Common snippets

Useful snippets of MQL to make building detection rules easier.

Has my organization ever sent an email to this sender?

If it's a freemail address, like, check the full email address. If it's a custom domain, check the domain instead.

and (
   in $free_email_providers
            and not in $recipient_emails
        or (
   not in $free_email_providers
            and not in $recipient_domains

Low reputation link (not in tranco 1m), or a free subdomain/file host

        .href_url.domain.root_domain in $free_subdomain_hosts 
        or .href_url.domain.domain in $free_file_hosts
        or .href_url.domain.root_domain not in $tranco_1m

Exclude email addresses or aliases in a custom list (To, CC, or BCC'd)

// exclude emails to support aliases
not any([,, recipients.bcc], 
    any(., in $support_email_aliases)

Exclude specific mailboxes

not in ("[email protected]")

Only run on specific mailboxes in a custom list in $highly_targeted_user_email_addresses