Message Subject
| Attribute group | Sample | Rule |
|---|---|---|
| subject | Y | Y |
subject
#Description
Message Data Model attribute: subject
Fields #
| Name | Description |
|---|---|
| base | Subject of the email with tags and reply/forward indicators removed |
| is_forward | Indicates if the subject of the email is a forward |
| is_reply | Indicates if the subject of the email is a reply |
| subject | Subject of the email |
Example Message Record #
{
"subject": {
"subject": "A file was shared with you tyrellcorp-Covid-19 Vaccination And Testing Report.pdf."
}
}
Common Indicators #
Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
type.inbound | eq | true | 285 rules | mql |
type.outbound | eq | true | 201 rules | mql |
attachments | length_compare | 0 | 46 rules | mql |
attachments | length_compare | 1 | 14 rules | mql |
body.links | length_compare | 0 | 39 rules | mql |
headers.in_reply_to | is_null | | 31 rules | mql |
headers.references | length_compare | 0 | 31 rules | mql |
profile.by_sender | func_call | profile.by_sender().prevalence in (new, outlier) | 17 rules | mql |
body.current_thread.text | contains | subscription | 16 rules | mql |
body.current_thread.text | contains | antivirus | 14 rules | mql |
body.current_thread.text | contains | cancel | 14 rules | mql |
body.current_thread.text | contains | order | 14 rules | mql |
headers.reply_to | length_compare | 0 | 16 rules | mql |
body.previous_threads | length_compare | 0 | 15 rules | mql |
headers.auth_summary.dmarc.pass | eq | true | 15 rules | mql |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sublime MQL #