EXPLORE

EXPLORE DETECTIONS

🔍
1,251 detections found

Impersonation: Australian Federal Police with criminal case language

Detects messages impersonating the Australian Federal Police using law enforcement terminology in the subject and sender display name, combined with official correspondence language including case references, investigation details, and compliance demands.

T1566.002T1534T1656T1486T1657+3
Sublimehigh

Impersonation: Chrome Web Store policy

Detects messages impersonating Chrome Web Store policy communications, including fake extension security alerts and policy acceptance requests. Messages using observed domains and specific HTML formatting patterns typical of this impersonation.

T1566T1566.001T1566.002T1598T1598.003+1
Sublimelow

Impersonation: DMARC failure with high confidence credential theft intent

Detects DMARC failures and messages with a high confidence of credential theft

Sublimehigh

Impersonation: Employee name in subject with suspicious sender

Detects inbound messages where the sender is using a free email provider and their display name matches an known organizational display name. The sender's local part contains common organizational role keywords (mail, office, staff, executive), and the subject line matches the recipient's first name or display name, suggesting a targeted impersonation of an internal employee or executive.

T1566.002T1534T1656T1566T1598
Sublimemedium

Impersonation: Employee using fabricated identity in initial contact

Detects inbound messages that appear to be initial contact attempts where the sender uses a display name that doesn't match their email address, includes basic greetings referencing the subject line, and signs off with their display name. The message is short with no attachments, suggesting a social engineering setup for further communication.

T1566.002T1534T1656T1566T1598
Sublimehigh

Impersonation: Executive using numbered local part

Detects messages from free email providers where the sender's email address uses a pattern commonly associated with executive impersonation, containing 'chair' or 'ceo' followed by numbers in the local part.

T1566.002T1534T1656T1566T1598
Sublimehigh

Impersonation: Fake Gmail attachment

Message detects fake Gmail attachments by inspecting the body of a message for elements found within Gmail's user interface for attachment. In expected use, these elements only appears within the gmail WebUI and not within the body of message. The presence of this within message indicates a fake attachment.

T1566T1566.001T1566.002T1598T1598.003
Sublimehigh

Impersonation: Fake product discount promotion

Detects messages containing fake product discount offers that leads to a googleapis.com domain.

T1566.002T1534T1656T1566T1598
Sublimemedium

Impersonation: HR administrative center PDF password lure

Detects inbound messages impersonating an internal HR administrative center or company HR department, referencing payroll, policy, or compliance updates. Messages include a numeric case-style identifier in the subject and reference a password-protected PDF attachment, with the decryption password embedded in the body text. Sender display names often use combining diacritical marks or long numeric strings to evade detection, and sending domains are typically unrelated, compromised, or lookalike infrastructure abusing legitimate-looking company names.

T1566T1566.001T1566.002T1598T1598.003+2
Sublimemedium

Impersonation: Human Resources with link or attachment and engaging language

Detects messages impersonating HR that contain at least 1 link or 1 attachment with engaging language in the body from an untrusted sender.

T1566.002T1534T1656T1566T1566.001+1
Sublimemedium

Impersonation: Internal corporate services

Detects phishing attempts that impersonate corporate services such as HR, helpdesk, and benefits, using specific language in the subject or sender's name and containing suspicious links from low-reputation or mass-mailing domains.

T1566T1566.001T1566.002T1598T1534
Sublimehigh

Impersonation: IT Department mailbox storage alert

Detects inbound messages impersonating an internal IT Department by presenting a fake mailbox storage alert.

T1566T1566.001T1566.002T1598T1534
Sublimemedium

Impersonation: Legal firm with copyright infringement notice

Detects messages impersonating legal firms or copyright enforcement entities with extensive legal terminology, threatening language, and urgent compliance demands.

T1566.002T1534T1656T1486T1657+3
Sublimemedium

Impersonation: Recipient organization in sender display name with credential theft image

Sender display name contains the recipient's organization domain while the actual email address differs. Message includes a single image attachment with OCR-detected credential theft language referencing the recipient's domain, and has no body text.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium

Impersonation: Recipient SLD in sender's email address local part

The sender's email address local part contains the recipients SLD, the sender's domain is not a known org domain, and it's an untrusted sender.

T1566T1566.001T1566.002T1598
Sublimelow

Impersonation: Salesforce fake campaign failure notification

Detects messages impersonating Salesforce with urgent language about failed or cancelled campaigns, containing external links from first-time senders outside legitimate Salesforce domains.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium

Impersonation: SAM/SBA federal registration

Detects inbound messages impersonating SAM.gov or the Small Business Administration by matching sender display names against known spoofed naming patterns (e.g. sba-support, sam registration/renewal) or by identifying sam.gov references paired with an embedded 'renew entity' image lure. Legitimate senders from verified sba.gov, sam.gov, or other high-trust domains that pass DMARC authentication are excluded.

T1566T1566.001T1566.002T1598T1534+2
Sublimehigh

Impersonation: SharePoint reply header anomaly

Detects messages with SharePoint reply headers that lack standard reply characteristics and contain inconsistencies in thread elements and recipient patterns

T1566T1566.001T1566.002T1598T1598.003+2
Sublimemedium

Impersonation: Suspected supplier impersonation with suspicious content

This rule detects supplier impersonation by checking for: similar linked domains to the sender, non-freemail senders using freemail infrastructure, sender domains less than 90 days old, unsolicited communication or no prior interaction with the reply-to address, and a suspicious body.

T1566.002T1534T1656T1036T1027+3
Sublimehigh

Inbound message from popular service via newly observed distribution list

Detects when a message comes through a distribution list by matching on return paths containing Sender Rewrite Scheme (SRS) from a previously unknown domain sender to a single recipient who has never interacted with the organization. This method has been observed being abused by threat actors to deliver callback phishing.

T1566.003T1598T1036T1027T1566
Sublimemedium

Inline image as message with attachment or link

Using inline images in lieu of HTML or text content in the message is a known technique used to bypass content based scanning engines. We've observed this technique used to deliver malware via attachments and phish credentials.

T1566T1566.001T1566.002T1598T1036+1
Sublimelow

Investor solicitation with organization targeting

Detects messages targeting organizations with investment solicitations that specifically reference the recipient's organization by extracting the organization name and matching it to the recipient's email domain.

T1566.002T1534T1656T1566T1598
Sublimemedium

Invoice from freemail sender (unsolicited)

An invoice from a freemail sender your organization has never sent an email to before.

Sublimemedium

Invoicera infrastructure abuse

This rule is tailored to flag infrastructural abuse involving Invoicera, a SaaS-based invoicing and billing platform, which has been identified as a tool in widespread spam and credential phishing campaigns.

T1566T1566.001T1566.002T1598
Sublimemedium
PreviousPage 27 of 53Next