LinkedIn SDR Agent Automated Outreach Fan-Out
This rule flags when an automated LinkedIn 'SDR' agent (a tool that finds prospects and sends connection requests or messages on your behalf) builds a list of targets and then blasts out a large batch of invites or messages in a short time, all from one automated process rather than a person using the browser. It doesn't judge whether the messages are legitimate or malicious — it just flags the unattended, high-volume pattern.
How the attack works
An AI agent session first calls LinkedIn's API to enumerate profiles, leads, or search results, building a target list. Shortly after, the same session sends 12 or more write requests (connection invites or messages) to LinkedIn in a 15-minute window — a volume and speed no human clicking through the web UI would produce. If that same session also sends traffic to an external, non-LinkedIn host during this window, it's flagged as more concerning, since that could be a source list, a reply-capture service, or a data exfil point. The rule ties all of this activity to one automated process and its lineage, not to a browser session.
Netzilo detection
Netzilo reports this behaviour when it is observed.
- Signature ID
- 7b3c1e42-9d0a-4f6b-8c25-1ae5f70d3b98
- Severity
- Medium
Why it matters
An organization could have an AI agent conducting unauthorized or unmonitored large-scale outreach on LinkedIn under its identity — which risks account bans, reputational damage, or (if the campaign is malicious) credential-harvesting/phishing at scale. This rule only detects the enumeration-then-burst automation pattern; it does not confirm phishing intent or inspect message content.
What you can do
- →Inventory which processes or service accounts are authorized to drive LinkedIn outreach agents, and treat any unrecognized session doing enumeration-then-burst messaging as worth investigating.
- →When this fires, check whether the campaign was sanctioned — if so, document it to reduce repeat alerts; if not, disable the account/session's LinkedIn API access immediately.
- →Review any external (non-LinkedIn) destinations the session contacted during the burst, since these could reveal a lead-list source or data exfiltration point.
- →Require human approval or rate-limiting on any agent capable of bulk LinkedIn messaging or invitations, rather than letting it run fully unattended.
Known benign look-alikes
- Sanctioned sales-development or recruiting campaign - an approved SDR agent legitimately sending connection invites and InMails from a seeded prospect list. This rule reports (never blocks) precisely so authorised campaigns can be attributed and volume-audited rather than interrupted.
- Sales Navigator bulk operations performed by an authorised user whose browser traffic is proxied through a process that resolves into a monitored agent lineage.
- QA / integration testing of a LinkedIn connector against a test-account seed list, which produces the same enumeration-then-burst pattern.
- A LinkedIn client that batches many messaging writes in a single thread (multi-part message send, retries, or read-receipt/typing writes on the same conversation endpoint); mitigated by requiring write methods, a 12-request floor, and a preceding enumeration stage, and by the 10-minute report dedupe.