EXPLORE

EXPLORE DETECTIONS

🔍
1,254 detections found

Link: Direct link to gamma.app document with mode parameter

Detects URLs linking to Gamma App presentation or document mode, which has been used to host malicious content due to its trusted domain status and presentation capabilities.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimemedium

Link: Direct link to keap.app contact-us page

Detects URLs linking to Keap App contact us, which has been used to host malicious content due to its trusted domain status and product capabilities

T1566T1566.001T1566.002T1598T1204.002+3
Sublimemedium

Link: Direct link to limewire hosted file

Message contains exactly one link to limewire.com domain with fewer than 10 total links in the body.

T1566.001T1204.002T1486
Sublimehigh

Link: Direct link to riddle.com hosted showcase

Message contains a single link to a Riddle.com hosted showcase which has been observed abused for credential phishing landing

T1566T1566.001T1566.002T1598
Sublimemedium

Link: Direct link to Zoom Docs from non-Zoom sender

Message includes a single link to Zoom Docs, with no other links to zoom and originates from a sender outside the Zoom organization

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium

Link: Direct MSI download from low reputation domain

Detects messages containing links that directly download MSI files from domains not in the top 10k trusted sites and unrelated to the sender's domain.

T1566.001T1204.002T1486T1036T1027
Sublimelow

Link: Direct POWR.io Form Builder with suspicious patterns

Detects POWR.io forms with suspicious characteristics including unverified creators, cross-domain redirects, suspended accounts, or form owners from African time zones that don't match sender domains.

T1566T1566.001T1566.002T1598T1566.003
Sublimemedium

Link: Display text matches subject line

Message with short body text contains a single link where the display text matches the subject line. The link is deceptive and the recipient patterns are unusual, such as the recipient's address appearing in the body or undisclosed recipients being used.

T1566.002T1534T1656T1566T1566.001+3
Sublimemedium

Link: Display text with excessive right-to-left mark characters

Detects links where the display text contains a high concentration of Unicode right-to-left mark characters (U+200F), which may be used to obfuscate or manipulate the visual representation of the link text to deceive recipients.

T1566T1566.001T1566.002T1598T1036+1
Sublimelow

Link: Document sharing invitation template

Detects inbound messages containing text indicating a document sharing invitation with the specific phrase 'has invited you to VIEW the following document:', commonly used in malicious document sharing schemes.

T1566T1566.001T1566.002T1598
Sublimehigh

Link: Document-themed link to newly registered domain

Detects inbound emails containing links whose display text mimics a document file (.xlsx, .xls, .pdf, .doc, .docx) but whose resolved destination domain was registered within the last 30 days, a strong indicator of a newly stood-up malicious infrastructure used to harvest credentials or deliver malware.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimemedium

Link: Double base64-encoded URL path

Flags inbound messages containing two or more links whose URL paths contain long base64-encoded strings that, when decoded, reveal additional base64-like content. This double-encoding pattern is used to obscure the true destination of a link and evade automated URL inspection. Senders from highly trusted root domains that pass DMARC authentication are excluded.

T1566T1566.001T1566.002T1598T1027+2
Sublimemedium

Link: Excessive URL rewrite encoders

Detects URLs with many (excessive) encoding patterns, including multiple instances of the same encoder or four or more distinct encoders. These techniques are commonly used to obfuscate malicious URLs and evade security filters.

T1566T1566.001T1566.002T1598T1204.002+4
Sublimehigh

Link: Executable file download with suspicious message content

Detects inbound messages containing links to executable files combined with high-confidence security, financial, or credential theft content indicators, while excluding legitimate trusted domains with proper DMARC authentication.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimehigh

Link: Fake forwarded message with suspicious URL in plain text

Detects inbound plain text messages (no HTML body) with no prior thread history that contain a URL and are structured as a forwarded message. The rule checks for a 'Begin forwarded message' preamble, either standalone or followed by a From field matching the sender's display name, suggesting the message may be disguising its origin or delivering malicious links via forwarded message formatting.

T1566T1566.001T1566.002T1598T1534+3
Sublimemedium

Link: Fake RFP/bid reference number lure

Flags inbound messages that reference an RFP, RFQ, bid, or proposal-style tracking code (e.g. REF-XXXX-XXXX) within a reply thread, where the embedded link points to a domain that differs from the sender's domain. This pattern is common in lures impersonating procurement, tender, or vendor bid notifications to drive recipients to an external link, and excludes messages from designated high-trust domains that pass DMARC.

T1566T1566.001T1566.002T1598T1534+2
Sublimemedium

Link: Fake secure message notification template

Detects inbound messages containing links that match a specific HTML styling fingerprint characterized by a distinctive blue color scheme (rgb(41, 88, 140)), a bottom border of 10px solid with the same blue, and a padding of 1.6em. This combination of CSS properties is associated with malicious messages designed to lure recipients into clicking embedded links.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Link: Fake video link from newly registered domain

Detects inbound messages from a sender using the local part 'support' whose domain was registered less than 30 days ago, containing a link with a path resembling a video file URL structure ('.mp4/views/').

T1566.001T1204.002T1486T1566T1598
Sublimemedium

Link: Figma design deck with credential theft language

A single link to a Figma design deck that contains credential theft language. The message comes from either a new sender, one with previously detected malicious activity, or a known sender who has not been in contact for over 30 days and has no history of benign messages.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Link: File sharing impersonation with suspicious language and sending patterns

Detects messages containing file sharing and cloud services topics combined with BEC or credential theft language, featuring links with document-related display text that lead to low-reputation domains outside the sender's domain and organization.

T1566.002T1534T1656T1566T1566.001+2
Sublimemedium

Link: File sharing pretext with suspicious body and link

Detects messages containing file sharing pretext with a single link to self-service creation platforms or URL shorteners, where the link display text matches the email subject and points to suspicious domains.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Link: Financial account issue with suspicious indicators

Detects messages to single recipients containing language about account or payment issues combined with suspicious links or high-confidence credential theft indicators related to financial communications.

T1566T1566.001T1566.002T1598
Sublimemedium

Link: Flagged bit.ly link

Shortened link is blocked or gated by bit.ly. Indicator of malicious email.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Link: Flare-branded credential harvesting via Cloudflare tunnels

Detects inbound messages that begin with 'Flare' branding (such as FlareDoc, FlareAudio, FlareBill, FlareReport) and contain links to trycloudflare.com domains. This pattern represents a consistent actor template using Cloudflare tunnels for credential harvesting operations.

T1566T1566.001T1566.002T1598
Sublimehigh
PreviousPage 30 of 53Next