EXPLORE

EXPLORE DETECTIONS

🔍
1,251 detections found

Brand impersonation: United Healthcare

Detects messages impersonating United Healthcare (UHC) by analyzing display names that contain variations of 'United Healthcare' or 'UHC', including those with character substitutions. The rule excludes legitimate messages from verified UHC domains that pass DMARC authentication and handles high-trust sender domains appropriately.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium

Brand impersonation: United States Patent and Trademark Office

Detects messages impersonating the United States Patent and Trademark Office (USPTO) using display name variations, confusable characters, or USPTO-related terminology in the sender or subject.

T1566.002T1534T1656T1598.003T1566+1
Sublimemedium

Brand impersonation: UPS

Detects messages impersonating UPS (United Parcel Service) through display name, email address patterns, subject content, or HTML styling that mimics UPS branding, while excluding legitimate UPS domains.

T1566T1566.001T1566.002T1598T1598.003+1
Sublimelow

Brand impersonation: USPS

Impersonation of the United States Postal Service.

T1566T1566.001T1566.002T1598T1598.003
Sublimehigh

Brand impersonation: Vanguard

Detects inbound messages from senders using Vanguard-like display names or domains, excluding legitimate Vanguard domains and authenticated communications. Additional checks ensure the sender is not from trusted organizational domains or high-trust sender domains with proper authentication.

T1566.002T1534T1656T1566.003T1598+6
Sublimemedium

Brand impersonation: Vanta

Impersonation of Vanta.

T1566T1566.001T1566.002T1598T1598.003+1
Sublimelow

Brand impersonation: Venmo

Impersonation of Venmo

T1566T1566.001T1566.002T1598T1598.003+1
Sublimemedium

Brand impersonation: Wells Fargo

Impersonation of Wells Fargo Bank.

T1566T1566.001T1566.002T1598T1598.003+1
Sublimehigh

Brand impersonation: WeTransfer

Detects messages claiming to be from WeTransfer that contain suspicious indicators, including misspelled domains, non-standard TLDs, suspicious file reference numbers, and French language variations. Excludes legitimate WeTransfer traffic with valid DMARC authentication.

T1566.002T1534T1656T1566.003T1598+6
Sublimehigh

Brand impersonation: Wise

Impersonating Wise Financial, an online banking platform.

T1566T1566.001T1566.002T1598T1598.003
Sublimehigh

Brand impersonation: Wix

Detects messages impersonating Wix by using similar display names or domain names, while not originating from legitimate WIX domains or failing DMARC authentication from trusted senders.

T1566T1566.001T1566.002T1598T1598.003+1
Sublimemedium

Brand impersonation: Xodo Sign

Detects messages impersonating Xodo Sign with 'Processed by Xodo Sign' text from unauthorized senders that fail DMARC authentication.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium

Brand impersonation: Zoom

Detects messages impersonating Zoom through social footers, webinar links, and suspicious domain pattern matching. The rule looks for specific combinations of social media links, redirects, and content analysis to identify inauthentic Zoom-branded messages not originating from legitimate Zoom domains.

T1566T1566.001T1566.002T1598T1598.003+2
Sublimemedium

Brand impersonation: Zoom (strict)

Impersonation of the video conferencing provider Zoom. This "strict" version of this rule will only flag when the sender's display name matches those used by Zoom exactly.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium

Brand impersonation: Zoom via HTML styling

Detects messages impersonating Zoom by identifying HTML table cells with specific blue styling (rgb(11,92,255)) containing Zoom branding in header elements.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium

Brand impersonation: Zoom via lookalike domain

Message contains a single link which attempts to spoof a 'zoom' link, sent from a free email provider to a single recipient.

T1566T1566.001T1566.002T1598T1598.003
Sublimehigh

Brand impersonation: Zoom with deceptive link display

Detects messages mentioning Zoom in the subject or body that contain links appearing to go to zoom.us but actually redirect to different domains.

T1566T1566.001T1566.002T1598T1204.002+2
Sublimemedium

Brand spoof: Dropbox

Impersonation of Dropbox, a file sharing service; specifically spoofs the Dropbox sender domain.

T1566T1566.001T1566.002T1598T1204.002+2
Sublimemedium

BullPhish ID phishing simulation

Identifies phishing simulations sent by BullPhish ID and excludes the message from live analysis.

Sublime

Business Email Compromise (BEC) attempt from unsolicited sender

Detects potential Business Email Compromise (BEC) attacks by analyzing text within the email body from unsolicited senders.

T1566.002T1534T1656T1566T1598
Sublimemedium

Business Email Compromise (BEC) attempt from untrusted sender

Detects potential Business Email Compromise (BEC) attacks by analyzing text within the email body from first-time senders.

T1566.002T1534T1656T1566T1598
Sublimemedium

Business Email Compromise (BEC) attempt from untrusted sender (French/Français)

Detects potential Business Email Compromise (BEC) attacks by searching for common French BEC language within the email body from first-time senders.

T1566.002T1534T1656T1566T1598
Sublimemedium

Business Email Compromise (BEC) attempt with masked recipients and reply-to mismatch (unsolicited)

This rule detects unsolicited messages where the recipient matches the sender address and no other recipients are identified. The reply-to address does not match the sender, and is a freemail with no links in the body. This a common combination of techniques used by low level BEC threats.

T1566.002T1534T1656T1036T1027
Sublimemedium

Business Email Compromise (BEC) with request for mobile number

This rule detects unsolicited messages with a small plain text body, that is attempting to solicit a mobile number.

T1566.002T1534T1656T1566T1598
Sublimemedium
PreviousPage 20 of 53Next