EXPLORE DETECTIONS
Brand impersonation: United Healthcare
Detects messages impersonating United Healthcare (UHC) by analyzing display names that contain variations of 'United Healthcare' or 'UHC', including those with character substitutions. The rule excludes legitimate messages from verified UHC domains that pass DMARC authentication and handles high-trust sender domains appropriately.
Brand impersonation: United States Patent and Trademark Office
Detects messages impersonating the United States Patent and Trademark Office (USPTO) using display name variations, confusable characters, or USPTO-related terminology in the sender or subject.
Brand impersonation: UPS
Detects messages impersonating UPS (United Parcel Service) through display name, email address patterns, subject content, or HTML styling that mimics UPS branding, while excluding legitimate UPS domains.
Brand impersonation: USPS
Impersonation of the United States Postal Service.
Brand impersonation: Vanguard
Detects inbound messages from senders using Vanguard-like display names or domains, excluding legitimate Vanguard domains and authenticated communications. Additional checks ensure the sender is not from trusted organizational domains or high-trust sender domains with proper authentication.
Brand impersonation: Vanta
Impersonation of Vanta.
Brand impersonation: Venmo
Impersonation of Venmo
Brand impersonation: Wells Fargo
Impersonation of Wells Fargo Bank.
Brand impersonation: WeTransfer
Detects messages claiming to be from WeTransfer that contain suspicious indicators, including misspelled domains, non-standard TLDs, suspicious file reference numbers, and French language variations. Excludes legitimate WeTransfer traffic with valid DMARC authentication.
Brand impersonation: Wise
Impersonating Wise Financial, an online banking platform.
Brand impersonation: Wix
Detects messages impersonating Wix by using similar display names or domain names, while not originating from legitimate WIX domains or failing DMARC authentication from trusted senders.
Brand impersonation: Xodo Sign
Detects messages impersonating Xodo Sign with 'Processed by Xodo Sign' text from unauthorized senders that fail DMARC authentication.
Brand impersonation: Zoom
Detects messages impersonating Zoom through social footers, webinar links, and suspicious domain pattern matching. The rule looks for specific combinations of social media links, redirects, and content analysis to identify inauthentic Zoom-branded messages not originating from legitimate Zoom domains.
Brand impersonation: Zoom (strict)
Impersonation of the video conferencing provider Zoom. This "strict" version of this rule will only flag when the sender's display name matches those used by Zoom exactly.
Brand impersonation: Zoom via HTML styling
Detects messages impersonating Zoom by identifying HTML table cells with specific blue styling (rgb(11,92,255)) containing Zoom branding in header elements.
Brand impersonation: Zoom via lookalike domain
Message contains a single link which attempts to spoof a 'zoom' link, sent from a free email provider to a single recipient.
Brand impersonation: Zoom with deceptive link display
Detects messages mentioning Zoom in the subject or body that contain links appearing to go to zoom.us but actually redirect to different domains.
Brand spoof: Dropbox
Impersonation of Dropbox, a file sharing service; specifically spoofs the Dropbox sender domain.
BullPhish ID phishing simulation
Identifies phishing simulations sent by BullPhish ID and excludes the message from live analysis.
Business Email Compromise (BEC) attempt from unsolicited sender
Detects potential Business Email Compromise (BEC) attacks by analyzing text within the email body from unsolicited senders.
Business Email Compromise (BEC) attempt from untrusted sender
Detects potential Business Email Compromise (BEC) attacks by analyzing text within the email body from first-time senders.
Business Email Compromise (BEC) attempt from untrusted sender (French/Français)
Detects potential Business Email Compromise (BEC) attacks by searching for common French BEC language within the email body from first-time senders.
Business Email Compromise (BEC) attempt with masked recipients and reply-to mismatch (unsolicited)
This rule detects unsolicited messages where the recipient matches the sender address and no other recipients are identified. The reply-to address does not match the sender, and is a freemail with no links in the body. This a common combination of techniques used by low level BEC threats.
Business Email Compromise (BEC) with request for mobile number
This rule detects unsolicited messages with a small plain text body, that is attempting to solicit a mobile number.