Email Reply-To address diverges from spoofed From display sender
Detects incoming email messages where the Reply-To header address domain differs from the Sender From address domain. This technique is commonly used in phishing attacks to redirect victim replies to an attacker-controlled mailbox while maintaining a spoofed appearance in the original sender field.
Microsoft Sentinel (KQL)

