EXPLORE DETECTIONS
Cyrillic vowel substitution in subject or display name from unknown sender
This rule detects unsolicited messages containing a mix of Cyrillic and Latin characters in the subject or sender's name while excluding emails from Russian domains and specific Google Calendar notification bounce emails.
Cyrillic vowel substitutions with suspicious subject from unknown sender
This rule detects unsolicited messages with between 1-9 links containing a suspicious subject as well as Cyrillic vowel substitutions detected in either the subject or the senders display name.
Deceptive Dropbox mention
Detects when a message mentions Dropbox but comes from non-Dropbox infrastructure, contains links to suspicious domains, shows discrepancies in sender identity, and contains language patterns associated with credential theft.
Display name and subject impersonation using recipient SLD (new sender)
The recipient domain's SLD is used in the sender's display name and in the subject to impersonate the organization.
Display Name Emoji with Financial Symbols
Detects messages where the sender's display name contains emoji characters alongside financial symbols ($ £ € ¥ ₿) in the subject line. The sender's domain is not present in the Alexa top 1 million sites and has DMARC authentication issues.
Display name impersonation using recipient SLD
The recipient domain's SLD is used in the sender's display name in order to impersonate the organization.
Disposable sender email (unsolicited)
Sender is using a disposable email service and no one in our organization has ever sent them an email.
DocuSign impersonation via CloudHQ links
Identifies messages containing CloudHQ share links from senders outside the CloudHQ domain who are impersonating DocuSign in either the subject line or display name.
DocuSign impersonation via spoofed Intuit sender
Detects messages appearing to come from Intuit domains with authentication failures while masquerading as DocuSign communications. The sender fails either SPF or DMARC verification, and includes DocuSign branding in either the subject line or display name.
Domain impersonation: Freemail reply-to local lookalike with financial request
This technique takes advantage of the use of free email services for the reply-to address. By incorporating the sender domain in the local part of the reply-to address, the attacker creates a visually similar appearance to a legitimate email address.
EML attachment with credential theft language (unknown sender)
Identifies EML attachments that use credential theft language from unknown senders.
Employee impersonation with urgent request (untrusted sender)
Sender is using a display name that matches the display name of someone in your organization. Detects potential Business Email Compromise (BEC) attacks by analyzing text within email body from untrusted senders.
Employee impersonation: Payroll fraud
This rule detects messages impersonating employees, from unsolicited senders attempting to reroute payroll or alter payment details.
Encrypted Microsoft Office files from untrusted sender
Detects encrypted Microsoft Office document attachments (Word, Excel, PowerPoint, Access) from untrusted senders or high-trust senders failing DMARC authentication, which may indicate an effort to bypass security scanning.
Evasion: Hidden content divs from freemail sender
Detects inbound messages from freemail senders containing multiple hidden HTML div elements with specific styling properties (display:none, opacity:0, zero dimensions) that are commonly used to evade content filtering and detection systems.
Evasion: Suspicious TLD link redirecting to Wikipedia
Flags inbound messages containing links with domains registered under suspicious top-level domains that redirect to Wikipedia when analyzed. This behavior indicates the link is detecting automated sandbox or security analysis tools and serving benign content to evade detection, while likely delivering malicious content to real users.
Evasion: Variation selectors in subject line
Detects inbound messages where invisible Unicode variation selector characters (U+FE00–U+FE0D) are inserted immediately after alphanumeric characters in the subject line. This technique is used to break up recognizable words or phrases at the character level, allowing the text to render normally to recipients while evading keyword-based or pattern-matching detection systems.
Extortion / Sextortion - PDF attachment leveraging breach data from freemail sender
Detects sextortion attempts leveraging breach data, including names, addresses, phone numbers and frequently using Google Maps/Bing Maps streetview images to bolster confidence and fear.
Extortion / sextortion (untrusted sender)
Detects extortion and sextortion attempts by analyzing the email body text from an untrusted sender.
Extortion / sextortion in attachment from untrusted sender
Detects extortion and sextortion attempts by analyzing attachment text from an untrusted sender.
Fable Security phishing simulation
Identifies phishing simulations sent by Fable and excludes the message from live analysis.
Fake email quarantine notification
Detects phishing messages implying that emails have been delayed or blocked, prompting users to view, release, or delete pending messages.
Fake message thread - Untrusted sender with a mismatched freemail reply-to address
Fake Message Threads or Chain Reuse is a common confidence technique exploited by threat actors to bolster credibility. This is typically used in conjunction with a reply-to address that is not the same as the sender address.
Fake message thread with a suspicious link and engaging language from an unknown sender
Detects fake message threads with suspicious links and financial request language