EXPLORE DETECTIONS
Link: Direct link to gamma.app document with mode parameter
Detects URLs linking to Gamma App presentation or document mode, which has been used to host malicious content due to its trusted domain status and presentation capabilities.
Link: Direct link to keap.app contact-us page
Detects URLs linking to Keap App contact us, which has been used to host malicious content due to its trusted domain status and product capabilities
Link: Direct link to limewire hosted file
Message contains exactly one link to limewire.com domain with fewer than 10 total links in the body.
Link: Direct link to riddle.com hosted showcase
Message contains a single link to a Riddle.com hosted showcase which has been observed abused for credential phishing landing
Link: Direct link to Zoom Docs from non-Zoom sender
Message includes a single link to Zoom Docs, with no other links to zoom and originates from a sender outside the Zoom organization
Link: Direct MSI download from low reputation domain
Detects messages containing links that directly download MSI files from domains not in the top 10k trusted sites and unrelated to the sender's domain.
Link: Direct POWR.io Form Builder with suspicious patterns
Detects POWR.io forms with suspicious characteristics including unverified creators, cross-domain redirects, suspended accounts, or form owners from African time zones that don't match sender domains.
Link: Display text matches subject line
Message with short body text contains a single link where the display text matches the subject line. The link is deceptive and the recipient patterns are unusual, such as the recipient's address appearing in the body or undisclosed recipients being used.
Link: Display text with excessive right-to-left mark characters
Detects links where the display text contains a high concentration of Unicode right-to-left mark characters (U+200F), which may be used to obfuscate or manipulate the visual representation of the link text to deceive recipients.
Link: Document sharing invitation template
Detects inbound messages containing text indicating a document sharing invitation with the specific phrase 'has invited you to VIEW the following document:', commonly used in malicious document sharing schemes.
Link: Document-themed link to newly registered domain
Detects inbound emails containing links whose display text mimics a document file (.xlsx, .xls, .pdf, .doc, .docx) but whose resolved destination domain was registered within the last 30 days, a strong indicator of a newly stood-up malicious infrastructure used to harvest credentials or deliver malware.
Link: Double base64-encoded URL path
Flags inbound messages containing two or more links whose URL paths contain long base64-encoded strings that, when decoded, reveal additional base64-like content. This double-encoding pattern is used to obscure the true destination of a link and evade automated URL inspection. Senders from highly trusted root domains that pass DMARC authentication are excluded.
Link: Excessive URL rewrite encoders
Detects URLs with many (excessive) encoding patterns, including multiple instances of the same encoder or four or more distinct encoders. These techniques are commonly used to obfuscate malicious URLs and evade security filters.
Link: Executable file download with suspicious message content
Detects inbound messages containing links to executable files combined with high-confidence security, financial, or credential theft content indicators, while excluding legitimate trusted domains with proper DMARC authentication.
Link: Fake forwarded message with suspicious URL in plain text
Detects inbound plain text messages (no HTML body) with no prior thread history that contain a URL and are structured as a forwarded message. The rule checks for a 'Begin forwarded message' preamble, either standalone or followed by a From field matching the sender's display name, suggesting the message may be disguising its origin or delivering malicious links via forwarded message formatting.
Link: Fake RFP/bid reference number lure
Flags inbound messages that reference an RFP, RFQ, bid, or proposal-style tracking code (e.g. REF-XXXX-XXXX) within a reply thread, where the embedded link points to a domain that differs from the sender's domain. This pattern is common in lures impersonating procurement, tender, or vendor bid notifications to drive recipients to an external link, and excludes messages from designated high-trust domains that pass DMARC.
Link: Fake secure message notification template
Detects inbound messages containing links that match a specific HTML styling fingerprint characterized by a distinctive blue color scheme (rgb(41, 88, 140)), a bottom border of 10px solid with the same blue, and a padding of 1.6em. This combination of CSS properties is associated with malicious messages designed to lure recipients into clicking embedded links.
Link: Fake video link from newly registered domain
Detects inbound messages from a sender using the local part 'support' whose domain was registered less than 30 days ago, containing a link with a path resembling a video file URL structure ('.mp4/views/').
Link: Figma design deck with credential theft language
A single link to a Figma design deck that contains credential theft language. The message comes from either a new sender, one with previously detected malicious activity, or a known sender who has not been in contact for over 30 days and has no history of benign messages.
Link: File sharing impersonation with suspicious language and sending patterns
Detects messages containing file sharing and cloud services topics combined with BEC or credential theft language, featuring links with document-related display text that lead to low-reputation domains outside the sender's domain and organization.
Link: File sharing pretext with suspicious body and link
Detects messages containing file sharing pretext with a single link to self-service creation platforms or URL shorteners, where the link display text matches the email subject and points to suspicious domains.
Link: Financial account issue with suspicious indicators
Detects messages to single recipients containing language about account or payment issues combined with suspicious links or high-confidence credential theft indicators related to financial communications.
Link: Flagged bit.ly link
Shortened link is blocked or gated by bit.ly. Indicator of malicious email.
Link: Flare-branded credential harvesting via Cloudflare tunnels
Detects inbound messages that begin with 'Flare' branding (such as FlareDoc, FlareAudio, FlareBill, FlareReport) and contain links to trycloudflare.com domains. This pattern represents a consistent actor template using Cloudflare tunnels for credential harvesting operations.