EXPLORE

EXPLORE DETECTIONS

🔍
1,251 detections found

Callback phishing: Zero-width character obfuscation from freemail sender

Detects inbound messages sent from free email providers that contain a high volume of zero-width no-break space characters inserted before closing HTML tags, a technique used to break up and obfuscate text from content scanners. The rule also requires the presence of a phone number pattern in the message thread, consistent with callback phishing lures that rely on victims dialing a number rather than clicking a link.

T1566.003T1598T1036T1027T1566
Sublimemedium

Callback scam: Impersonation via TimeTrade infrastructure

Detects callback scam messages that abuse legitimate TimeTrade sending infrastructure to impersonate well-known brands like McAfee, Norton, Geek Squad, PayPal, eBay, Symantec, Best Buy, or LifeLock. The message contains purchase, payment, or subscription-related terms along with a phone number, soliciting victims to call for fraudulent support.

T1566.003T1598T1566.002T1598.003T1566
Sublimemedium

Callback Scam: Outlook groups

Detects inbound messages sent to Outlook group distribution lists (groups.outlook.com) where the body text is classified with high confidence as callback scam intent by an NLU model, while excluding cases where recipient lists are empty or entirely invalid.

T1566.003T1598T1566
Sublimemedium

Canva design with suspicious embedded link

Detects when a Canva design contains links to suspicious domains or credential harvesting sites. The rule examines embedded scripts within Canva documents for suspicious URLs and analyzes link text for malicious intent.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Canva infrastructure abuse

A fraudulent invoice/receipt found in the body of the message sent by exploiting Canva's design sharing feature.

T1566.002T1534T1656T1566.003T1598+2
Sublimemedium

Catbox.moe link from untrusted source

Detects messages containing links to catbox.moe file hosting service from senders who either aren't in highly trusted domains or failed DMARC authentication

T1566.001T1204.002T1486T1566T1598
Sublimemedium

ClickFix: Clipboard hijack lure with copy-paste-to-terminal instruction

Detects emails delivering ClickFix social engineering lures — messages that instruct the recipient to copy and paste a command into their terminal, Run dialog, or PowerShell, typically combined with a fake CAPTCHA, browser error, or verification prompt. ClickFix attacks use JavaScript to silently replace clipboard contents, causing the user to unknowingly execute a malicious command. Active campaigns in 2026 include TELEPUZ (April 2026+), which uses this technique to deliver a modular MaaS payload via a ClickFix-VIDAR chain.

T1566.001T1204.002T1486T1566T1566.002+4
Sublimehigh

ClickFunnels link infrastructure abuse

Email contains a ClickFunnels (mass mailing platform) tracking link but does not originate from ClickFunnels sending infrastructure. The myclickfunnels.com domain has been abused by threat actors to attempt credential phishing.

T1566T1566.001T1566.002T1598
Sublimehigh

Cloud storage impersonation with credential theft indicators

Detects messages impersonating cloud storage services that contain hyperlinked images leading to free file hosts, where message screenshots reveal high-confidence credential theft language and storage-related urgency tactics.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium

Cofense PhishMe phishing simulation

Identifies phishing simulations sent by Cofense PhishMe and excludes the message from live analysis.

Sublime

Commonly abused sender TLD with engaging language

Message is from a commonly abused sender TLD, contains various suspicious indicators resembling credential theft, and is unsolicited.

T1566T1566.001T1566.002T1598
Sublimemedium

Compensation review with QR code in attached EML

Detects inbound messages containing compensation-related terms (salary, bonus, merit, etc.) combined with review/change language that include EML attachments containing QR codes or barcodes in scanned documents.

T1566T1566.001T1566.002T1598
Sublimehigh

Constant Contact link infrastructure abuse

Email contains a Constant Contact (mass mailing platform) tracking link but does not originate from Constant Contact sending infrastructure. The rs6.net domain has been abused by threat actors to attempt credential phishing.

T1566T1566.001T1566.002T1598
Sublimehigh

COVID-19 themed fraud with sender and reply-to mismatch or compensation award

Detects potential COVID-19 themed BEC/Fraud scams by analyzing text within the email body for mentions of COVID-19 assistance, compensation, or awards from mismatched senders and other suspicious language.

T1566.002T1534T1656T1566T1598
Sublimemedium

Credential phishing content and link (untrusted sender)

Message contains credential theft language and a link to a credential phishing page from an unknown sender. We use Link Analysis in aggressive mode to increase our chances of scanning.

T1566T1566.001T1566.002T1598
Sublimehigh

Credential phishing language and suspicious indicators (unknown sender)

Message contains various suspicious indicators as well as engaging language resembling credential theft from an unknown sender.

T1566T1566.001T1566.002T1598
Sublimemedium

Credential phishing link (unknown sender)

Message contains a link to a credential phishing page from an unknown sender.

T1566T1566.001T1566.002T1598
Sublimehigh

Credential Phishing via Dropbox comment abuse

This rule detects Credential Phishing attacks exploiting familiar brands via Dropbox comments. These attacks originate from legitimate Dropbox infrastructure and attempt to pivot to external freemail addresses.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Credential phishing: 'Secure message' and engaging language

Body contains language resembling credential theft, and a "secure message" from an untrusted sender.

T1566T1566.001T1566.002T1598
Sublimemedium

Credential phishing: AWS Lambda URL with recipient targeting

Detects messages containing AWS Lambda URLs with the recipient's email address embedded in the fragment, indicating potential abuse of AWS Lambda services for targeted malicious activities.

T1566T1566.001T1566.002T1598
Sublimemedium

Credential Phishing: Bitcoin portfolio confirmation

Detects inbound messages that combine bitcoin/BTC terminology with portfolio or balance confirmation language, alongside at least two credential-harvesting indicators such as references to a web portal, customer ID, or password. The rule further requires the NLU classifier to flag the message with credential theft, advance fee, or BEC intent, and excludes messages from senders on high trust root domains that pass DMARC authentication.

T1566T1566.001T1566.002T1598T1534+1
Sublimemedium

Credential phishing: Blue button styled link with file-sharing template artifacts

Detects inbound messages containing styled blue button links commonly associated with generic file-sharing phishing templates, where the link does not point to legitimate Outlook domains.

T1566T1566.001T1566.002T1598T1598.003
Sublimelow

Credential phishing: DocuSign embedded image lure with no DocuSign domains in links

Detects DocuSign phishing emails with no DocuSign links, a DocuSign logo embedded in the body of the message, from a new sender.

T1566T1566.001T1566.002T1598T1598.003
Sublimehigh

Credential phishing: Email delivery failure impersonation

Detects phishing emails impersonating email system notifications claiming delivery failures, rejected messages, or email system issues requiring user action to 'fix' or 'recover' email functionality. These attacks typically claim incoming emails couldn't be delivered and direct users to malicious portals to harvest credentials.

T1566T1566.001T1566.002T1598T1598.003
Sublimehigh
PreviousPage 22 of 53Next