EXPLORE

EXPLORE DETECTIONS

🔍
1,251 detections found

Attachment: SVG files with evasion elements

This rule identifies incoming SVG vector graphics files containing specific patterns: circle elements combined with either embedded images, hyperlinks, QR codes, or filenames that match recipient information. Limited to three attachments. SVG circle elements have been used to obfuscate QR codes and bypass automated QR code scanning methods.

T1566.001T1204.002T1486T1566T1566.002+3
Sublimehigh

Attachment: TAR file with RAR type

Detects messages with TAR file extensions that are actually RAR file types. This mismatch between file extension and actual file type may indicate an evasion technique.

T1566.001T1204.002T1486T1036T1027
Sublimehigh

Attachment: Targeted DOCX with personalized recipient acknowledgement lure

Detects inbound messages with a DOCX attachment containing a quarterly date reference, specific STATUS and ACKNOWLEDGEMENT formatting patterns, and a personalized salutation where the recipient's name or local email part is dynamically embedded in the document XML.

T1566T1566.001T1566.002T1598
Sublimemedium

Attachment: Uncommon compressed file

Use if passing compressed or archive files is not typical behavior in your organization. This behavior has been observed in a number of phishing campaigns.

T1566.001T1204.002T1486T1566T1566.002+1
Sublimelow

Attachment: USDA bid invitation impersonation

Detects messages claiming to be from USDA containing bid invitations with macro-enabled attachments or PDFs. Validates USDA-related content through OCR and natural language analysis.

T1566.002T1534T1656T1598.003T1204.002+3
Sublimemedium

Attachment: Web files with suspicious comments

Detects HTML or SVG files under 100KB that contain duplicate or padding text in the form of literary quotes or common sayings within code comments.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimehigh

Attachment: WinRAR CVE-2025-8088 exploitation

Detects attempts to exploit CVE-2025-8088 via attached RAR files

T1566.001T1204.002T1486T1190T1203+2
Sublimehigh

Attachment: XLSX file with suspicious print titles metadata

Detects XLSX attachments containing EXIF metadata with suspicious TitlesOfParts fields that follow a specific pattern combining 'Company_Name' with extracted values and 'Print_Titles', potentially indicating malicious document preparation.

T1566T1566.001T1566.002T1598T1036+3
Sublimehigh

Attachment: ZIP containing Office binary with embedded DLL

Detects inbound messages with a ZIP attachment that contains an office binary and an unknown DLL.

T1566.001T1204.002T1486T1036T1027
Sublimemedium

Attachment: Zip exploiting CVE-2023-38831 (unsolicited)

A Zip attachment that exhibits attributes required to exploit CVE-2023-38831, a vulnerability in WinRAR (prior to 6.23).

Sublimecritical

Attachment: ZIP file with CVE-2026-0866 exploit

Detects ZIP attachments containing exploits targeting CVE-2026-0866 vulnerability through YARA signature matching.

T1566.001T1204.002T1486T1190T1203+2
Sublimemedium

Attachment: ZIP filename mismatch

Detects inbound messages with ZIP attachments that exhibit a mismatch between the filename stored in the local file header and the filename in the central directory.

T1566.001T1204.002T1486T1036T1027
Sublimelow

BEC with unusual reply-to or return-path mismatch

Detects an unusual header mismatch where the sender is not a freemail address, but the reply-to or return-path are. NLU also detects a BEC intent with medium or high confidence.

T1566.002T1534T1656T1036T1027+2
Sublimehigh

BEC: Employee impersonation with subject manipulation

Subject matches the display name of someone in your organization, and the body resembles a BEC attack.

T1566.002T1534T1656T1566T1598
Sublimehigh

BEC: Executive coaching vendor impersonation

Detects fraudulent messages impersonating leadership development coaching services. The rule identifies inbound messages referencing coaching and executive services terminology alongside financial indicators such as invoices and W-9 forms. Natural language understanding is used to confirm high-confidence financial communication intent and BEC signals.

T1566.002T1534T1656T1598.003T1566+1
Sublimemedium

BEC: Financial fraud from newly registered sender domain

Detects inbound messages from domains registered less than 30 days ago that exhibit business email compromise intent with high-confidence financial or payment topics. The message must also contain explicit banking details such as account and routing numbers, invoice references, or payment urgency language, and must either fail DMARC on a trusted domain or originate from an untrusted domain.

T1566.002T1534T1656T1566T1598
Sublimemedium

BEC: Tax document request

Detects messages requesting W-2 tax documents or related tax information that exhibit authentication failures such as DMARC or SPF failures, or mismatched reply-to addresses. The rule identifies senders using common administrative local parts and filters for messages containing W-2 language combined with request entities detected through natural language processing.

T1566.002T1534T1656T1566T1598
Sublimemedium

BEC/Fraud: Fake investment outreach from suspicious TLD

Detects unsolicited investment/funding outreach emails from suspicious TLDs. Targets mass-mailed spam campaigns offering business funding, capital allocation, and family office outreach.

T1566.002T1534T1656T1566T1598
Sublimemedium

BEC/Fraud: Generic scam attempt to undisclosed recipients

Detects potential generic scams by analyzing text within the email body and other suspicious signals.

T1566.002T1534T1656T1566T1598
Sublimelow

BEC/Fraud: Job scam fake thread or plaintext pivot to freemail

Detects potential job scams using plaintext or fake threads attempting to pivot to a freemail address from an unsolicited sender.

T1566.002T1534T1656
Sublimemedium

BEC/Fraud: Penpal scam

This rule detects messages from individuals looking to establish contact under the guise of seeking friendship or a penpal relationship. Over time, they build trust and then exploit this relationship by asking for money, personal information, or involvement in suspicious activities.

T1566.002T1534T1656T1566T1598
Sublimemedium

BEC/Fraud: Reply-chain manipulation with urgent keywords and self-reply

Detects suspicious reply messages with urgent language in sender name or email address, minimal body content, and the sender's email address appearing in previous thread content, indicating a self reply.

T1566.002T1534T1656T1566T1598+2
Sublimemedium

BEC/Fraud: Romance scam

This rule detects messages attempting to initiate a Romance scam. The rule leverage tells such as undisclosed recipients, freemail emails in the body and common scam phrasing. Romance scams are deceptive schemes where scammers establish false romantic intentions towards individuals to gain their trust and eventually exploit them financially.

T1566.002T1534T1656T1566T1598
Sublimemedium

BEC/Fraud: Scam lure with freemail pivot

This message detects BEC/Fraud lures attempting to solicit the victim to pivot out of band via a freemail address in the body.

T1566.002T1534T1656
Sublimelow
PreviousPage 12 of 53Next