EXPLORE

EXPLORE DETECTIONS

🔍
992 detections found

VIP impersonation with urgent request (strict match, untrusted sender)

Sender is using a display name that matches the display name of someone in your $org_vips list. Detects potential Business Email Compromise (BEC) attacks by analyzing text within email body from untrusted senders.

T1566.002T1534T1656T1566T1598
Sublimehigh

VIP impersonation with w2 request with reply-to mismatch

This rule detects emails attempting to impersonate a VIP requesting a W-2 with a reply-to mismatch.

T1566.002T1534T1656
Sublimehigh

VIP impersonation: Fake thread with display name match, email mismatch

This rule is intended to detect fake threads that are impersonating a VIP. It looks for a matching $org_vips display name and checks the email address following it does not match what is in the $org_vips list.

T1566.002T1534T1656T1036T1027+2
Sublimemedium

VIP local_part impersonation from unsolicited sender

This rule identifies potential impersonation attempts involving the local part of an $org_vip email address. Specifically, it checks for cases where the local part of an $org_vip email (e.g., local_part@domain.com) appears with a different domain (e.g., local_part@foreigndomain.com). Additionally, the rule flags messages that match an $org_vip address exactly but fail authentication.

T1566.002T1534T1566T1598
Sublimehigh

X (Twitter) impersonation with credential phishing motives

This rule is designed to identify impersonation attempts by analyzing the display name or sender's local part for the solitary use of "X" provided the email doesn't originate from twitter.com or x.com. Natural Language Understanding (NLU) is used to check for credential theft requiring a medium-to-high confidence level for flagging.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium

Xero infrastructure abuse

Identifies messages that resemble credential theft, originating from Xero. Xero infrastrcture abuse has been observed recently to send phishing attacks.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Xero invoice abuse

Detects suspicious Xero invoice communications containing urgent payment requests where the sender's display name contains either confusable characters or impersonates internal services like HR or IT support.

T1566.002T1534T1656T1566T1566.001+2
Sublimemedium

Zoom Events newsletter abuse

Detects suspicious content in Zoom Events notifications that contain credential theft language and links to file hosting sites.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium
PreviousPage 42 of 42