MFA / one-time-code harvesting lure

SE_MFA_LURE

← All detection heuristics · Social Engineering

high SE_MFA_LURE

What it means

Document asks for an MFA, OTP, authenticator, or one-time passcode action.

Why it fires

The rule matches requests for MFA, OTP, authenticator, one-time code, or push approval actions. Documents that ask for these actions should be reviewed carefully, especially when combined with credential or account language.

Other Social Engineering heuristics

SE_BOOKING_COMPLAINT_PHISH PDF_FAKE_DOCUMENT_COMPONENT_INSTALLER OOXML_QR_CREDENTIAL_PHISH SE_CALLBACK_SCAM_TEMPLATE PDF_BRAND_ACCOUNT_UPDATE_REDIRECT_LURE PDF_IMAGE_REPEATED_DECOY_REDIRECT_LURE PDF_IMAGE_DOCUMENT_REVIEW_HOST_LURE PDF_LOCALIZED_DOWNLOAD_HOSTING_LURE PDF_MINIMAL_VIEW_DOCUMENT_REDIRECT PDF_NESTED_ENCODED_CROSSHOST_REDIRECT PDF_RFP_EXTERNAL_ACTION_LURE PDF_UTILITY_REFUND_OFFDOMAIN_LURE PDF_SPARSE_MOVED_ARTICLE_DOORWAY