EXPLORE

EXPLORE DETECTIONS

🔍
1,251 detections found

Cyrillic vowel substitution in subject or display name from unknown sender

This rule detects unsolicited messages containing a mix of Cyrillic and Latin characters in the subject or sender's name while excluding emails from Russian domains and specific Google Calendar notification bounce emails.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Cyrillic vowel substitutions with suspicious subject from unknown sender

This rule detects unsolicited messages with between 1-9 links containing a suspicious subject as well as Cyrillic vowel substitutions detected in either the subject or the senders display name.

T1566T1566.001T1566.002T1598T1036+2
Sublimemedium

Deceptive Dropbox mention

Detects when a message mentions Dropbox but comes from non-Dropbox infrastructure, contains links to suspicious domains, shows discrepancies in sender identity, and contains language patterns associated with credential theft.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium

Display name and subject impersonation using recipient SLD (new sender)

The recipient domain's SLD is used in the sender's display name and in the subject to impersonate the organization.

T1566T1566.001T1566.002T1598
Sublimemedium

Display Name Emoji with Financial Symbols

Detects messages where the sender's display name contains emoji characters alongside financial symbols ($ £ € ¥ ₿) in the subject line. The sender's domain is not present in the Alexa top 1 million sites and has DMARC authentication issues.

T1566.002T1534T1656T1566.003T1598+3
Sublimelow

Display name impersonation using recipient SLD

The recipient domain's SLD is used in the sender's display name in order to impersonate the organization.

T1566T1566.001T1566.002T1598
Sublimemedium

Disposable sender email (unsolicited)

Sender is using a disposable email service and no one in our organization has ever sent them an email.

Sublimelow

DocuSign impersonation via CloudHQ links

Identifies messages containing CloudHQ share links from senders outside the CloudHQ domain who are impersonating DocuSign in either the subject line or display name.

T1566T1566.001T1566.002T1598T1534+2
Sublimemedium

DocuSign impersonation via spoofed Intuit sender

Detects messages appearing to come from Intuit domains with authentication failures while masquerading as DocuSign communications. The sender fails either SPF or DMARC verification, and includes DocuSign branding in either the subject line or display name.

T1566T1566.001T1566.002T1598T1598.003
Sublimehigh

Domain impersonation: Freemail reply-to local lookalike with financial request

This technique takes advantage of the use of free email services for the reply-to address. By incorporating the sender domain in the local part of the reply-to address, the attacker creates a visually similar appearance to a legitimate email address.

T1566T1566.001T1566.002T1598
Sublimemedium

EML attachment with credential theft language (unknown sender)

Identifies EML attachments that use credential theft language from unknown senders.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Employee impersonation with urgent request (untrusted sender)

Sender is using a display name that matches the display name of someone in your organization. Detects potential Business Email Compromise (BEC) attacks by analyzing text within email body from untrusted senders.

T1566.002T1534T1656T1566T1598
Sublimemedium

Employee impersonation: Payroll fraud

This rule detects messages impersonating employees, from unsolicited senders attempting to reroute payroll or alter payment details.

T1566.002T1534T1656T1566T1598
Sublimehigh

Encrypted Microsoft Office files from untrusted sender

Detects encrypted Microsoft Office document attachments (Word, Excel, PowerPoint, Access) from untrusted senders or high-trust senders failing DMARC authentication, which may indicate an effort to bypass security scanning.

T1566.002T1534T1656T1566.003T1598+8
Sublimemedium

Evasion: Hidden content divs from freemail sender

Detects inbound messages from freemail senders containing multiple hidden HTML div elements with specific styling properties (display:none, opacity:0, zero dimensions) that are commonly used to evade content filtering and detection systems.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Evasion: Suspicious TLD link redirecting to Wikipedia

Flags inbound messages containing links with domains registered under suspicious top-level domains that redirect to Wikipedia when analyzed. This behavior indicates the link is detecting automated sandbox or security analysis tools and serving benign content to evade detection, while likely delivering malicious content to real users.

T1566T1566.001T1566.002T1598T1036+1
Sublimelow

Evasion: Variation selectors in subject line

Detects inbound messages where invisible Unicode variation selector characters (U+FE00–U+FE0D) are inserted immediately after alphanumeric characters in the subject line. This technique is used to break up recognizable words or phrases at the character level, allowing the text to render normally to recipients while evading keyword-based or pattern-matching detection systems.

T1566T1566.001T1566.002T1598T1534+3
Sublimemedium

Extortion / Sextortion - PDF attachment leveraging breach data from freemail sender

Detects sextortion attempts leveraging breach data, including names, addresses, phone numbers and frequently using Google Maps/Bing Maps streetview images to bolster confidence and fear.

T1566.002T1534T1656T1566T1598
Sublimehigh

Extortion / sextortion (untrusted sender)

Detects extortion and sextortion attempts by analyzing the email body text from an untrusted sender.

T1486T1657T1566T1598
Sublimelow

Extortion / sextortion in attachment from untrusted sender

Detects extortion and sextortion attempts by analyzing attachment text from an untrusted sender.

T1486T1657T1566T1598
Sublimelow

Fable Security phishing simulation

Identifies phishing simulations sent by Fable and excludes the message from live analysis.

Sublime

Fake email quarantine notification

Detects phishing messages implying that emails have been delayed or blocked, prompting users to view, release, or delete pending messages.

T1566T1566.001T1566.002T1598
Sublimehigh

Fake message thread - Untrusted sender with a mismatched freemail reply-to address

Fake Message Threads or Chain Reuse is a common confidence technique exploited by threat actors to bolster credibility. This is typically used in conjunction with a reply-to address that is not the same as the sender address.

T1566.002T1534T1656T1566T1598
Sublimemedium

Fake message thread with a suspicious link and engaging language from an unknown sender

Detects fake message threads with suspicious links and financial request language

T1566T1566.001T1566.002T1598
Sublimemedium
PreviousPage 24 of 53Next