← All detection heuristics · Social Engineering
high
OFFICE_SHARED_FILE_REVIEW_LURE
What it means
Document impersonates a file-sharing notification and its only action is to click a rendered button/link to 'access the document'.
Why it fires
The rule fires when a document's extracted text contains BOTH a file-share impersonation claim ("… shared a secured file with you", "you have received a secure document") AND a call-to-action to click a button or link to access / view the document. This is the SharePoint/OneDrive consent-phishing template: the click target is typically a flattened image with no extractable URL, so link-based lure rules never see it. Requiring BOTH phrases together keeps false positives near zero — a benign document almost never carries both. Note: the incriminating text often lives in a DrawingML textbox ("<a:t>" shape runs), so the OOXML text extractor now reads drawing parts as well.
Other Social Engineering heuristics
SE_BOOKING_COMPLAINT_PHISH PDF_FAKE_DOCUMENT_COMPONENT_INSTALLER OOXML_QR_CREDENTIAL_PHISH SE_CALLBACK_SCAM_TEMPLATE PDF_BRAND_ACCOUNT_UPDATE_REDIRECT_LURE PDF_IMAGE_REPEATED_DECOY_REDIRECT_LURE PDF_IMAGE_DOCUMENT_REVIEW_HOST_LURE PDF_LOCALIZED_DOWNLOAD_HOSTING_LURE PDF_MINIMAL_VIEW_DOCUMENT_REDIRECT PDF_NESTED_ENCODED_CROSSHOST_REDIRECT PDF_RFP_EXTERNAL_ACTION_LURE PDF_UTILITY_REFUND_OFFDOMAIN_LURE PDF_SPARSE_MOVED_ARTICLE_DOORWAY