π Overview
Implement a KQL rule to detect AI-generated voice deepfake fraud targeting retail finance teams. Attackers use AI voice cloning to impersonate executives or suppliers over VoIP, tricking staff into authorising fraudulent payments. This is an emerging TTP with growing retail impact in 2025.
π― Acceptance Criteria
π Related
- MITRE Technique: T1598 β Phishing for Information
- Related files:
playbooks/phishing-triage.md, docs/threat-model.md
- Dependencies: VoIP/telephony log connector and ERP connector configured in Sentinel
π Resources
π Overview
Implement a KQL rule to detect AI-generated voice deepfake fraud targeting retail finance teams. Attackers use AI voice cloning to impersonate executives or suppliers over VoIP, tricking staff into authorising fraudulent payments. This is an emerging TTP with growing retail impact in 2025.
π― Acceptance Criteria
detection-rules/ai_voice_fraud.kqlHightests/detection-rules/test_kql_rules.pydocs/mitre-mapping.mddevπ Related
playbooks/phishing-triage.md,docs/threat-model.mdπ Resources