EXPLORE

EXPLORE DETECTIONS

🔍
1,254 detections found

Link: Invalid reply-to with recipient details in subject, body, and encoded link

Detects inbound messages with an invalid reply-to address where the recipient's domain SLD appears in the subject, the recipient's local part and domain SLD appear in the body, and the recipient's full email address is base64-encoded within a link fragment.

T1566T1566.001T1566.002T1598T1534+3
Sublimemedium

Link: Invoice or receipt from freemail sender with customer service number

An email from a freemail sender which instructs the recipient to call a fraudulent customer service number.

T1566.002T1534T1656T1566.003T1598+2
Sublimelow

Link: IPFS

Detects messages containing links that have 'ipfs' in the domain, or unanalyzed links that contain 'ipfs' in the url. IPFS has been recently observed hosting phishing sites.

T1566T1566.001T1566.002T1598T1204.002+1
Sublimemedium

Link: IPv4-mapped IPv6 address obfuscation

Detects links containing IPv4-mapped IPv6 addresses in the format [::ffff:xxxx:xxxx], commonly used to obfuscate malicious URLs and evade detection systems.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimemedium

Link: JavaScript obfuscation with Telegram bot integration

Detects links containing obfuscated JavaScript code with embedded Telegram bot tokens or API references, indicating potential data exfiltration or command and control infrastructure.

T1566T1566.001T1566.002T1598T1036+2
Sublimehigh

Link: Jensi file preview link from unsolicited sender

This detection rule matches on messaging containing at least one link to app.jensi.io from an unsolicited sender. Jensi provides a free trail enabling users to create upload documents and preview PDFs within the browser as native HTML. This services has been abused by threat actors to host landing pages directing victims to a next stage of credential phishing.

T1566.003T1598
Sublimemedium

Link: Job recruitment lure from unsolicited sender with suspicious hosting

Message contains job recruitment language with links to suspicious hosting services including free file hosts, subdomain hosts, or URL shorteners from an unsolicited sender.

T1566T1566.001T1566.002T1598
Sublimemedium

Link: Landing page with search-ms protocol redirect

Detects messages containing URL shortener links that redirect to search-ms protocol queries, which can be used to execute local file searches on Windows systems.

T1566.001T1204.002T1486T1036T1027+1
Sublimehigh

Link: Mamba 2FA phishing kit

Detects links containing base64-encoded parameters characteristic of the Mamba 2FA phishing kit, specifically looking for 'sv=o365' and '&uid=USER' patterns in redirect history.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Link: Microsoft device code authentication with suspicious indicators

Detects messages containing links with Microsoft device code authentication patterns, including verification prompts, copy code instructions, and suspicious API endpoints or antibot tokens commonly used in device code takeover attacks.

T1566T1566.001T1566.002T1598T1598.003+2
Sublimehigh

Link: Microsoft Dynamics 365 form phishing

Email body is suspicious, and links to a Microsoft Dynamics form. Known phishing tactic.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Link: Microsoft impersonation using hosted png with suspicious link

Detects messages with a link to a Microsoft hosted logo where the sender's display name and the display text of a link in the body are in all caps, and a request is being made from a first-time sender.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium

Link: Microsoft protected message with suspicious recipient patterns

Detects when a user receives a protected message (RPMSG) with the to and from headers matching or there is no TO header at all. Benign matches are possible, sender exclusions can be used to avoid matching on senders which commonly use Microsoft protected messages with suspicious recipient patterns

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Link: Mismatched free file host links with document lure

Detects inbound emails containing mismatched hyperlinks where the displayed URL references a free file hosting service but the actual destination points to another free file host or a suspicious TLD. The rule combines this with NLU classification identifying BEC or credential theft intent, along with body text patterns common to fake document/scan notifications (e.g., 'scanned from', 'shared via', 'for your review') or short, urgency-driven messages. Trusted senders with passing DMARC are excluded to reduce false positives.

T1566.002T1534T1656T1566T1566.001+1
Sublimemedium

Link: Mismatched Shopify template button href

Flags inbound messages where the sender's display name contains a space and the HTML body includes a styled table cell with a linked button whose title attribute reveals a leftover Shopify CDN file path, but the button's actual href does not point to that same path on cdn.shopify.com. This mismatch suggests a hijacked or repurposed Shopify email template being used to redirect recipients to an unintended destination. Messages from highly trusted sender domains that pass DMARC authentication are excluded.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Link: Mixed case HTTPS protocol

Detects messages containing links with mixed case 'hTTPs' protocol, a technique used to evade detection filters.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimemedium

Link: Multiple HTTP protocols in single URL

Detects messages containing links with 5 or more HTTP protocol declarations within a single URL, indicating potential URL manipulation or obfuscation techniques.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimemedium

Link: Multistage landing - Abused Adobe Acrobat hosted PDF

Detects an inbound message containing an Adobe Acrobat link that leads to a single page PDF document with suspicious indicators, including minimal text, brand logos, document viewer language, and the message is not a reply.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium

Link: Multistage landing - Abused Adobe frame.io

The detection rule matches on message groups which make use of Adobe's frame.io as a landing page. The landing page contains links which are newly registered, use free file or subdomain hosts, url shortners or when visited are phishing pages, lead to a captcha or redirect to a well-known domain, seen in evasion tactics.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Link: Multistage Landing - Abused Buildin.ai

Analyzes shared content links from buildin.ai domain that contain credential harvesting language with medium to high confidence in the display text.

T1566T1566.001T1566.002T1598
Sublimemedium

Link: Multistage landing - Abused Docusign

The detection rule matches on message groups which make use of Docusign as a landing page. The landing page contains links which are newly registered, use free file or subdomain hosts, url shortners or when visited are phishing pages, lead to a captcha or rediret to a top website.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Link: Multistage landing - Abused Google Drive

The detection rule matches on message groups which make use of Google Drive as a landing page. The landing page contains links which are newly registered, use free file or subdomain hosts, url shortners or when visited are phishing pages, lead to a captcha or redirect to a common website.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Link: Multistage landing - ClickUp abuse

Detects ClickUp documents that contain external links to suspicious domains including new domains, free file hosts, URL shorteners, or links that redirect to phishing pages or contain captchas.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimehigh

Link: Multistage landing - FreshDesk knowledge base abuse

Detects messages containing links to Freshdesk support solution pages that redirect to external domains with credential theft language, excluding legitimate Freshworks domains and organizational domains.

T1566T1566.001T1566.002T1598T1598.003
Sublimehigh
PreviousPage 32 of 53Next