Email Security: document callback, smuggling and PII detection facts - #464
Merged
Merged
Conversation
Adds HTMLIndicators, PDFInfo, PhoneNumbers/PhoneSource, visible_chars and lookalike.display_name_brand to the rule reference, plus a detections section on how the default rules read callback phishing and HTML smuggling. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Contributor
Author
|
/lc-review |
lcbill
previously approved these changes
Sep 30, 2026
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
lcbill
previously approved these changes
Sep 30, 2026
Contributor
Author
|
/lc-review |
lcbill
previously approved these changes
Oct 1, 2026
Contributor
Author
|
/lc-review |
lcbill
previously approved these changes
Oct 1, 2026
Contributor
Author
|
/lc-review |
lcbill
previously approved these changes
Oct 1, 2026
Contributor
Author
|
/lc-review |
lcbill
previously approved these changes
Oct 1, 2026
Contributor
Author
|
/lc-review |
lcbill
approved these changes
Oct 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Document callback phishing, HTML smuggling and optional outbound PII detections in Email Security. Add the message-model field reference for HTML indicators, locked versus readable encrypted PDFs, per-document phone facts, and distinct PII counts. Explain sender-oddity gates, inspection bounds, incomplete results, browser-file checks and the managed pack's current severity coverage.
PII facts contain counts only. Detection events may still contain sensitive values in the originating email body. The docs describe dashed internal-ID false positives, ordinary invoice IBANs, and the exclusion of text inside ordinary document, spreadsheet and PDF files. Late attachment facts do not replay the initial outbound DLP evaluation.
Validation: strict local documentation build; all current checks and the complete rendered-build log must be verified before publication. This describes the coming matching service/detection-pack release and should wait for that rollout.
🤖 Generated with Claude Code