Executive Tracking with Subject

Updated 1 month ago by admin

Our Email Security Threat Detection team has identified a trend in Executive Tracking style emails, that instead of using the Outlook display name, they use the subject line to impersonate users within your company.

The example rule below will help to detect these targeted emails as well as place them in Global – Quarantine for later review.

The rule is looking to match both impersonation subjects from popular free domains, such as Gmail, Yahoo, and Outlook; and then quarantines the matched emails.

To create this rule:

  1. Visit your USS Dashboard and click Products -> E-mail Security -> Custom Rule Data.
  2. Click New then Rule Regex.
  3. Give the Regex a sensible name, such as “Subject Tracking Regex”.
  4. Add the entries you wish to track with each new entry or variation separated by a pipe (|): example: ^(Joe Bloggs|Sally Fields|John Smith|Jane Doe)$
These names used in the Regex can be taken from the executive tracked names listed in the mailbox section
  1. Click Save in the bottom right corner
  2. Next, navigate to Email Security -> Message Rules -> and click the + to create a new rule
  3. Give the rule a sensible name, such as “Subject Tracking”.
  4. Add a Direction Condition, with the logic set to Matches: Inbound.
  5. Add a Subject Condition, with the logic set to Matches: Subject Tracking Regex.
  6. Add a Sender Condition, with the logic set to Matches: Free Domains.
  7. Do not add any actions.
  8. Add a Quarantine – Company Only Final Action, which will send the message to the Global Quarantine (see note below), with the value set to: Spam.
  9. Make sure that the Active checkbox is enabled, so that your new rule will start working immediately.
  10. Click Save
  11. Drag the new rule to just below the Possible Spam rule within Message Rules.

The completed rule should look like this:

If you would like a copy of the list of domains within the “Free Domains” rule data, please contact your Service Provider
If you do not wish to Quarantine – Company (Global Quarantine) these emails, you can remove this Final Action, and replace it with “Add Spam Score” to allow the email to be processed by all rules. However, you will need to move this rule to above “Apply DKIM Signing”.

 

 


How did we do?