Phishing: address-shaped From display name on homograph domain
This rule detects potential phishing attempts where the sender's display name is formatted as an email address and the sender's domain uses a capital 'I' character to mimic a well-known service provider (typosquatting/homoglyph attack), such as 'gmaiI.com'. It identifies discrepancies between the actual sender domain and the normalized domain name after character replacement.
Microsoft Sentinel (KQL)

