EXPLORE DETECTIONS
Open redirect: Panera Bread
Looks for use of the Panera Bread open redirect coming from someone other than Panera.
Open redirect: people.anuneo.com
Message contains use of a people.anuneo.com redirect. This redirection has been abused by threat actors in the wild.
Open redirect: phoenixartstudio.net
Message contains use of the Phoenix Art Studio redirect. This has been exploited in the wild.
Open redirect: PIRL San Diego
Message contains use of the PIRL San Diego open redirect. This has been exploited in the wild.
Open redirect: plasticsurgery.or.kr
Message contains use of the plasticsurgery.or.kr open redirect. This has been exploited in the wild.
Open redirect: pmifunds.com
Message contains use of the pmifunds.com redirect. This has been exploited in the wild.
Open redirect: predictiveresponse.net
Message contains use of the predictiveresponse.net open redirect. This has been exploited in the wild.
Open redirect: PremierBet
Message contains use of the PremierBet open redirect. This has been exploited in the wild.
Open redirect: qrxtech.com
Message contains use of the qrxtech.com open redirect. This has been exploited in the wild.
Open redirect: queue.swytchbike.com
Message contains use of the queue.swytchbike.com open redirect. This has been exploited in the wild.
Open redirect: radiopublic.com
Message contains use of the radiopublic.com redirect. This has been exploited in the wild.
Open redirect: Recipient address embedded in redirect URL pointing to newly registered domain
Detects inbound messages sent to a single recipient where the body contains a link that embeds the recipient's email address in a URL query parameter, and the resolved destination domain was registered less than 100 days ago. This pattern is consistent with personalized redirect links designed to evade detection while directing targets to newly established infrastructure.
Open redirect: retailrocket.net
Message contains use of the retailrocket.net open redirect. This has been exploited in the wild.
Open redirect: ringaraja.net
Message contains use of the ringaraja.net open redirect. This has been exploited in the wild.
Open redirect: Samsung
Message contains use of the Samsung open redirect, but the sender is not Samsung.
Open redirect: sciencebuddies.org
Message contains use of the sciencebuddies.org open redirect. This has been exploited in the wild.
Open redirect: secondstreetapp.com
Message contains use of the secondstreetapp.com redirect. This has been exploited in the wild.
Open redirect: Shibboleth SSO Logout Return Parameter
Detects links that contain a Shibboleth SSO logout endpoint with a return parameter, which could be used for open redirect attacks. The rule checks for both direct path inclusion and URL-encoded versions in query parameters. Only triggers on senders with non-common prevalence.
Open redirect: shoppermeet.net
Message contains use of the shoppermeet.net redirect. This has been exploited in the wild for phishing.
Open redirect: shoppingwebapi.didatravel.com
Message contains use of the shoppingwebapi.didatravel.com open redirect. This has been exploited in the wild.
Open redirect: Signature Travel Network
Message contains use of the Signature Travel Network open redirect, but the sender is not Signature Travel Network. This has been exploited in the wild.
Open redirect: Slack
Message contains use of Slack's open redirect but the sender is not Slack.
Open redirect: slubnaglowie.pl
Message contains use of a slubnaglowie.pl redirect. This redirection has been abused by threat actors in the wild.
Open redirect: smartadserver.com
Message contains use of the smartadserver.com redirect. This has been exploited in the wild.