How does one start looking for payload portions uniquely identifying base64 emails, to be able to use them as starting point of snort rules (i.e. what part of a MIME base64 encoded payload would one consider as possible "content" option for such rules)?

TIA,
Stef