EXPLORE

EXPLORE DETECTIONS

🔍
1,251 detections found

BEC/Fraud: Self-addressed reply with unrelated link in ongoing thread

Flags messages where the sender appears to be replying to themselves within an established thread, but the first non-mailto link in the current message points to a domain unrelated to the sender and to any links seen in the previous thread history (accounting for Mimecast link wrapping). The rule confirms the sender was a genuine participant in prior thread messages and that no organizational recipients or domain matches exist in the earlier history, indicating a likely compromised external account being used to redirect the conversation via a newly introduced, unrelated link.

T1566.002T1534T1656T1566T1566.001+1
Sublimemedium

BEC/Fraud: Student loan callback phishing

This rule detects phishing emails that attempt to engage the recipient by soliciting a callback under the guise of student loan forgiveness or assistance. The messages often come from free email providers, lack a proper HTML structure, and include suspicious indicators such as phone numbers embedded in the text. These emails typically contain language urging the recipient to respond or take immediate action, leveraging urgency around student loan repayment to entice engagement.

T1566.002T1534T1656T1566T1598
Sublimemedium

BEC/Fraud: Unsolicited business acquisition offer

Detects inbound messages with subjects referencing an offer to purchase, combined with body content mentioning private equity, acquiring companies, or discussing an opportunity. These messages are characteristic of fraudulent or unsolicited business acquisition solicitations designed to engage targets in fraudulent financial dealings.

T1566.002T1534T1656T1566T1598
Sublimemedium

BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns

Identifies inbound messages using urgent language patterns and sender behavioral traits common in social manipulation. Combines multiple indicators including urgent subject lines, characteristic message content, short message length, and suspicious sender attributes.

T1566.002T1534T1656T1566.003T1598+2
Sublimemedium

Benefits enrollment impersonation

Detects messages about benefit enrollment periods and healthcare selections from external senders that contain urgent language or requests for action. Excludes legitimate HR communications, marketing mailers, and trusted sender domains with valid authentication.

T1566T1566.001T1566.002T1598T1036+2
Sublimehigh

Body HTML: Comment with 24-character hex token

Detects messages containing HTML comments with exactly 24 hexadecimal characters, which may indicate tracking tokens, session identifiers, or other suspicious embedded data used for evasion or tracking purposes.

T1566T1036T1027
Sublimelow

Body HTML: Recipient SLD in HTML class

Detects when there is a single recipient within $org_domains where the domain SLD is concealed within HTML class attributes. The message comes from either an unauthenticated trusted sender or an untrusted source.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Body: AI-generated invoice template artifacts

Flags inbound messages where NLU classification of the thread text indicates medium or high confidence credential theft or BEC intent, and the message HTML contains comment artifacts characteristic of AI-generated invoice/billing templates (e.g. 'PDF icon', 'File row', 'Billing Table', 'CTA Button'). Messages from highly trusted sender domains are excluded unless they fail DMARC authentication.

T1566T1566.001T1566.002T1598T1534+1
Sublimemedium

Body: CSS clamp() font obfuscation with suspicious URL

Detects inbound messages where the HTML body, or an embedded .eml attachment, contains CSS using the clamp() function with a negative or zero font-size/line-height value—a technique used to hide or obscure text from readers or automated scanners—combined with a link whose URL contains an IP address or an embedded username, both common indicators of an obfuscated or malicious destination.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Body: CSS Hidden text via clip-path

Detects inbound messages containing a div styled with 'clip-path: inset(100%)', a CSS technique used to visually hide substantial blocks of text (over 150 characters) from the recipient while keeping it present in the underlying HTML. This method is commonly used to evade content-based detection engines by hiding filler or unrelated text within the message body.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Body: CSS zero-value calc() obfuscation

Detects inbound messages containing HTML where a CSS calc() expression subtracts an identical value and unit from itself (e.g., calc(100px - 100px)), always resolving to zero. This pattern is commonly used to hide or collapse content from view while keeping it present in the underlying HTML, a technique often leveraged to evade text-based detection or conceal malicious content from recipients.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Body: Embedded email headers indicative of thread hijacking/abuse

Detects email headers embedded in the message body content, indicating forwarded phishing attempts, MIME boundary manipulation, delivery notification spoofing, or copy-paste phishing. This pattern is commonly seen when attackers forward legitimate emails and the headers get included in the body, or when spoofing system notifications.

T1566T1566.001T1566.002T1598T1534+3
Sublimemedium

Body: Fake secure email portal with HTML obfuscation

Detects inbound messages with empty subjects impersonating a secure email portal, identified through multiple indicators including hidden HTML characters used to obfuscate the sender address, recipient domain echoed back as a portal sender, template typos, or frozen tracking links associated with known secure messaging infrastructure abuse.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Body: HTML whitespace stuffing with short initial message

Detects messages that uses HTML-based whitespace padding (repeated br tags, p-nbsp blocks, or div-br wrappers) to push content below the visible fold.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Body: Invisible Unicode obfuscation student loan callback phishing

Detects messages containing clusters of Unicode zero-width and invisible characters (such as LRM, RLM, zero-width space, BOM, and directional isolates) interspersed within digit sequences and body content matching 'student loan' patterns. This technique is used to obscure text from security filters while remaining visually coherent to recipients.

T1566.002T1534T1656T1566T1566.001+3
Sublimemedium

Body: PayApp transaction reference pattern

Detects messages containing PayApp transaction reference numbers in a specific format (PayApp# followed by digits) in either the message body or subject line.

T1566.003T1598T1566.002T1534T1656+2
Sublimemedium

Body: Suspicious date format

Detects messages containing strage date formats observed in phishing emails.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Body: Suspicious table template fingerprint

Detects messages matching a specific HTML template fingerprint characterized by a table containing both 'Important' and 'Company' text nodes. This pattern is associated with a known malicious message template used to deceive recipients.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Body: Yellow highlighted text markers

Detects messages containing multiple HTML span elements with yellow background highlighting (rgb(255, 241, 0)) and data-markjs attributes, potentially indicating evasion techniques through visual markup manipulation.

T1566T1566.001T1566.002T1598T1534+3
Sublimelow

Brand impersonation: AARP

Detects messages impersonating AARP by analyzing sender display name and body content for AARP references, address information, or survey-related language from unauthorized senders.

T1566.002T1534T1656T1566T1566.001+2
Sublimemedium

Brand impersonation: Adobe (QR code)

Detects messages using Adobe image based lures, referencing or including a QR code from an Unsolicited sender. These messages often lead users to phishing sites or initiate unwanted downloads.

T1566T1566.001T1566.002T1598T1598.003
Sublimehigh

Brand impersonation: Adobe Acrobat Sign PDF phishing file format template

Detects specific credential phishing PDF attachments that contain Adobe branding or Adobe Acrobat Sign text along with specific file format indicators, potentially indicating fraudulent documents impersonating legitimate Adobe services.

T1566T1566.001T1566.002T1598T1598.003
Sublimehigh

Brand impersonation: Adobe Sign with suspicious indicators

Detects messages impersonating Adobe Sign that contain Adobe branding elements but are not sent from legitimate Adobe domains and lack proper Adobe Sign authentication headers.

T1566T1566.001T1566.002T1598T1598.003
Sublimehigh

Brand impersonation: Adobe with suspicious language and link

Email contains an Adobe logo, at least one link, and suspicious link language from a new sender.

T1566T1566.001T1566.002T1598T1598.003
Sublimehigh
PreviousPage 13 of 53Next