EXPLORE DETECTIONS
Google presentation open redirect phishing
Detects emails containing links to Google Document Presentations that either have a single page with a single external link, have been removed for Terms of Service violations, or have been deleted.
Google services using g.co shortlinks
Identifies messages from authenticated Google domains containing g.co shortened URLs with a subdomain in either the message body links or thread text.
Google share notification with suspicious comments
This detection rule matches on messages which contain suspicious language within the comments of a Google share notification. Suspicious content within the comments section of the notification is deemed as email abbreviations such as FW:, FWD:, and RE: or by containing words that reference a file share.
Hardbacon infrastructure abuse
Hardbacon is a defunct Canadian budgeting app. Attackers have been observed using their marketing platform to send credential phishing messages.
Headers: Fake in-reply-to with wildcard sender and missing thread context
Detects messages claiming to be replies with In-Reply-To headers but lacking previous thread context, sent from addresses containing multiple wildcard characters in the local part.
Headers: Invalid recipient domain with mismatched reply-to from new sender
Message sent to an invalid recipient domain with a reply-to address that differs from the sender address, originating from a new sender.
Headers: iOS/iPadOS mailer with invalid build number
Detects emails claiming to be sent from an iOS or iPadOS device that contain an invalid build number.
Headers: Outlook Express mailer
Detects emails claiming to be sent from Outlook Express, which is a legacy email client that is no longer supported or commonly used.
Headers: risky-recover-production message ID
Detects messages containing 'risky-recover-production' in the message ID header, which may indicate suspicious or malicious activity.
Headers: Self-sender using Microsoft CompAuth bypass with credential theft content
Detects messages sent to self or invalid domains containing credential theft content that bypass Microsoft's CompAuth while failing both SPF and DMARC authentication checks.
Headers: System account impersonation with empty sender address
Detects messages with an empty sender email address and a display name impersonating system accounts like mailer-daemon, postmaster, or administrator, but lacking legitimate bounce back content as determined by natural language processing.
Headers: X-Source-Auth mismatch with mismatched reply-to domain
Detects messages where the X-Source-Auth header value doesn't match the sender's email address and the reply-to domain differs from the sender's domain, indicating potential sender spoofing or impersonation.
Headers: Zimbra mailer from a non-supported OS version
Detects Zimbra originated emails sent from non-supported Windows versions. Observed in widespread HTML credential phishing campaigns.
Honorific greeting BEC attempt with sender and reply-to mismatch
Detects generic BEC/Fraud scams by analyzing text within the email body from mismatched senders with other suspicious indicators.
HoxHunt phishing simulation
Identifies phishing simulations sent by HoxHunt and excludes the message from live analysis.
HR impersonation via e-sign agreement comment
This rule inspects messages originating from legitimate e-signature platform infrastructure, with engaging language in the body that matches HR Impersonation criteria.
HTML content with print styling and credential theft language
Detects messages containing specific HTML print styling directives combined with high or medium confidence credential theft language, often used to format malicious content for printing or display.
HTML smuggling containing recipient email address
HTML attachment (or HTML attachment in attached email) is small and contains a recipients email address.
HTML smuggling with atob in message body
Detects if the email body HTML contains the document write or insertAdjacentHTML method and atob function call. This technique has been observed leading to credential phishing.
HTML: Bidirectional (BIDI) HTML override with right to left obfuscation
Body HTML contains multiple instances of right-to-left (RTL) text direction override markup, which can be used to visually manipulate text display and potentially bypass common strings checks.
HTML: Template placeholders or recipient email in element class attributes
Detects inbound messages where HTML element class attributes contain either unfilled template placeholders (e.g., {email}, {RECIPIENT_EMAIL}, {domain}) or the recipient's actual email address — optionally wrapped in curly braces. This pattern indicates a bulk-sending infrastructure that failed to substitute personalization tokens, or one that embeds recipient identifiers directly into HTML class names for tracking or evasion purposes. Observed samples follow a consistent pattern: subjects contain numeric identifiers flanking the recipient's email address, and senders vary across unrelated domains, suggesting a coordinated operation targeting multiple organizations including technology and fitness brands.
Huntress phishing simulation
Identifies phishing simulations sent by Huntress and excludes the message from live analysis.
Image as content with a link to an open redirect
Body contains little, no, or only disclaimer text, an image, and a link to an open redirect.
Impersonation using recipient domain (untrusted sender)
The recipient's domain is used in the sender's display name in order to impersonate the organization. The impersonation has been observed to use both the recipient's full email address, as well as just the domain.