Tag
medium
advisory
Monitor Email for Brand Abuse via Domain Permutations
2 rules 1 TTPThis analytic identifies emails claiming to originate from domains similar to those being monitored for abuse by cross-referencing sender addresses with a lookup table of domain permutations, indicating potential phishing or brand impersonation.
Splunk Enterprise +2
brand-abuse
email
phishing
impersonation
2r
1t
medium
advisory
Monitor Web Traffic For Brand Abuse
2 rules 1 TTPThis analytic identifies web requests to domains that closely resemble a monitored brand's domain, indicating potential brand abuse indicative of phishing or malware distribution attempts.
Splunk Enterprise +2
brand-abuse
phishing
network
2r
1t