQyKgN6/9XRjVK8kn2t1sTqudKY1XEEMAdRBLvC69PeL1pVwHqpfqsSo8Fyrak8wW0howAVfKAH9Idk0Y52qUMJ6CVkRQzAiemHYVpuF55cV9JwAfSJQ6ukI98vM/RRY=\r\n4RGh1MUSTt4/VZKbV+8mZrwld+j/yXqjsJGb7/4jebdYSxBMvnHMBHJtnlTbS1VxUSH0/HjHa31jRUrr+P+08JUPFGn9tnR8uWFfO0tGCbsAp5pRevMOghW5eND3wXBXRm68AHiILtXpkCthooN7Y/uh/qSxCjfFku8xBbeORYuDB0kUgC44JpwUth9+YoFEKpCToA79lFU4GEQjke12QD7CxCMy/kTbEvNbHgRM1Co3H2sBJw9TN8AOWabVAdTSdVNSt5w7txbd8atn27/xasxM3MHRWAukiWIzDHlv+PQGHxGsdsIWZj4Zmi0C5hdS1HAQElNQxUotTkiXc/ZNO2mZT0nndD/7SnZsaSVo2rKO4B5iHbOPhqTaWXOIjuBU6gZ/OYEdrpZOolrQweigsn2agKFpbIUc40udZR8kOLPFH4vbXZsq6rSq5+K8SqNaHCDrjrjH5TpdxPk0FigregCbwLm2pd1aueo9wGwjXlMTWr1SBTF/VWkbjKOvrr4woyUaPN70uHsuPDbkXrqSfFNHIyIG5AFHd/jSHR2EJuGMrHFb2nz9TWsGhY6v9xw+xWRT4gv4pKFWdOvsnUw/x6Nqqp1TOdNoUa4iW/9jA1Hmoz0TnYQC5ujFPdFve0WUWgjj1zP3RMl1p37K3y0bYYO+O2gGaBZatQ6T8zeJYP0="
},
{
"name": "X-Microsoft-Antispam-Message-Info",
"position": 2,
"value": "K2qYuKhxn5vGRN4OLmOczcXpgGq1VtWpGA6uJG9J1k9hW0ceF01E08fkv57N2fwNiHtzjsuyk0mVMzClnNxrXg2t06ta9TXJ+LUb9wGmlKOYuw9TEi3ji/otLwNSVarW9mCGbYWAyY5HIvAcNNwVJblnubgbIoZwP6iXRwY4v2QBNHvKsj9k7FeGBqkgJFuU1qEqJbT0u4IkAuOyzUMBQ0nqUX5Y8rdfbcOY0q9lLSGfDJK376LRDoD5GdMLEe8y6nunLpPD8BX1LxYjBnpXkqCwph8X+0MQd9TcXLvL2X0jLJv2tMylM8ibSSboSYjR8irw04QX5IdCZg6OSH/Xavjv5vzzhMXeJ3e9U2yOmps0rs6NHW8RvUCDgb3pQeHH2JgIAQMXEqKE66TfSLkiT2ubUes7ykARPmKIcZzsYQVQKT2W+b1LBHljlBxxzEvl2vkQP/CuaIb+m1KOdPMgfilFIFDasGFY/c1WhT2lAyilqdebi4OGA/4A42efmxORRkBxPwGi822S+T1Ik6Yz6+Tf3zbS8nOZuMIO6ZXvA7PHIocg/0xiNhf6YjSQOH93TDqdFzH/VThnHy/X+zdjYjgWt+3gaq18slpVQ5V1LExZTlgCiSfD4UY8U5AAcBx82/9ryes1KeDrUZJ/E9VCUt/91bBBurgpSH2jjUE0ioejFz6Mn7wz8DkUM7YzL7ZIg0ew6uEpPAeQXYXvZ4O2eXSVjCy23C+UP5erTYZDJvVRKjZeMbLlNLSpTnroDrImtsRnJcslktPHZorSxRjFkbviyoPyu9T9yNE1WOGu+F/SQa84oOqG++rvwRgvFs1L24kgu/iEsSzl3Qfy7vweWODTnViWF9vHdh3zbb1/T5AnQ+RqFv1N57cDPby58UKjXkUVBH/fww9ljD9JZhk9ViQh0CS9aEkOSIluWDhbDjc8VmPs/Fio5wrwIn8I8oEu/r4PePCIg2TzumLmrkC6g/2Cfm6GQZbxGvnwxUw4jdwZLlzedoHtqrpxb8BsQUy7PYfN59sN8WyJ+SAHFe1qhFAlNGaSvglllpd0sCZHhDrKAe6L/AGd5y9s23fGN1A1H5f8KpqODd7P3m72ABi0CEoujASOT8LDzoCy0OF25vRJ4KpF4kSrbNGCADBOKojf52qGnFweDU+jewZDbhKT+DT/pk5sPtyWwjUbmJ/G+eT3FzBxxDC1OjeI+S5pbDkIdgCo37350M00OFgt5ffzPQ1dljKXwaRy2RkRNQvnFNOkrUaInmhewt3HG/D0b8JNQhpLN6vf/m88cVOzRpFra5so3llbhnqrPvbkZ+5tkeE95pxxIB5tjRCo4zloMNEt7FbbkC7yUZl54iz/ygva5QSHGRbMo8dLL8O12JBqLIG0Mq/YBJM47ePhitY+xxq81wb4B3lbaQHBq4vwbb6Ea+8Mirkqg1XPy0510b4HEsMeHoapRFO/SFilYwUKBqvrLGNi5AHvRuCpEbYwgJ5kgv+8Mkd77qq71l0mo1A5qvQMKNYpd2vNRUqnODIHgtMbxaDQSgE5xAuSQtuY0EA/Fgslequ34Nc7NJZerGIbQcu/Z74iMYSbYcB9nnSGGC4igT8fy3kej+ngo+lzx3bRvuHLzoJFrAeHfgJEwrTO8sPypVH2yAPCzZMl8vE5QmSQqYVNkA7q/x45dNoKmoqLkFArCEDtD0A0CgvBgXiBrihWy8Pkwm8QGA8s155qXt7RHhSQhNNjjHRJ9IKFNIUxuufX5wwJSoMcFBkTD8Q6GGrVHWDG0EmXQibxfyaNwPTYp414zJxEjabuP01Y2ePSfTqpBNezunyPy0cGeNhiH9W4RwBEr1kgmgVEEx5ItiQCdYv6zQSq8C0ENovTJQXEuUG+PR/X9mmkXnF2B5njy/rWE9BoIX1Zdqc1xTeiwE3nSm+EtWt5hbfW8eeBXR7REw=="
},
{
"name": "X-Microsoft-Antispam-Mailbox-Delivery",
"position": 3,
"value": "ucf:0;jmr:0;auth:0;dest:I;ENG:(750128)(520011016)(944506458)(944626604);"
},
{
"name": "X-Ms-Exchange-Processed-By-Bccfoldering",
"position": 4,
"value": "15.20.3805.025"
},
{
"name": "X-Ms-Exchange-Transport-Endtoendlatency",
"position": 5,
"value": "00:00:04.5082358"
},
{
"name": "X-Ms-Exchange-Transport-Crosstenantheadersstamped",
"position": 6,
"value": "BYAPR08MB5527"
},
{
"name": "X-Ms-Exchange-Crosstenant-Fromentityheader",
"position": 7,
"value": "Internet"
},
{
"name": "X-Ms-Exchange-Crosstenant-Authas",
"position": 8,
"value": "Anonymous"
},
{
"name": "X-Ms-Exchange-Crosstenant-Authsource",
"position": 9,
"value": "BN8NAM11FT049.eop-nam11.prod.protection.outlook.com"
},
{
"name": "X-Ms-Exchange-Crosstenant-Id",
"position": 10,
"value": "3063c015-52d3-4e0f-8074-4426a1cfd3cb"
},
{
"name": "X-Ms-Exchange-Crosstenant-Network-Message-Id",
"position": 11,
"value": "8d992cc4-63d2-4438-a152-08d8c83c9792"
},
{
"name": "X-Ms-Exchange-Crosstenant-Originalarrivaltime",
"position": 12,
"value": "03 Feb 2021 12:09:43.5789 (UTC)"
},
{
"name": "X-Forefront-Antispam-Report",
"position": 13,
"value": "CIP:216.71.148.252;CTRY:US;LANG:en;SCL:-1;SRV:;IPV:CAL;SFV:SKN;H:esa2.hc2528-13.iphmx.com;PTR:esa2.hc2528-13.iphmx.com;CAT:NONE;SFS:;DIR:INB;"
},
{
"name": "X-Microsoft-Antispam",
"position": 14,
"value": "BCL:0;"
},
{
"name": "X-Ms-Exchange-Organization-Scl",
"position": 15,
"value": "-1"
},
{
"name": "X-Ms-Oob-Tlc-Oobclassifiers",
"position": 16,
"value": "OLM:1850;"
},
{
"name": "X-Ms-Traffictypediagnostic",
"position": 17,
"value": "BYAPR08MB5527:"
},
{
"name": "X-Ms-Office365-Filtering-Correlation-Id",
"position": 18,
"value": "8d992cc4-63d2-4438-a152-08d8c83c9792"
},
{
"name": "X-Ms-Exchange-Organization-Authas",
"position": 19,
"value": "Anonymous"
},
{
"name": "X-Ms-Exchange-Organization-Authsource",
"position": 20,
"value": "BN8NAM11FT049.eop-nam11.prod.protection.outlook.com"
},
{
"name": "X-Ms-Publictraffictype",
"position": 21,
"value": "Email"
},
{
"name": "X-Ms-Exchange-Organization-Messagedirectionality",
"position": 22,
"value": "Incoming"
},
{
"name": "X-Eoptenantattributedmessage",
"position": 23,
"value": "3063c015-52d3-4e0f-8074-4426a1cfd3cb:0"
},
{
"name": "X-Eopattributedmessage",
"position": 24,
"value": "0"
},
{
"name": "X-Ms-Exchange-Organization-Network-Message-Id",
"position": 25,
"value": "8d992cc4-63d2-4438-a152-08d8c83c9792"
},
{
"name": "X-Ms-Exchange-Organization-Expirationintervalreason",
"position": 26,
"value": "OriginalSubmit"
},
{
"name": "X-Ms-Exchange-Organization-Expirationinterval",
"position": 27,
"value": "1:00:00:00.0000000"
},
{
"name": "X-Ms-Exchange-Organization-Expirationstarttimereason",
"position": 28,
"value": "OriginalSubmit"
},
{
"name": "X-Ms-Exchange-Organization-Expirationstarttime",
"position": 29,
"value": "03 Feb 2021 12:09:43.9487 (UTC)"
},
{
"name": "Return-Path",
"position": 30,
"value": "root@vps.server.com"
},
{
"name": "Content-Transfer-Encoding",
"position": 31,
"value": "base64"
},
{
"name": "Content-Type",
"position": 32,
"value": "text/html; charset=UTF-8"
},
{
"name": "From",
"position": 33,
"value": "\"HR tyrellcorp <noreply@tyrellcorp.io>\" <rachael@tyrellcorp.io>"
},
{
"name": "Subject",
"position": 34,
"value": "A file was shared with you tyrellcorp-Covid-19 Vaccination And Testing Report.pdf."
},
{
"name": "Replyto",
"position": 35,
"value": ""
},
{
"name": "To",
"position": 36,
"value": "rachael@tyrellcorp.io"
},
{
"name": "Date",
"position": 37,
"value": "Wed, 03 Feb 2021 07:09:40 -0500"
},
{
"name": "Message-Id",
"position": 38,
"value": "<202102031209.113C9eDc031722@vps.server.com>"
}
],
"index": 0
},
{
"fields": [
{
"name": "Received",
"position": 39,
"value": "(from root@localhost) by vps.server.com (8.14.7/8.14.7/Submit) id 113C9eDc031722; Wed, 3 Feb 2021 07:09:40 -0500"
}
],
"index": 1
},
{
"fields": [
{
"name": "Received",
"position": 40,
"value": "from vps.server.com (localhost [127.0.0.1]) by vps.server.com (8.14.7/8.14.7) with ESMTP id 113C9e2c031727 for <rachael@tyrellcorp.io>; Wed, 3 Feb 2021 07:09:40 -0500"
}
],
"index": 2
},
{
"fields": [
{
"name": "Received",
"position": 41,
"value": "from unknown (HELO vps.server.com) ([185.243.112.105]) by esa2.hc2528-13.iphmx.com with ESMTP/TLS/ECDHE-RSA-AES128-GCM-SHA256; 03 Feb 2021 07:09:42 -0500"
},
{
"name": "X-Amp-File-Uploaded",
"position": 42,
"value": "False"
},
{
"name": "X-Amp-Result",
"position": 43,
"value": "SKIPPED(no attachment in message)"
},
{
"name": "X-Ironport-Av",
"position": 44,
"value": "E=Sophos;i=\"5.79,398,1602561600\"; d=\"scan'208,217\";a=\"1650488\""
},
{
"name": "X-Ironport-Anti-Spam-Filtered",
"position": 45,
"value": "true"
},
{
"name": "Ironport-Phdr",
"position": 46,
"value": "9a23:jU3PyR9CP0SRz/9uRHKM819IXTAuvvDOBiVQ1KB+0+0TIJqq85mqBkHD//Il1AaPAdyKra4ewLGM++C4ACpcuMnH6ChDOLV3FDY9wf0MmAIhBMPXQWbaF9XNKxIAIcJZSVV+9Gu6O0UGUOz3ZlnVv2HgpWVKQka3OgV6PPn6FZDPhMqrye+y54fTYwJVjzahfL9+Nhq7oRjVu8UMjoZuNKk9xxXXrnBVf+ha2X5kKUickhrh5Mq85oJv/zhVt/k868NOTKL2crgiQ7dFFjomKWc15MPqtRnHUwSC42YXX3sVnBRVHQXL9Qn2UZjtvCT0sOp9wzSaMtbtTb8oQzSi7rxkRwHuhSwaKjM26mDXish3jKJGvBKsogF0zoDIbI2JMvd1Y6TScM8USGZdQ8pdTjBNDp6hZIcLEuYMPeNUoo/6qFYTtxSxGAmiBPnoyj9Nn3P40qI33/k8HQ3f3AEsA88FvHDVodnpMasfV+e6wbfPzTrZdPNWxS3y6IzRfh4vrvyAQax8fdPNxUUxDg/LjFKQqZf5PziI0ugAvXSX4/ZlWe+plmUpqRx+oiK3y8gjhIfHmJ8bxFDY+it224s1Jca3RFJnbdK4DJddtSeXPJZ2TMM4RGFovT43xrMEt5CnYSMF1oonxxnaa/OdaYiI4QzsVPqKITxlg39lfrW/hwys/ki4zu39VtK530hUripCl9nDrGoN1x/N5cibUftx5Fuu2TGK1w3K5O1PPEc5mrTBJJ4737E9jYQcsVrEHi/zgkr2lqyWeVs4+uiz8ejofrLmppqFOoJylwrxPbgglNalDuQkLggBQXKb+eKk2bDg/UD0XbRHg+M2n6XErJzXO8AWq7KlDwJbzIsu9RSyAjm63dkagHUKMk5IdRCIgoXtNFzCPu70Aeuhj1ixnjlmwe3NMLPmApXINHfDkbHhcK5g5E5dxwozzMxf6IhQCrEGPP38RFX+tNrDDh8hKQO73/joCM5n2owCXmKPB6mUO77Rv1+Q/u8jPuqBaY8PtDrjJPUo6eTigWIklVMDZ6WlwIcbZXC+E/97OUuWe2Dsjc0EEWoSvgoxUujqiFqaXD5Nf3ayRLgw5iolB4K8E4fMWJqtjKad0ye8G51afmFGClaSHnf0b4iIRvQBZSKILsN/nTEJW6KtR5I82R2wrgP21qZrI+rM9i0dr53j1dx15+PJlRE18Dx5F96d02aKT2FohW4IWSc23LtlrUxm1FiDy7Z4jOJCFdBJ+/xJVQI6OYbGz+NmE9DyRh7BftCRRVm4WNqmGyw+Q8kvzN8QZEZ9Hs+tjgrA3yW0H78VjKaHC4Az8qLZjDDNIJNwwmzK/KQ/iFwvWMhCKXbgjal6pCbJAIuc2WWj36u0cqEVxi3A6HzLmWyJpkxAVB9YXLvCWHkFZUbKtpLy4UaUBff6BL09PiNM18mHI7FJZ8Hyy15BQaGwa5zlf2utljLpVl6zzbSWYd+xJDgQ"
},
{
"name": "X-Ipas-Result",
"position": 47,
"value": "A0lFXQDMkRpgl2lw87liGwEDAwEFARYBAwMBQgeBSAIBDA4IAX0BGgKBYXoSFxqEQIgmXoY7AYIXgxgBkT4BhQ1mE4EsPQoBAQEBAQEBAQEJJwgEAQECgy6BGhkHgWABJTwCDQIDAQEBAwQBAQEBAQEEAQEBAgEBBgECAQEBARABAQEBAQEBAXNtWYM+CgQxDT+CBQEEAQEBAQMDAwEBDAEOYk06AQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBBQInGzkcSxERUxoNAiYCBBQzJyKCbxUBgwoBCj6iJQGBKD4CIwFAAQyBCIkRAQEBdIEyGgKEJAGGGgWBCRMVAgEBhnodhiYmGz4BgUGBR4QKgRVfAwEGgRk5UoJMF4InCBoEgVWBHGSBBDJ3IgMUjBsBg3qMCnqJOpItBwOCeoEZJAGHeJJugy+BM4kThVQDiF+CAIFgglFEhj6XcoErlnKCBAqBWhUjOBWDJAlEAQIBAQENAQICAwECAQFfB417gzqKdiMDMAIBAQERHgMCBgoBAQMJjBUBAQ"
},
{
"name": "X-Ironport-Mailflowpolicy",
"position": 48,
"value": "$ACCEPTED"
},
{
"name": "X-Ironport-Sendergroup",
"position": 49,
"value": "UNKNOWNLIST"
},
{
"name": "X-Ironport-Listener",
"position": 50,
"value": "BidirectionalMail"
},
{
"name": "X-Ironport-Reputation",
"position": 51,
"value": "5.1"
},
{
"name": "X-Ironport-Mid",
"position": 52,
"value": "1650488"
},
{
"name": "X-Ironport-Remoteip",
"position": 53,
"value": "185.243.112.105"
},
{
"name": "Ironport-Sdr",
"position": 54,
"value": "cTti+076Q288FeDFpFsjC2m03kAZNiHNTZouC3doe3gr1hSLmWJJmSmAuO9FXL6rfcfsGqD3MS +IoDTZtzNOYqw08W3kHp5diTvmQ50ZX7VDHDMrVd1L9pimUfppiy1ZZOBzDEIRpI2p8JeXSf1Q p+rhTH7W4jonDFHdvVCoGNJDOEto26ccJKowjycrrxYlnPO4vjpUxGVujRNFmK36VJMCO8UbSf 3D1wJueE9dS6gXQ02YdaGYgBozgcG6B3YW43tRJQv+KWosz4nIclTtMpPQ4rvZLP7QlNeq/tF4 YNQwsYR33uHVxSiFiEa52et5"
}
],
"index": 3
},
{
"authentication_results": {
"compauth": {
"reason": "905",
"verdict": "none"
},
"dkim_details": [
{
"domain": "none",
"type": "dkim"
}
],
"dmarc": "none",
"dmarc_details": {
"action": "none",
"from": {
"domain": "tyrellcorp.io",
"root_domain": "tyrellcorp.io",
"sld": "tyrellcorp",
"tld": "io",
"valid": true
},
"verdict": "none",
"version": ""
},
"server": {
"domain": "tyrellcorp.io",
"root_domain": "tyrellcorp.io",
"sld": "tyrellcorp",
"tld": "io",
"valid": true
},
"spf": "none",
"spf_details": {
"client_ip": {
"ip": "216.71.148.252"
},
"description": "sender IP is 216.71.148.252",
"designator": "vps.server.com",
"verdict": "none"
},
"type": "standard"
},
"fields": [
{
"name": "Received",
"position": 55,
"value": "from esa2.hc2528-13.iphmx.com (216.71.148.252) by BN8NAM11FT049.mail.protection.outlook.com (10.13.177.157) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3784.12 via Frontend Transport; Wed, 3 Feb 2021 12:09:43 +0000"
},
{
"name": "Received-Spf",
"position": 56,
"value": "None (protection.outlook.com: vps.server.com does not designate permitted sender hosts)"
},
{
"name": "Authentication-Results",
"position": 57,
"value": "spf=none (sender IP is 216.71.148.252) smtp.mailfrom=vps.server.com; tyrellcorp.io; dkim=none (message not signed) header.d=none;tyrellcorp.io; dmarc=none action=none header.from=tyrellcorp.io;compauth=none reason=905"
}
],
"index": 4,
"received_spf": {
"client_ip": {
"ip": ""
},
"description": "protection.outlook.com: vps.server.com does not designate permitted sender hosts",
"designator": "vps.server.com",
"server": {
"domain": "protection.outlook.com",
"root_domain": "outlook.com",
"sld": "outlook",
"subdomain": "protection",
"tld": "com",
"valid": true
},
"verdict": "None"
}
},
{
"fields": [
{
"name": "Received",
"position": 58,
"value": "from BN8NAM11FT049.eop-nam11.prod.protection.outlook.com (2603:10b6:408:106:cafe::de) by BN9PR03CA0612.outlook.office365.com (2603:10b6:408:106::17) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3805.17 via Frontend Transport; Wed, 3 Feb 2021 12:09:44 +0000"
}
],
"index": 5
},
{
"fields": [
{
"name": "Received",
"position": 59,
"value": "from BN9PR03CA0612.namprd03.prod.outlook.com (2603:10b6:408:106::17) by BYAPR08MB5527.namprd08.prod.outlook.com (2603:10b6:a03:c4::12) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3805.24; Wed, 3 Feb 2021 12:09:45 +0000"
}
],
"index": 6
},
{
"fields": [
{
"name": "Received",
"position": 60,
"value": "from BYAPR08MB5527.namprd08.prod.outlook.com (2603:10b6:a03:c4::12) by MN2PR08MB6239.namprd08.prod.outlook.com with HTTPS; Wed, 3 Feb 2021 12:09:48 +0000"
}
],
"index": 7
}
],
"ips": [
{
"ip": "127.0.0.1"
},
{
"ip": "185.243.112.105"
},
{
"ip": "216.71.148.252"
},
{
"ip": "10.13.177.157"
}
],
"message_id": "<202102031209.113C9eDc031722@vps.server.com>",
"return_path": {
"domain": {
"domain": "vps.server.com",
"root_domain": "server.com",
"sld": "server",
"subdomain": "vps",
"tld": "com",
"valid": true
},
"email": "root@vps.server.com",
"local_part": "root"
}
}
}
Common Indicators #
Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
profile.by_sender | func_call | profile.by_sender().any_messages_malicious_or_spam | 58 rules | mql |
headers.references | length_compare | 0 | 46 rules | mql |
headers.in_reply_to | is_null | | 45 rules | mql |
body.links | length_compare | 0 | 36 rules | mql |
body.links | length_compare | 10 | 19 rules | mql |
headers.reply_to | length_compare | 0 | 32 rules | mql |
recipients.to | length_compare | 0 | 24 rules | mql |
recipients.to | length_compare | 1 | 24 rules | mql |
headers.auth_summary.dmarc.pass | eq | true | 18 rules | mql |
headers.auth_summary.spf.pass | eq | true | 18 rules | mql |
profile.by_sender_email | func_call | profile.by_sender_email().any_messages_malicious_or_spam | 14 rules | mql |
profile.by_sender_email | func_call | profile.by_sender_email().prevalence in (new, outlier) | 9 rules | mql |
recipients.cc | length_compare | 0 | 14 rules | mql |
body.previous_threads | length_compare | 0 | 12 rules | mql |
recipients.bcc | length_compare | 0 | 12 rules | mql |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sublime MQL #
References #
headers.auth_summary
#Description
Message Data Model attribute: headers.auth_summary
Fields #
| Name | Description |
|---|---|
| dmarc.details.from.domain | The fully qualified domain name (FQDN). This may not *always* be routable, e.g. when an email address contains a domain that is just a TLD with no SLD, e.g. foo@WIN-bar |
| dmarc.details.from.root_domain | The root domain, including the TLD |
| dmarc.pass | Whether the DMARC check passed |
| spf.details.designator | Email or domain of the designating body |
| spf.pass | Whether the SPF check passed |
Common Indicators #
Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
type.inbound | eq | true | 466 rules | mql |
profile.by_sender | func_call | profile.by_sender().any_messages_malicious_or_spam | 91 rules | mql |
profile.by_sender | func_call | profile.by_sender().prevalence in (new, outlier) | 24 rules | mql |
attachments | length_compare | 0 | 43 rules | mql |
body.links | length_compare | 0 | 41 rules | mql |
body.links | length_compare | 10 | 26 rules | mql |
headers.auth_summary.dmarc.pass | eq | true | 36 rules | mql |
headers.auth_summary.spf.pass | eq | true | 32 rules | mql |
headers.in_reply_to | is_null | | 29 rules | mql |
headers.references | length_compare | 0 | 29 rules | mql |
recipients.to | length_compare | 0 | 23 rules | mql |
profile.by_sender_email | func_call | profile.by_sender_email().any_messages_malicious_or_spam | 21 rules | mql |
headers.reply_to | length_compare | 0 | 16 rules | mql |
recipients.cc | length_compare | 0 | 14 rules | mql |
body.current_thread.text | contains | invoice | 13 rules | mql |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sublime MQL #
References #
headers.domains (collection)
#Description
Message Data Model attribute: headers.domains
Fields #
| Name | Description |
|---|---|
| domain | The fully qualified domain name (FQDN). This may not *always* be routable, e.g. when an email address contains a domain that is just a TLD with no SLD, e.g. foo@WIN-bar |
| root_domain | The root domain, including the TLD |
| tld | The domain's top-level domain. E.g. the TLD of google.com is 'com' |
Example Message Record #
{
"headers.domains": [
{
"domain": "vps.server.com",
"root_domain": "server.com",
"sld": "server",
"subdomain": "vps",
"tld": "com",
"valid": true
},
{
"domain": "tyrellcorp.io",
"root_domain": "tyrellcorp.io",
"sld": "tyrellcorp",
"tld": "io",
"valid": true
},
{
"domain": "esa2.hc2528-13.iphmx.com",
"root_domain": "iphmx.com",
"sld": "iphmx",
"subdomain": "esa2.hc2528-13",
"tld": "com",
"valid": true
},
{
"domain": "bn8nam11ft049.mail.protection.outlook.com",
"root_domain": "outlook.com",
"sld": "outlook",
"subdomain": "bn8nam11ft049.mail.protection",
"tld": "com",
"valid": true
},
{
"domain": "bn8nam11ft049.eop-nam11.prod.protection.outlook.com",
"root_domain": "outlook.com",
"sld": "outlook",
"subdomain": "bn8nam11ft049.eop-nam11.prod.protection",
"tld": "com",
"valid": true
},
{
"domain": "bn9pr03ca0612.outlook.office365.com",
"root_domain": "office365.com",
"sld": "office365",
"subdomain": "bn9pr03ca0612.outlook",
"tld": "com",
"valid": true
},
{
"domain": "bn9pr03ca0612.namprd03.prod.outlook.com",
"root_domain": "outlook.com",
"sld": "outlook",
"subdomain": "bn9pr03ca0612.namprd03.prod",
"tld": "com",
"valid": true
},
{
"domain": "byapr08mb5527.namprd08.prod.outlook.com",
"root_domain": "outlook.com",
"sld": "outlook",
"subdomain": "byapr08mb5527.namprd08.prod",
"tld": "com",
"valid": true
},
{
"domain": "mn2pr08mb6239.namprd08.prod.outlook.com",
"root_domain": "outlook.com",
"sld": "outlook",
"subdomain": "mn2pr08mb6239.namprd08.prod",
"tld": "com",
"valid": true
}
]
}
Common Indicators #
Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
beta.ocr(file.message_screenshot()).text | contains | review | 2 rules | mql |
beta.ocr(file.message_screenshot()).text | contains | view | 2 rules | mql |
body.current_thread.text | contains | blocked | 2 rules | mql |
body.current_thread.text | contains | notification | 2 rules | mql |
body.current_thread.text | contains | prevented | 2 rules | mql |
body.current_thread.text | contains | review | 2 rules | mql |
body.current_thread.text | contains | server error | 2 rules | mql |
body.current_thread.text | contains | unsubscribe | 2 rules | mql |
body.current_thread.text | contains | 2884 sand hill road | 1 rule | mql |
body.current_thread.text | length_compare | 250 | 2 rules | mql |
body.current_thread.text | length_compare | 700 | 2 rules | mql |
body.current_thread.text | regex_match | \+?([ilo0-9]{1,2})?\s?\(?\d{3}\)?[\s\.\-⋅]{0,5}[ilo0-9]{3}[\s\.\-⋅]{0,5}[ilo0-9]{4} | 2 rules | mql |
body.current_thread.text | regex_match | \+?([ilo0-9]{1}.)?\(?[ilo0-9]{3}?\)?.[ilo0-9]{3}.?[ilo0-9]{4} | 2 rules | mql |
filter(body.links, .href_url.scheme != 'mailto') | length_compare | 0 | 2 rules | mql |
sender.display_name | regex_match | [a-z0-9]+@[a-z]+ | 2 rules | mql |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sublime MQL #
References #
headers.hops (collection)
#Description
Message Data Model attribute: headers.hops
Fields #
| Name | Description |
|---|---|
| authentication_results.compauth.verdict | Verdict of the compauth |
| authentication_results.dkim | Verdict of the Domain Keys Identified Mail check |
| authentication_results.dkim_details | List of details of the Domain Keys Identified Mail checks |
| authentication_results.dkim_details[].domain | Domain identified in the DKIM signature if any. This is the domain that's queried for the public key. |
| authentication_results.dmarc | Verdict of the Domain-based Message Authentication, Reporting & Conformance check |
| authentication_results.dmarc_details.from.domain | The fully qualified domain name (FQDN). This may not *always* be routable, e.g. when an email address contains a domain that is just a TLD with no SLD, e.g. foo@WIN-bar |
| authentication_results.spf | Verdict of the Sender Policy Framework |
| authentication_results.spf_details.designator | Email or domain of the designating body |
| fields | List of all raw header fields contained within this hop |
| fields[].name | The name of the field |
| fields[].value | The value contained within the field |
| index | Index indicates the order in which a hop occurred from sender to recipient |
| received.server.raw | The raw string of 'by' section |
| received.source.raw | The raw string of 'from' section |
| received_spf.designator | Email or domain of the designating body |
| signature.headers | Header fields signed by the algorithm |
Example Message Record #
{
"headers.hops": [
{
"fields": [
{
"name": "Content-Type",
"position": 0,
"value": "multipart/alternative; boundary=\"00000000000041de5d05956fc8ff\""
},
{
"name": "To",
"position": 1,
"value": "ian@sublimesecurity.com"
},
{
"name": "Subject",
"position": 2,
"value": "Urgent: Need W2s"
},
{
"name": "Message-Id",
"position": 3,
"value": "<CAO_do4n4jwcfabQcEScYd9oSjDytgm_PveKKiF_gtBEYL8a0XQ@mail.gmail.com>"
},
{
"name": "Date",
"position": 4,
"value": "Mon, 21 Oct 2019 14:23:24 -0400"
},
{
"name": "From",
"position": 5,
"value": "Joshua Kamdjou <joshkamdjou90@gmail.com>"
},
{
"name": "Mime-Version",
"position": 6,
"value": "1.0"
}
],
"index": 0
},
{
"authentication_results": {
"dkim": "pass",
"dkim_details": [
{
"selector": "20161025",
"signature": "ehHYOeNl",
"type": "dkim"
}
],
"dmarc": "pass",
"dmarc_details": {
"action": "",
"disposition": "NONE",
"from": {
"domain": "gmail.com",
"root_domain": "gmail.com",
"sld": "gmail",
"tld": "com",
"valid": true
},
"policy": "NONE",
"sub_policy": "QUARANTINE",
"verdict": "pass",
"version": ""
},
"spf": "pass",
"spf_details": {
"client_ip": {
"ip": "209.85.220.41"
},
"description": "google.com: domain of joshkamdjou90@gmail.com designates 209.85.220.41 as permitted sender",
"designator": "joshkamdjou90@gmail.com",
"server": {
"domain": "google.com",
"root_domain": "google.com",
"sld": "google",
"tld": "com",
"valid": true
},
"verdict": "pass"
},
"type": "standard"
},
"fields": [
{
"name": "X-Received",
"position": 7,
"value": "by 2002:a92:98d8:: with SMTP id a85mr26122504ill.98.1571682217220; Mon, 21 Oct 2019 11:23:37 -0700 (PDT)"
},
{
"name": "X-Google-Smtp-Source",
"position": 8,
"value": "APXvYqxfE+fdj3jGAojIsortyqTNR1ENm62PygXYKTqDYckHdh7KidULa/8SDeiB1Ps2nUSdRWovZ3PmLrHWEYTKcUM="
},
{
"name": "X-Gm-Message-State",
"position": 9,
"value": "APjAAAVb/mSXq4NJu3c7kNHqknwEGp+eM42+kc6mXX24l99qU1v5jye3 pkOTMEXLRcUUpLcn4Iyu8dy7L0IuAAK7NxEuPsemag=="
},
{
"name": "X-Google-Dkim-Signature",
"position": 10,
"value": "v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to; bh=A/tRNE/3QQOEOzM/F3H1tLMQfWBKJTRJtWmC+XlE/1g=; b=P8xfZoR5KiUmlqs6fZgxEJ8iA4FJ4gFOORhUiv6a7U4QCGDQOz1uGO0eaMJVorUFxG sWhSjONT6TuAHnAsTlbau8f6WozxX6XhUWTMzXFQ110YV3XI5ZSoa4QhrIoOkdkbdEFl Y6+QKc+HZlzvRhaPS8VOF0cqr2Nn6bjtb03AxjIHSCJUMd0TAs6ejofnaDtiIF/vQuVP AdXFUIYlRMNMKRzWv3PNvdUUFmcevbbJ9QGEKadAGTHD+tA2ZXy+1tu822Z0Rd0Z0stH RHb5lvJhtdp3NiphSFrOkZZXg2ffouEJ/nvYcGJll8gxT4LVWPbkQwH6zHsuMeG9CS9O l1dQ=="
},
{
"name": "Dkim-Signature",
"position": 11,
"value": "v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:from:date:message-id:subject:to; bh=A/tRNE/3QQOEOzM/F3H1tLMQfWBKJTRJtWmC+XlE/1g=; b=ehHYOeNliqIXd1VH8iKAMXAamG14fB/cNjH+zRkLMvXIiKrk0cmaZcXHa6L8JmJMlB tMJ/QEm9bOCfaHo1AWXJHtitwTrW0kjI4yAKFnlak82PJ20fDkcRuRmtO18GRINrg3/l 11WGWONbqw/Hh6+Az9slE5dR9sXQDhjK3ibNgev+A7KdUrj/gSY3kLWXj20VqxchN7ze DtHYxI5YtQnyeXVIHtiZ1E2DtpfkWgl6SWY9PIoBkmsd64aBrvUbMh8dC14u/qfn4N+Q wMGR1BQW7P8GP0jazwXXTfBeA8NwlORTCLMrcxNyzaQeUC3g4xxDF4krj2xsewk8j9Tr 1N9g=="
},
{
"name": "Authentication-Results",
"position": 12,
"value": "mx.google.com; dkim=pass header.i=@gmail.com header.s=20161025 header.b=ehHYOeNl; spf=pass (google.com: domain of joshkamdjou90@gmail.com designates 209.85.220.41 as permitted sender) smtp.mailfrom=joshkamdjou90@gmail.com; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com"
},
{
"name": "Received-Spf",
"position": 13,
"value": "pass (google.com: domain of joshkamdjou90@gmail.com designates 209.85.220.41 as permitted sender) client-ip=209.85.220.41;"
}
],
"index": 1,
"received": "by 2002:a92:98d8:: with SMTP id a85mr26122504ill.98.1571682217220; Mon, 21 Oct 2019 11:23:37 -0700 (PDT)",
"received_spf": {
"client_ip": {
"ip": "209.85.220.41"
},
"description": "google.com: domain of joshkamdjou90@gmail.com designates 209.85.220.41 as permitted sender",
"designator": "domain of joshkamdjou90@gmail.com",
"server": {
"domain": "google.com",
"root_domain": "google.com",
"sld": "google",
"tld": "com",
"valid": true
},
"verdict": "pass"
},
"signature": {
"algorithm": "rsa-sha256",
"body_hash": "A/tRNE/3QQOEOzM/F3H1tLMQfWBKJTRJtWmC+XlE/1g=",
"domain": "gmail.com",
"headers": "mime-version:from:date:message-id:subject:to",
"selector": "20161025",
"signature": "ehHYOeNliqIXd1VH8iKAMXAamG14fB/cNjH+zRkLMvXIiKrk0cmaZcXHa6L8JmJMlB tMJ/QEm9bOCfaHo1AWXJHtitwTrW0kjI4yAKFnlak82PJ20fDkcRuRmtO18GRINrg3/l 11WGWONbqw/Hh6+Az9slE5dR9sXQDhjK3ibNgev+A7KdUrj/gSY3kLWXj20VqxchN7ze DtHYxI5YtQnyeXVIHtiZ1E2DtpfkWgl6SWY9PIoBkmsd64aBrvUbMh8dC14u/qfn4N+Q wMGR1BQW7P8GP0jazwXXTfBeA8NwlORTCLMrcxNyzaQeUC3g4xxDF4krj2xsewk8j9Tr 1N9g==",
"type": "dkim",
"version": "1"
}
},
{
"authentication_results": {
"dkim": "pass",
"dkim_details": [
{
"selector": "20161025",
"signature": "ehHYOeNl",
"type": "dkim"
}
],
"dmarc": "pass",
"dmarc_details": {
"action": "",
"disposition": "NONE",
"from": {
"domain": "gmail.com",
"root_domain": "gmail.com",
"sld": "gmail",
"tld": "com",
"valid": true
},
"policy": "NONE",
"sub_policy": "QUARANTINE",
"verdict": "pass",
"version": ""
},
"instance": "1",
"spf": "pass",
"spf_details": {
"client_ip": {
"ip": "209.85.220.41"
},
"description": "google.com: domain of joshkamdjou90@gmail.com designates 209.85.220.41 as permitted sender",
"designator": "joshkamdjou90@gmail.com",
"server": {
"domain": "google.com",
"root_domain": "google.com",
"sld": "google",
"tld": "com",
"valid": true
},
"verdict": "pass"
},
"type": "arc"
},
"fields": [
{
"name": "Received",
"position": 14,
"value": "from mail-sor-f41.google.com (mail-sor-f41.google.com. [209.85.220.41]) by mx.google.com with SMTPS id h17sor9568062ilr.14.2019.10.21.11.23.38 for <ian@sublimesecurity.com> (Google Transport Security); Mon, 21 Oct 2019 11:23:39 -0700 (PDT)"
},
{
"name": "Return-Path",
"position": 15,
"value": "<joshkamdjou90@gmail.com>"
},
{
"name": "Arc-Authentication-Results",
"position": 16,
"value": "i=1; mx.google.com; dkim=pass header.i=@gmail.com header.s=20161025 header.b=ehHYOeNl; spf=pass (google.com: domain of joshkamdjou90@gmail.com designates 209.85.220.41 as permitted sender) smtp.mailfrom=joshkamdjou90@gmail.com; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com"
},
{
"name": "Arc-Message-Signature",
"position": 17,
"value": "i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=to:subject:message-id:date:from:mime-version:dkim-signature; bh=A/tRNE/3QQOEOzM/F3H1tLMQfWBKJTRJtWmC+XlE/1g=; b=gGZe3yO0AYVr+QYSoKCjPrs+7iZauVl0h9FLH/cz/YjelR8e0xJ1w9kJHcjlCigmRd LQX3GVGMdC3O17VMeTeiztsd6OIZHg8pQqQy5exuO5BLm2VnLHoeP8weY+6LVPK7kJiH /KFdZ3S4f7hQrtlxqQWrHTUSAQesPAV0UC+2bUVDUTJGjnDDG/FRumwDpM5q3r284/pK LwLD3Vn9vVuKJJhvNlkrU3sIBGCLSitLjGCAcUwkm0FX9t8bQPAYjN9E8iadIZpIIVU0 XPKc14wQ3RF907FrrwaB8JOiQtKn5SBjbeAWnWXS8DwbEoWIAOpVyXuGrbH6QxEvkALz czmg=="
},
{
"name": "Arc-Seal",
"position": 18,
"value": "i=1; a=rsa-sha256; t=1571682219; cv=none; d=google.com; s=arc-20160816; b=UjFMxEI17M6u7hd/V3tM+q/qAYJeKUX6+wZaFWZrXAi/H8RWsiUcBcnPzc8mx1c8d4 q6YIqczF3TEs6wfbbuAgHbel8oAYegOchVgiv0NTgmQsOQ2rzxC2vzyc2ynBdusQUGsv M1TPSJcRHOeimJr5vJA+LDrkKoBhq+Hd8CAqfLycaqnVTK9gWsdP0l2B3phWMGw7a91X KUPVTosgoXRtco/PlfeJbQm9W42S20bOdN/7e8L3T/LbYJ7e0G97/wi7rqzpX9nXoCl3 mOyF84a8HPTMB/hRHjqC5RyrC0no+JeeToDWFMkiYXaZsvEt+4A8L+XWX1a/fNSmj6JG VyBg=="
}
],
"index": 2,
"received": "from mail-sor-f41.google.com (mail-sor-f41.google.com. [209.85.220.41]) by mx.google.com with SMTPS id h17sor9568062ilr.14.2019.10.21.11.23.38 for <ian@sublimesecurity.com> (Google Transport Security); Mon, 21 Oct 2019 11:23:39 -0700 (PDT)",
"signature": {
"algorithm": "rsa-sha256",
"body_hash": "A/tRNE/3QQOEOzM/F3H1tLMQfWBKJTRJtWmC+XlE/1g=",
"domain": "google.com",
"headers": "to:subject:message-id:date:from:mime-version:dkim-signature",
"instance": "1",
"selector": "arc-20160816",
"signature": "gGZe3yO0AYVr+QYSoKCjPrs+7iZauVl0h9FLH/cz/YjelR8e0xJ1w9kJHcjlCigmRd LQX3GVGMdC3O17VMeTeiztsd6OIZHg8pQqQy5exuO5BLm2VnLHoeP8weY+6LVPK7kJiH /KFdZ3S4f7hQrtlxqQWrHTUSAQesPAV0UC+2bUVDUTJGjnDDG/FRumwDpM5q3r284/pK LwLD3Vn9vVuKJJhvNlkrU3sIBGCLSitLjGCAcUwkm0FX9t8bQPAYjN9E8iadIZpIIVU0 XPKc14wQ3RF907FrrwaB8JOiQtKn5SBjbeAWnWXS8DwbEoWIAOpVyXuGrbH6QxEvkALz czmg==",
"type": "arc-message"
}
},
{
"fields": [
{
"name": "X-Received",
"position": 19,
"value": "by 2002:a05:6e02:a:: with SMTP id h10mr3524960ilr.254.1571682219618; Mon, 21 Oct 2019 11:23:39 -0700 (PDT)"
}
],
"index": 3,
"received": "by 2002:a05:6e02:a:: with SMTP id h10mr3524960ilr.254.1571682219618; Mon, 21 Oct 2019 11:23:39 -0700 (PDT)"
},
{
"fields": [
{
"name": "Received",
"position": 20,
"value": "by 2002:a2e:5419:0:0:0:0:0 with SMTP id i25csp4721902ljb; Mon, 21 Oct 2019 11:23:39 -0700 (PDT)"
},
{
"name": "Delivered-To",
"position": 21,
"value": "ian@sublimesecurity.com"
}
],
"index": 4,
"received": "by 2002:a2e:5419:0:0:0:0:0 with SMTP id i25csp4721902ljb; Mon, 21 Oct 2019 11:23:39 -0700 (PDT)"
}
]
}
Common Indicators #
Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
headers.auth_summary.dmarc.pass | is_null | | 4 rules | mql |
coalesce | func_call | coalesce(headers.auth_summary.dmarc.pass) | 3 rules | mql |
ml.nlu_classifier(body.current_thread.text).intents | length_compare | 0 | 3 rules | mql |
attachments | length_compare | 8 | 2 rules | mql |
beta.ocr(file.message_screenshot()).text | contains | docusign | 2 rules | mql |
beta.ocr(file.message_screenshot()).text | regex_match | Dokument (überprüfen|prüfen|unterschreiben|geschickt) | 2 rules | mql |
beta.ocr(file.message_screenshot()).text | regex_match | important edocs | 2 rules | mql |
body.current_thread.text | contains | document portal | 2 rules | mql |
body.current_thread.text | length_compare | 100 | 2 rules | mql |
body.html.raw | regex_match | ((<br\s*/?>\s*){20,}|\n{20,}) | 2 rules | mql |
body.html.raw | regex_match | (<p class=".*?"><span style=".*?"><o:p>&nbsp;</o:p></span></p>\s*){30,} | 2 rules | mql |
body.html.raw | regex_match | (<p>&nbsp;</p>\s*){7,} | 2 rules | mql |
body.html.raw | regex_match | (<p[^>]*>&nbsp;</p>\s*){7,} | 2 rules | mql |
body.html.raw | regex_match | (<p[^>]*>\s*&nbsp;<br>\s*</p>\s*){5,} | 2 rules | mql |
body.html.raw | regex_match | (<p[^>]*>\s*<br\s*/?>\s*</p>\s*){30,} | 2 rules | mql |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sublime MQL #
References #
headers.ips (collection)
#Description
Message Data Model attribute: headers.ips
Fields #
| Name | Description |
|---|---|
| ip | The IP in canonical form |
Example Message Record #
{
"headers.ips": [
{
"ip": "127.0.0.1"
},
{
"ip": "185.243.112.105"
},
{
"ip": "216.71.148.252"
},
{
"ip": "10.13.177.157"
}
]
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sublime MQL #
References #
headers.reply_to (collection)
#Description
Message Data Model attribute: headers.reply_to
Fields #
| Name | Description |
|---|---|
| display_name | Display name |
| email.domain | |
| email.domain.domain | The fully qualified domain name (FQDN). This may not *always* be routable, e.g. when an email address contains a domain that is just a TLD with no SLD, e.g. foo@WIN-bar |
| email.domain.root_domain | The root domain, including the TLD |
| email.domain.tld | The domain's top-level domain. E.g. the TLD of google.com is 'com' |
| email.domain.valid | Whether the domain is valid |
| email.email | Full email address |
| email.local_part | Local-part, i.e. before the @ |
Common Indicators #
Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
headers.reply_to | length_compare | 0 | 31 rules | mql |
headers.auth_summary.dmarc.pass | eq | true | 12 rules | mql |
headers.auth_summary.spf.pass | eq | true | 12 rules | mql |
beta.profile.by_reply_to | func_call | beta.profile.by_reply_to().prevalence == new | 5 rules | mql |
network.whois | func_call | network.whois(sender.email.domain).days_old <= 30 | 3 rules | mql |
sender.email.domain.root_domain | eq | docusign.net | 3 rules | mql |
sender.email.email | eq | no-reply@zoom.us | 3 rules | mql |
body.current_thread.text | contains | (kindly | 2 rules | mql |
body.current_thread.text | contains | anyone you know | 2 rules | mql |
body.current_thread.text | contains | downsizing | 2 rules | mql |
body.current_thread.text | contains | free donation | 2 rules | mql |
body.current_thread.text | contains | generously offering | 2 rules | mql |
body.current_thread.text | contains | if you will take it | 2 rules | mql |
body.current_thread.text | contains | indicate your interest | 2 rules | mql |
body.current_thread.text | contains | kindly | 2 rules | mql |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sublime MQL #
References #
headers.return_path
#Description
Message Data Model attribute: headers.return_path
Fields #
| Name | Description |
|---|---|
| domain | |
| domain.domain | The fully qualified domain name (FQDN). This may not *always* be routable, e.g. when an email address contains a domain that is just a TLD with no SLD, e.g. foo@WIN-bar |
| domain.root_domain | The root domain, including the TLD |
| domain.tld | The domain's top-level domain. E.g. the TLD of google.com is 'com' |
| Full email address | |
| local_part | Local-part, i.e. before the @ |
Example Message Record #
{
"headers.return_path": {
"domain": {
"domain": "vps.server.com",
"root_domain": "server.com",
"sld": "server",
"subdomain": "vps",
"tld": "com",
"valid": true
},
"email": "root@vps.server.com",
"local_part": "root"
}
}
Common Indicators #
Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
headers.return_path.domain.domain | cross_field_compare | sender.email.domain.domain | 2 rules | mql |
headers.return_path.domain.domain | eq | sendgrid.net | 3 rules | mql |
headers.return_path.domain.domain | ne | calendar-server.bounces.google.com | 2 rules | mql |
headers.auth_summary.spf.details.designator | contains | +srs= | 2 rules | mql |
headers.return_path.domain.root_domain | eq | salesforce.com | 2 rules | mql |
headers.return_path.domain.root_domain | ne | bestdeals.today | 2 rules | mql |
headers.return_path.email | cross_field_compare | sender.email.email | 2 rules | mql |
headers.return_path.email | is_not_null | | 2 rules | mql |
headers.return_path.local_part | contains | +srs= | 2 rules | mql |
network.whois | func_call | network.whois(sender.email.domain).days_old <= 30 | 2 rules | mql |
sender.email.domain.root_domain | ne | bestdeals.today | 2 rules | mql |
subject.subject | regex_match | remittance | 2 rules | mql |
subject.subject | regex_match | w2 | 2 rules | mql |
beta.ocr(file.message_screenshot()).text | contains | best buy | 1 rule | mql |
beta.ocr(file.message_screenshot()).text | contains | ebay | 1 rule | mql |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sublime MQL #
References #
headers.x_authenticated_domain
#Description
Message Data Model attribute: headers.x_authenticated_domain
Fields #
| Name | Description |
|---|---|
| domain | The fully qualified domain name (FQDN). This may not *always* be routable, e.g. when an email address contains a domain that is just a TLD with no SLD, e.g. foo@WIN-bar |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sublime MQL #
References #
headers.x_authenticated_sender
#Description
Message Data Model attribute: headers.x_authenticated_sender
Fields #
| Name | Description |
|---|---|
| Full email address |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sublime MQL #
References #
headers.x_originating_ip
#Description
Message Data Model attribute: headers.x_originating_ip
Fields #
| Name | Description |
|---|---|
| ip | The IP in canonical form |
Common Indicators #
Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
headers.mailer | starts_with | Open-Xchange Mailer | 1 rule | mql |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sublime MQL #