EXPLORE

EXPLORE DETECTIONS

🔍
1,251 detections found

Google presentation open redirect phishing

Detects emails containing links to Google Document Presentations that either have a single page with a single external link, have been removed for Terms of Service violations, or have been deleted.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Google services using g.co shortlinks

Identifies messages from authenticated Google domains containing g.co shortened URLs with a subdomain in either the message body links or thread text.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Google share notification with suspicious comments

This detection rule matches on messages which contain suspicious language within the comments of a Google share notification. Suspicious content within the comments section of the notification is deemed as email abbreviations such as FW:, FWD:, and RE: or by containing words that reference a file share.

T1566T1566.001T1566.002T1598T1534
Sublimehigh

Hardbacon infrastructure abuse

Hardbacon is a defunct Canadian budgeting app. Attackers have been observed using their marketing platform to send credential phishing messages.

T1566T1566.001T1566.002T1598T1036+2
Sublimehigh

Headers: Fake in-reply-to with wildcard sender and missing thread context

Detects messages claiming to be replies with In-Reply-To headers but lacking previous thread context, sent from addresses containing multiple wildcard characters in the local part.

T1566.002T1534T1656T1566T1566.001+3
Sublimehigh

Headers: Invalid recipient domain with mismatched reply-to from new sender

Message sent to an invalid recipient domain with a reply-to address that differs from the sender address, originating from a new sender.

T1566.002T1534T1656T1566T1566.001+3
Sublimemedium

Headers: iOS/iPadOS mailer with invalid build number

Detects emails claiming to be sent from an iOS or iPadOS device that contain an invalid build number.

T1566.002T1534T1656T1566T1566.001+5
Sublimemedium

Headers: Outlook Express mailer

Detects emails claiming to be sent from Outlook Express, which is a legacy email client that is no longer supported or commonly used.

T1566.002T1534T1656T1566T1566.001+5
Sublimemedium

Headers: risky-recover-production message ID

Detects messages containing 'risky-recover-production' in the message ID header, which may indicate suspicious or malicious activity.

T1566T1036T1027
Sublimelow

Headers: Self-sender using Microsoft CompAuth bypass with credential theft content

Detects messages sent to self or invalid domains containing credential theft content that bypass Microsoft's CompAuth while failing both SPF and DMARC authentication checks.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Headers: System account impersonation with empty sender address

Detects messages with an empty sender email address and a display name impersonating system accounts like mailer-daemon, postmaster, or administrator, but lacking legitimate bounce back content as determined by natural language processing.

T1566.002T1534T1656T1566T1566.001+1
Sublimemedium

Headers: X-Source-Auth mismatch with mismatched reply-to domain

Detects messages where the X-Source-Auth header value doesn't match the sender's email address and the reply-to domain differs from the sender's domain, indicating potential sender spoofing or impersonation.

T1566.002T1534T1656T1566T1598
Sublimehigh

Headers: Zimbra mailer from a non-supported OS version

Detects Zimbra originated emails sent from non-supported Windows versions. Observed in widespread HTML credential phishing campaigns.

Sublimemedium

Honorific greeting BEC attempt with sender and reply-to mismatch

Detects generic BEC/Fraud scams by analyzing text within the email body from mismatched senders with other suspicious indicators.

T1566.002T1534T1656T1566T1598
Sublimelow

HoxHunt phishing simulation

Identifies phishing simulations sent by HoxHunt and excludes the message from live analysis.

Sublime

HR impersonation via e-sign agreement comment

This rule inspects messages originating from legitimate e-signature platform infrastructure, with engaging language in the body that matches HR Impersonation criteria.

T1566.002T1534T1656T1566T1566.001+4
Sublimehigh

HTML content with print styling and credential theft language

Detects messages containing specific HTML print styling directives combined with high or medium confidence credential theft language, often used to format malicious content for printing or display.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

HTML smuggling containing recipient email address

HTML attachment (or HTML attachment in attached email) is small and contains a recipients email address.

T1566T1566.001T1566.002T1598T1204.002+4
Sublimemedium

HTML smuggling with atob in message body

Detects if the email body HTML contains the document write or insertAdjacentHTML method and atob function call. This technique has been observed leading to credential phishing.

T1566T1566.001T1566.002T1598T1204.002+1
Sublimehigh

HTML: Bidirectional (BIDI) HTML override with right to left obfuscation

Body HTML contains multiple instances of right-to-left (RTL) text direction override markup, which can be used to visually manipulate text display and potentially bypass common strings checks.

T1566.002T1534T1656T1566T1566.001+4
Sublimemedium

HTML: Template placeholders or recipient email in element class attributes

Detects inbound messages where HTML element class attributes contain either unfilled template placeholders (e.g., {email}, {RECIPIENT_EMAIL}, {domain}) or the recipient's actual email address — optionally wrapped in curly braces. This pattern indicates a bulk-sending infrastructure that failed to substitute personalization tokens, or one that embeds recipient identifiers directly into HTML class names for tracking or evasion purposes. Observed samples follow a consistent pattern: subjects contain numeric identifiers flanking the recipient's email address, and senders vary across unrelated domains, suggesting a coordinated operation targeting multiple organizations including technology and fitness brands.

T1566T1566.001T1566.002T1598T1534+3
Sublimehigh

Huntress phishing simulation

Identifies phishing simulations sent by Huntress and excludes the message from live analysis.

Sublime

Image as content with a link to an open redirect

Body contains little, no, or only disclaimer text, an image, and a link to an open redirect.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimehigh

Impersonation using recipient domain (untrusted sender)

The recipient's domain is used in the sender's display name in order to impersonate the organization. The impersonation has been observed to use both the recipient's full email address, as well as just the domain.

T1566T1566.001T1566.002T1598
Sublimemedium
PreviousPage 26 of 53Next