EXPLORE

EXPLORE DETECTIONS

🔍
1,254 detections found

Link: Recipient domain in URL path

This rule detects URL paths which contain the recipient SLD multiple times. This has been observed in multiple credential phishing campaigns with MFA enrollment themed lures.

T1566T1566.001T1566.002T1598T1583.001
Sublimehigh

Link: Recipient email address in 'eta' parameter

Detects links containing the recipient's email address in the 'eta' query parameter, a technique commonly used to personalize malicious links and track targets.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Link: Referrer anonymization service from untrusted sender

Detects messages containing links that utilize a referrer anonymization service. The rule examines senders who are either not in a trusted domain list or have failed DMARC authentication despite being from a trusted domain.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Link: Remittance payment request with timeline template

Detects messages containing references to business days and account information with links containing 'remittance' in the URL path, commonly used in financial fraud schemes. This rule is looking at a specific template we're seeing in use with a expedited timeline.

T1566.002T1534T1656T1566T1566.001+1
Sublimemedium

Link: RFI document reference pattern in display text

Detects links with display text containing RFI (Request for Information) document reference patterns using format RFI-###-###-###, commonly used in construction and procurement fraud schemes.

T1566.002T1534T1656T1566T1598
Sublimemedium

Link: Romance/Sexual Language With Suspicious Link

Detects messages containing romantic or adult-themed language, combined with links to newly registered domains or suspicious reply-to addresses.

T1566T1598
Sublimelow

Link: RTL text reversal with recipient email in URL

Flags inbound messages containing anchor tags styled with 'direction:rtl' to visually reverse displayed text—an evasion tactic against text-based scanning—where the underlying link URL also contains the recipient's email address, a common personalization technique used to track or validate targets in phishing links.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Link: ScreenConnect installer with suspicious relay domain

Detects when a link leads to a ConnectWise ScreenConnect installer and references a relay domain that doesn't match sender or organizational domains.

T1566.001T1204.002T1486T1036T1027+2
Sublimehigh

Link: ScreenConnect remote access tool delivery with unattended guest access

Detects inbound messages containing ScreenConnect links that direct recipients to download a Guest Access installer (.msi or .exe). The links use ScreenConnect's integration parameters specifying Guest session type and Access mode, indicating unsolicited remote access tool deployment. Lures observed include fake invoices, payment proofs, event invitations, and social gathering notifications — often urging recipients to open the link on a Windows desktop and install the downloaded file.

T1566.001T1204.002T1486T1566T1598
Sublimehigh

Link: Scribd fullscreen link from suspicious sender

Detects messages containing Scribd links with the fullscreen parameter from senders with no prior benign communication or recent history.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Link: Secure SharePoint file share from new or unusual sender

This ASR rule detects the use of secure SharePoint links which require recipient verifcation before allowing access to the shared file. This has been observed as a method of evading automated analysis of the shared files' content.

T1566T1566.001T1566.002T1598T1036+1
Sublimelow

Link: Self-sender credential theft with configuration placeholder

Detects messages where the sender and recipient are the same address, containing credential theft language and links with configuration placeholder text indicating a phishing lure.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Link: Self-sender with IP geolocation check and suspicious link behavior

Detects messages where the sender and recipient are the same address that access IP geolocation services (ipinfo.io) and exhibit suspicious behavior, such as randomization scripting or confirmed credential harvesting indicators.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Link: Self-sender with sender org in subject and credential theft indicator

Detects messages where the sender and recipient are the same email address, containing organizational names in the subject, credential theft language with high confidence, and suspicious links. These messages often bypass traditional security measures by appearing to come from the recipient themselves.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Link: Self-sent message with quarterly document review request

Detects messages sent from a user to themselves containing a link with quarterly indicators (q1_, q2_, q3_, q4_) and specific document review language requesting urgent feedback.

T1566.002T1534T1656T1566T1566.001+3
Sublimecritical

Link: Self-sent PDF lure with subject correlation

Detects messages sent from a user to themselves containing bold PDF links where the link text correlates with the subject line or sender domain, potentially indicating a compromised account or social engineering technique.

T1566.002T1534T1656T1566T1566.001+3
Sublimemedium

Link: SharePoint filename matches org name

Detects messages claiming to share files via SharePoint or OneDrive where the shared file name pattern matches the organizational naming pattern, indicating potential abuse of legitimate file sharing services to impersonate organizations.

T1566T1566.001T1566.002T1598T1534
Sublimemedium

Link: SharePoint files shared from GoDaddy federated tenants

This matches on inbound Shared File notiifcation emails from Microsoft, where any link to SharePoint contains a default GoDaddy Federated Tenant Name. These have been observed being frequently abused to send credential phishing campaigns.

T1566T1566.001T1566.002T1598T1036+1
Sublimelow

Link: SharePoint OneNote or PDF link with self sender behavior

Detects messages where the sender and recipient are the same address, containing SharePoint links to OneNote or PDF files, with minimal attachments and non-standard message IDs indicating potential abuse of SharePoint services for malicious purposes.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Link: Shortened URL with fragment matching subject

Detects messages containing shortened links where the URL fragment appears in the email subject line, indicating potential targeted link tracking or social engineering tactics.

T1566T1566.001T1566.002T1598T1534+3
Sublimemedium

Link: Single character path with credential theft body and self sender behavior or invalid recipient

Message where the sender and recipient are the same or the recipient domain is invalid, contains a link with a single character path and no query parameters or fragments, and includes credential theft language.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Link: Spam website with evasion indicators

Detects messages containing links to spam websites that show signs of evasion techniques, including blocklisted IP provider messages or rate limiting responses when analyzed.

T1566T1036T1027
Sublimelow

Link: Squarespace infrastructure abuse

Detects inbound messages containing exactly one Squarespace tracking link but lacking authentic Squarespace email headers and sender patterns.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium

Link: Suspicious Family fragment parameter with encoded recipient data

Detects messages containing links with URL fragments that include 'Family' parameters containing base64 or hex encoded email addresses, which may indicate personalized malicious content targeting specific recipients.

T1566T1566.001T1566.002T1598T1036+2
Sublimehigh
PreviousPage 34 of 53Next