Skip to content

Email Security: document callback, smuggling and PII detection facts - #464

Merged
maximelb merged 8 commits into
masterfrom
fbG/email-security-detection-content
Oct 2, 2026
Merged

maximelb merged 8 commits into
masterfrom
fbG/email-security-detection-content

Conversation

@maximelb

@maximelb maximelb commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Document callback phishing, HTML smuggling and optional outbound PII detections in Email Security. Add the message-model field reference for HTML indicators, locked versus readable encrypted PDFs, per-document phone facts, and distinct PII counts. Explain sender-oddity gates, inspection bounds, incomplete results, browser-file checks and the managed pack's current severity coverage.

PII facts contain counts only. Detection events may still contain sensitive values in the originating email body. The docs describe dashed internal-ID false positives, ordinary invoice IBANs, and the exclusion of text inside ordinary document, spreadsheet and PDF files. Late attachment facts do not replay the initial outbound DLP evaluation.

Validation: strict local documentation build; all current checks and the complete rendered-build log must be verified before publication. This describes the coming matching service/detection-pack release and should wait for that rollout.

🤖 Generated with Claude Code

Adds HTMLIndicators, PDFInfo, PhoneNumbers/PhoneSource, visible_chars and
lookalike.display_name_brand to the rule reference, plus a detections section on
how the default rules read callback phishing and HTML smuggling.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@maximelb

Copy link
Copy Markdown
Contributor Author

/lc-review

lcbill
lcbill previously approved these changes Sep 30, 2026
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
lcbill
lcbill previously approved these changes Sep 30, 2026
@maximelb

maximelb commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

/lc-review

lcbill
lcbill previously approved these changes Oct 1, 2026
@maximelb maximelb changed the title Email Security: document callback-phishing and HTML-smuggling detection facts Email Security: document callback, smuggling and PII detection facts Oct 1, 2026
@maximelb

maximelb commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

/lc-review

lcbill
lcbill previously approved these changes Oct 1, 2026
@maximelb

maximelb commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

/lc-review

lcbill
lcbill previously approved these changes Oct 1, 2026
@maximelb

maximelb commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

/lc-review

lcbill
lcbill previously approved these changes Oct 1, 2026
@maximelb

maximelb commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

/lc-review

@maximelb
maximelb merged commit ec90a6e into master Oct 2, 2026
7 checks passed
@maximelb
maximelb deleted the fbG/email-security-detection-content branch October 2, 2026 00:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants