EXPLORE

EXPLORE DETECTIONS

🔍
1,254 detections found

Navohost.com hosting link

The message contains a Navohost.com link, which can be used to host malicious content.

Sublimelow

New Account Verification Code From Common IdP Vendor

Identifies incoming verification codes from Apple, GitHub, Microsoft, Google, Slack, and Facebook, typically associated with new account creation. We recommend commenting out vendors where your users already have accounts, as this may flag verification codes for existing accounts.

Sublime

New link domain (<=10d) from untrusted sender

Detects links in the body of an email where the linked domain is less than 10 days old from untrusted senders.

T1566T1566.001T1566.002T1598T1204.002+1
Sublimemedium

New sender domain (<=10d) from untrusted sender

Detects inbound emails where the sender domain is less than 10 days old from untrusted senders.

Sublimemedium

Newly registered sender or reply-to domain with newly registered linked domain

This rule detects inbound emails that contain links and a reply-to address, where either the sender domain or the reply-to domain is newly registered (≤30 days old), and at least one linked domain is also very new (≤14 days old). It flags potential phishing or business email compromise attempts that use recently created infrastructure and reply-to mismatch tactics to bypass trust and impersonate legitimate contacts.

T1566.002T1534T1656T1566T1566.001+3
Sublimemedium

NINJIO phishing simulation

Identifies phishing simulations sent by NINJIO and excludes the message from live analysis.

Sublime

Non-RFC compliant calendar files from unsolicited sender

Detects calendar (.ics) files that do not follow RFC standards by lacking required UID identifiers while containing specific calendar components (VTODO, VJOURNAL, VFREEBUSY, or VEVENT). Forged ICS calendar invites can be spoofed to seemingly originate from any sender.

T1036T1027T1566T1598
Sublimemedium

Notion suspicious file share

Message contains a notion link that contains suspicious terms. You may need to deactivate or fork this rule if your organization uses Notion.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimemedium

Observed IOC: Mail transiting bulletproof host - SmartApe

Detects inbound mail whose IP space is announced by SmartApe (SmartApe LLC), a Russia-based hosting provider widely reported for abuse-tolerant / bulletproof hosting. IP ranges are the prefixes announced by SmartApe's ASN (AS56694).

T1566.001T1204.002T1486T1566T1566.002+5
Sublimemedium

Observed IOC: Mail transiting OFAC-sanctioned bulletproof host Aeza Group

Detects inbound mail whose Received-header IP path transits IP space announced by Aeza Group LLC, a bulletproof hosting provider designated by the U.S. Treasury's Office of Foreign Assets Control (OFAC) on 2025-07-01 (CYBER4 / CAATSA-RUSSIA). IP ranges are the prefixes announced by Aeza's ASNs (AS210644, AS216246).

T1566.001T1204.002T1486T1566T1566.002+5
Sublimehigh

Observed IOC: Malicious attachment SHA-256 hashes

Detects inbound messages carrying an attachment whose SHA-256 file hash matches a known malicious file observed by the detection-engineering team. IOC list is automatically managed by the IOC pipeline. NOTE: an attachment SHA-256 is itself a file hash, so the embedded literals are SHA-256 of that file hash (hash-of-hash), consistent with the pipeline's hashing convention.

T1566.001T1204.002T1486T1566T1566.002+3
Sublimehigh

Observed IOC: Malicious domains in body links

Detects inbound messages containing links to known malicious domains in the message body. IOC list is automatically managed and hashed by the IOC pipeline from the private threat intelligence feed.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimehigh

Observed IOC: Malicious reply-to domains

Detects inbound messages with reply-to headers containing known malicious domains. IOC list is automatically managed and hashed by the IOC pipeline from the private threat intelligence feed.

T1566.002T1534T1656T1566T1566.001+3
Sublimehigh

Observed IOC: Malicious reply-to email addresses

Detects inbound messages with reply-to headers containing known malicious email addresses. IOC list is automatically managed and hashed by the IOC pipeline from the private threat intelligence feed.

T1566.002T1534T1656T1566T1566.001+3
Sublimehigh

Observed IOC: Malicious reply-to root domains

Detects inbound messages with reply-to headers containing known malicious root domains. IOC list is automatically managed and hashed by the IOC pipeline from the private threat intelligence feed.

T1566.002T1534T1656T1566T1566.001+3
Sublimehigh

Observed IOC: Malicious root domains in body links

Detects inbound messages containing links to known malicious root domains in the message body. IOC list is automatically managed and hashed by the IOC pipeline from the private threat intelligence feed.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimehigh

Observed IOC: Malicious sender domains

Detects inbound messages sent from known malicious sender domains. IOC list is automatically managed and hashed by the IOC pipeline from the private threat intelligence feed.

T1566.002T1534T1656T1566T1566.001+3
Sublimehigh

Observed IOC: Malicious sender email addresses

Detects inbound messages from known malicious sender email addresses. IOC list is automatically managed and hashed by the IOC pipeline from the private threat intelligence feed.

T1566.002T1534T1656T1566T1566.001+3
Sublimehigh

Observed IOC: Malicious sender root domains

Detects inbound messages sent from known malicious sender root domains. IOC list is automatically managed and hashed by the IOC pipeline from the private threat intelligence feed.

T1566.002T1534T1656T1566T1566.001+3
Sublimehigh

Observed IOC: Malicious URLs in body links

Detects inbound messages containing specific known malicious URLs in the message body. IOC list is automatically managed and hashed by the IOC pipeline from the private threat intelligence feed.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimehigh

Office 365 fake file share

Sublime

Open redirect (go2.aspx) leading to Microsoft credential phishing

This rule is designed to detect credential phishing attacks that exploit go2.aspx redirects and masquerade as Microsoft-related emails.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium

Open redirect: adnxs.com

Message contains use of the adnxs.com redirect with getuid parameter. This has been exploited in phishing campaigns to redirect users to malicious sites.

T1566T1566.001T1566.002T1598T1204.002+1
Sublimemedium

Open redirect: agena-smile.com

Message contains use of the agena-smile.com redirect with wptouch_switch parameter. This has been exploited in the wild for phishing.

T1566T1566.001T1566.002T1598T1204.002+1
Sublimemedium
PreviousPage 37 of 53Next