EXPLORE DETECTIONS
Impersonation: Australian Federal Police with criminal case language
Detects messages impersonating the Australian Federal Police using law enforcement terminology in the subject and sender display name, combined with official correspondence language including case references, investigation details, and compliance demands.
Impersonation: Chrome Web Store policy
Detects messages impersonating Chrome Web Store policy communications, including fake extension security alerts and policy acceptance requests. Messages using observed domains and specific HTML formatting patterns typical of this impersonation.
Impersonation: DMARC failure with high confidence credential theft intent
Detects DMARC failures and messages with a high confidence of credential theft
Impersonation: Employee name in subject with suspicious sender
Detects inbound messages where the sender is using a free email provider and their display name matches an known organizational display name. The sender's local part contains common organizational role keywords (mail, office, staff, executive), and the subject line matches the recipient's first name or display name, suggesting a targeted impersonation of an internal employee or executive.
Impersonation: Employee using fabricated identity in initial contact
Detects inbound messages that appear to be initial contact attempts where the sender uses a display name that doesn't match their email address, includes basic greetings referencing the subject line, and signs off with their display name. The message is short with no attachments, suggesting a social engineering setup for further communication.
Impersonation: Executive using numbered local part
Detects messages from free email providers where the sender's email address uses a pattern commonly associated with executive impersonation, containing 'chair' or 'ceo' followed by numbers in the local part.
Impersonation: Fake Gmail attachment
Message detects fake Gmail attachments by inspecting the body of a message for elements found within Gmail's user interface for attachment. In expected use, these elements only appears within the gmail WebUI and not within the body of message. The presence of this within message indicates a fake attachment.
Impersonation: Fake product discount promotion
Detects messages containing fake product discount offers that leads to a googleapis.com domain.
Impersonation: HR administrative center PDF password lure
Detects inbound messages impersonating an internal HR administrative center or company HR department, referencing payroll, policy, or compliance updates. Messages include a numeric case-style identifier in the subject and reference a password-protected PDF attachment, with the decryption password embedded in the body text. Sender display names often use combining diacritical marks or long numeric strings to evade detection, and sending domains are typically unrelated, compromised, or lookalike infrastructure abusing legitimate-looking company names.
Impersonation: Human Resources with link or attachment and engaging language
Detects messages impersonating HR that contain at least 1 link or 1 attachment with engaging language in the body from an untrusted sender.
Impersonation: Internal corporate services
Detects phishing attempts that impersonate corporate services such as HR, helpdesk, and benefits, using specific language in the subject or sender's name and containing suspicious links from low-reputation or mass-mailing domains.
Impersonation: IT Department mailbox storage alert
Detects inbound messages impersonating an internal IT Department by presenting a fake mailbox storage alert.
Impersonation: Legal firm with copyright infringement notice
Detects messages impersonating legal firms or copyright enforcement entities with extensive legal terminology, threatening language, and urgent compliance demands.
Impersonation: Recipient organization in sender display name with credential theft image
Sender display name contains the recipient's organization domain while the actual email address differs. Message includes a single image attachment with OCR-detected credential theft language referencing the recipient's domain, and has no body text.
Impersonation: Recipient SLD in sender's email address local part
The sender's email address local part contains the recipients SLD, the sender's domain is not a known org domain, and it's an untrusted sender.
Impersonation: Salesforce fake campaign failure notification
Detects messages impersonating Salesforce with urgent language about failed or cancelled campaigns, containing external links from first-time senders outside legitimate Salesforce domains.
Impersonation: SAM/SBA federal registration
Detects inbound messages impersonating SAM.gov or the Small Business Administration by matching sender display names against known spoofed naming patterns (e.g. sba-support, sam registration/renewal) or by identifying sam.gov references paired with an embedded 'renew entity' image lure. Legitimate senders from verified sba.gov, sam.gov, or other high-trust domains that pass DMARC authentication are excluded.
Impersonation: SharePoint reply header anomaly
Detects messages with SharePoint reply headers that lack standard reply characteristics and contain inconsistencies in thread elements and recipient patterns
Impersonation: Suspected supplier impersonation with suspicious content
This rule detects supplier impersonation by checking for: similar linked domains to the sender, non-freemail senders using freemail infrastructure, sender domains less than 90 days old, unsolicited communication or no prior interaction with the reply-to address, and a suspicious body.
Inbound message from popular service via newly observed distribution list
Detects when a message comes through a distribution list by matching on return paths containing Sender Rewrite Scheme (SRS) from a previously unknown domain sender to a single recipient who has never interacted with the organization. This method has been observed being abused by threat actors to deliver callback phishing.
Inline image as message with attachment or link
Using inline images in lieu of HTML or text content in the message is a known technique used to bypass content based scanning engines. We've observed this technique used to deliver malware via attachments and phish credentials.
Investor solicitation with organization targeting
Detects messages targeting organizations with investment solicitations that specifically reference the recipient's organization by extracting the organization name and matching it to the recipient's email domain.
Invoice from freemail sender (unsolicited)
An invoice from a freemail sender your organization has never sent an email to before.
Invoicera infrastructure abuse
This rule is tailored to flag infrastructural abuse involving Invoicera, a SaaS-based invoicing and billing platform, which has been identified as a tool in widespread spam and credential phishing campaigns.