Whisper Security - SPF Record Unauthorized Include Detection

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Detects new SPF include directives on monitored domains that were not seen in the previous scan window. Unauthorized SPF modifications may allow adversaries to send phishing emails that pass SPF checks.

Attribute Value
Type Analytic Rule
Solution Whisper
ID 9c275139-b554-58f1-b390-8520b10e54ad
Severity High
Status Available
Kind Scheduled
Tactics InitialAccess
Techniques T1566
Required Connectors WhisperSecurityConnector
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
WhisperInfraContext_CL ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules · Back to Whisper