Back
Id50c61708-9824-46f3-87cf-22490796fae2
RulenameCorelight - SMTP Email containing NON Ascii Characters within the Subject
DescriptionDetects where an emails contain non ascii characters within the Subject.
SeverityLow
TacticsInitialAccess
TechniquesT1566
Required data connectorsCorelight
KindScheduled
Query frequency1h
Query period1h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Corelight/Analytic%20Rules/CorelightSMTPEmailSubjectNonAsciiCharacters.yaml
Version2.2.0
Arm template50c61708-9824-46f3-87cf-22490796fae2.json
Deploy To Azure
corelight_smtp
| where subject hasprefix @'\=?utf-16'
| mv-expand to_recipient = todynamic(to_) to typeof(string)
| summarize recipients = dcount(to_recipient)
| extend k = 1
| join (corelight_smtp
        | where subject hasprefix @'\=?utf-16'
        | mv-expand to_recipient = todynamic(to_) to typeof(string)
        | summarize by to_recipient
        | extend k = 1) on k
| where recipients > 1
name: Corelight - SMTP Email containing NON Ascii Characters within the Subject
triggerOperator: gt
query: |
  corelight_smtp
  | where subject hasprefix @'\=?utf-16'
  | mv-expand to_recipient = todynamic(to_) to typeof(string)
  | summarize recipients = dcount(to_recipient)
  | extend k = 1
  | join (corelight_smtp
          | where subject hasprefix @'\=?utf-16'
          | mv-expand to_recipient = todynamic(to_) to typeof(string)
          | summarize by to_recipient
          | extend k = 1) on k
  | where recipients > 1
queryFrequency: 1h
description: |
  'Detects where an emails contain non ascii characters within the Subject.'
id: 50c61708-9824-46f3-87cf-22490796fae2
triggerThreshold: 0
queryPeriod: 1h
version: 2.2.0
kind: Scheduled
status: Available
severity: Low
requiredDataConnectors:
- connectorId: Corelight
  dataTypes:
  - corelight_smtp
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Corelight/Analytic%20Rules/CorelightSMTPEmailSubjectNonAsciiCharacters.yaml
relevantTechniques:
- T1566
tactics:
- InitialAccess
entityMappings:
- fieldMappings:
  - identifier: Recipient
    columnName: to_recipient
  entityType: MailMessage
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/50c61708-9824-46f3-87cf-22490796fae2')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/50c61708-9824-46f3-87cf-22490796fae2')]",
      "properties": {
        "alertRuleTemplateName": "50c61708-9824-46f3-87cf-22490796fae2",
        "customDetails": null,
        "description": "'Detects where an emails contain non ascii characters within the Subject.'\n",
        "displayName": "Corelight - SMTP Email containing NON Ascii Characters within the Subject",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "MailMessage",
            "fieldMappings": [
              {
                "columnName": "to_recipient",
                "identifier": "Recipient"
              }
            ]
          }
        ],
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Corelight/Analytic%20Rules/CorelightSMTPEmailSubjectNonAsciiCharacters.yaml",
        "query": "corelight_smtp\n| where subject hasprefix @'\\=?utf-16'\n| mv-expand to_recipient = todynamic(to_) to typeof(string)\n| summarize recipients = dcount(to_recipient)\n| extend k = 1\n| join (corelight_smtp\n        | where subject hasprefix @'\\=?utf-16'\n        | mv-expand to_recipient = todynamic(to_) to typeof(string)\n        | summarize by to_recipient\n        | extend k = 1) on k\n| where recipients > 1\n",
        "queryFrequency": "PT1H",
        "queryPeriod": "PT1H",
        "severity": "Low",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "InitialAccess"
        ],
        "techniques": [
          "T1566"
        ],
        "templateVersion": "2.2.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}