Common snippets

Useful snippets of MQL to make building detection rules easier.

Has my organization ever sent an email to this sender?

If it's a freemail address, like, check the full email address. If it's a custom domain, check the domain instead.

and (
   in $free_email_providers
            and not in $recipient_emails
        or (
   not in $free_email_providers
            and not in $recipient_domains

Low reputation link (not in tranco 1m), or a free subdomain/file host

        .href_url.domain.root_domain in $free_subdomain_hosts 
        or .href_url.domain.domain in $free_file_hosts
        or .href_url.domain.root_domain not in $tranco_1m