Message Subject

Attribute groupSampleRule
subjectYY

subject

#

Description

Message Data Model attribute: subject

Fields #

NameDescription
baseSubject of the email with tags and reply/forward indicators removed
is_forwardIndicates if the subject of the email is a forward
is_replyIndicates if the subject of the email is a reply
subjectSubject of the email

Example Message Record #

{
  "subject": {
    "subject": "A file was shared with you tyrellcorp-Covid-19 Vaccination And Testing Report.pdf."
  }
}

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
type.inboundeqtrue285 rulesmql
type.outboundeqtrue201 rulesmql
attachmentslength_compare046 rulesmql
attachmentslength_compare114 rulesmql
body.linkslength_compare039 rulesmql
headers.in_reply_tois_null31 rulesmql
headers.referenceslength_compare031 rulesmql
profile.by_senderfunc_callprofile.by_sender().prevalence in (new, outlier)17 rulesmql
body.current_thread.textcontainssubscription16 rulesmql
body.current_thread.textcontainsantivirus14 rulesmql
body.current_thread.textcontainscancel14 rulesmql
body.current_thread.textcontainsorder14 rulesmql
headers.reply_tolength_compare016 rulesmql
body.previous_threadslength_compare015 rulesmql
headers.auth_summary.dmarc.passeqtrue15 rulesmql

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sublime MQL #

References #