EXPLORE

EXPLORE DETECTIONS

🔍
1,251 detections found

Credential phishing: Engaging language and other indicators (untrusted sender)

Message contains various suspicious indicators as well as engaging language resembling credential theft from an untrusted sender.

T1566T1566.001T1566.002T1598
Sublimemedium

Credential phishing: Engaging language with IPFS link

Body contains credential theft indicators, and contains a link to an IPFS site. IPFS has been recently observed hosting phishing sites.

T1566T1566.001T1566.002T1598
Sublimehigh

Credential phishing: Fake card notification with tracking lure

Detects inbound messages using fake credit card delivery or approval themes with credential theft intent. Messages contain card-related language paired with delivery or status indicators, and tracking call-to-action links.

T1566T1566.001T1566.002T1598
Sublimemedium

Credential phishing: Fake password expiration from new and unsolicited sender

This rule looks for password expiration verbiage in the subject and body. Requiring between 1 - 9 links, a short body, and NLU in addition to statically specified term anchors. High trust senders are also negated.

T1566T1566.001T1566.002T1598
Sublimemedium

Credential phishing: Fake storage alerts (unsolicited)

This rule targets credential phishing attempts disguised as storage space alerts, activating for inbound emails with specific storage-related keywords and evaluating sender trustworthiness and history.

T1566T1566.001T1566.002T1598
Sublimemedium

Credential phishing: Financial lure via ActiveCampaign infrastructure

Detects inbound phishing messages sent via ActiveCampaign using identifiable infrastructure fingerprints and hidden boilerplate text. Covers a wide range of lure themes including credit cards, loans, deposits, account updates, and vague document or verification prompts. Requires NLU Financial Communications topic classification.

T1566T1566.001T1566.002T1598
Sublimemedium

Credential phishing: Generic document share with unicode and proceedural greeting template

Detects messages that incorporate recipient-specific information (email domain, local part, domain elements or mailbox elements) alongside document-themed Unicode symbols and keywords. The rule identifies various targeting patterns including greeting-based personalization, attention-grabbing prefixes and multiple recipient elements. It also catches broken template attacks where recipient placeholders remain visible.

T1566.002T1534T1656T1566T1566.001+3
Sublimelow

Credential phishing: Generic document sharing

Detects credential phishing attempts using generic document sharing language where the sender claims to have sent a document for review, but the link doesn't point to legitimate file sharing services.

T1566T1566.001T1566.002T1598T1534+3
Sublimemedium

Credential phishing: Hyper-linked image leading to free file host

This rule detects messages with short or null bodies, where all attachments are images, and the image is hyperlinking to a free_file_host from an unsolicited and untrusted sender.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Credential phishing: Image as content, short or no body contents

This rule identifies incoming messages with minimal links, all image attachments and either empty, brief or the body text is only a warning banner/disclaimer. It also checks for truncated PNG images or logos in addition to high-confidence credit theft intentions.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Credential phishing: Onedrive impersonation

This rule detects messages impersonating Microsoft's OneDrive service with medium to high credential theft language in the current thread. The subject is inspected for one drive language, with additional checks for free_subdomain hosted links, additional suspicious subject language or suspicious display text language.

T1566T1566.001T1566.002T1598T1598.003
Sublimehigh

Credential phishing: Personalized document signing request

Detects messages with a single recipient and personalized document signing requests. The rule identifies messages referencing DocuSign or document-related language, combined with domain-specific greeting patterns or known malicious HTML artifacts associated with fraudulent signing invitations from entities such as STAR Capital or Agito AS.

T1566T1566.001T1566.002T1598T1534+2
Sublimemedium

Credential phishing: Re-Authentication lure

Contains suspicious links and server-related terminology, requesting email account reauthentication with language targeting recipient credentials.

T1566T1566.001T1566.002T1598T1598.003
Sublimehigh

Credential phishing: Suspicious e-sign agreement document notification

Detects phishing attempts disguised as e-signature requests, characterized by common document sharing phrases, unusual HTML padding, and suspicious link text.

T1566T1566.001T1566.002T1598
Sublimemedium

Credential Phishing: Suspicious language, link, recipients and other indicators

The rule flags inbound messages with no visible recipients, contain all-caps text, and include links from certain free hosts. It also checks for signs of credential theft using machine learning classifiers and is from an untrusted sender.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Credential phishing: Suspicious subject with urgent financial request and link

This rule inspects messages where the subject is suspicious with less than 5 links and a relatively short body. Natural Language Understanding is being used to identify the inclusion of a financial, request, urgency and org entity from an unsolicited sender.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium

Credential phishing: Tax form impersonation with payment request

Detects messages impersonating tax-related communications that contain payment requests and PDF links, excluding legitimate tax service providers. The rule identifies tax terminology combined with payment solicitation language and PDF link references, which is a common pattern in tax season scams.

T1566.002T1534T1656T1566T1566.001+2
Sublimemedium

Credential Phishing: W-2 lure with inline SVG Windows logo

Detects inbound messages containing a link with W-2 display text and an inline SVG constructed from four colored rectangles approximating the Microsoft Windows logo. Threat actors use hand-crafted SVG elements rather than image attachments to bypass image-based detection and render a convincing Windows or Microsoft brand impersonation directly in the email body. The color matching uses fuzzy hex ranges to account for minor variations across campaigns.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Credential theft with 'safe content' deception and social engineering topics

Detects messages containing credential theft language combined with social engineering topics like secure messages, notifications, or authentication alerts. The rule specifically identifies emails that deceptively claim to be from a 'safe sender' or contain 'safe content' in the first line, which is a common tactic used to bypass security filters and gain user trust.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Credential theft: Gophish abuse with hidden tracking image

Detects messages containing hidden tracking images with display:none style and tracking parameters in the source URL, commonly used for user tracking and engagement monitoring.

T1566T1036T1027
Sublimehigh

Credential theft: JavaScript date manipulation in HTML body

Detects inbound messages containing JavaScript that uses date manipulation functions (setDate/getDate) within script tags, combined with credential theft intent identified by NLU classification. This pattern is commonly used to evade detection by dynamically altering content or expiry logic while targeting user credentials.

T1566T1566.001T1566.002T1598T1036+2
Sublimemedium

Current event: CrowdStrike impersonation

Discovery rule for messages which are leveraging the CrowdStrike defect generated on Jul 19th 2024 which caused wide spread outages.

T1566.002T1598.003T1583.001T1566T1598
Sublimelow

Cutt.ly hosting link

The message contains a Cutt.ly link, which can be used to host malicious content.

Sublimelow

CVE-2023-5631 - Roundcube Webmail XSS via crafted SVG

Body HTML contains an exploit for CVE-2023-5631, a vulnerability in Roundcube Webmail that allows stored XSS via an HTML e-mail message with a crafted SVG document.

T1566.001T1204.002T1486T1036T1027+3
Sublimecritical
PreviousPage 23 of 53Next