EXPLORE DETECTIONS
Open redirect: smore.com
Message contains use of the smore.com redirect. This has been exploited in the wild for phishing.
Open redirect: Snapchat
Message contains use of the click.snapchat.com open redirect.
Open redirect: social.bigpress.net
Message contains use of the social.bigpress.net open redirect. This has been exploited in the wild.
Open redirect: ssg-financial.com
Message contains use of the ssg-financial.com open redirect. This has been exploited in the wild.
Open redirect: stats.lib.pdx.edu
Message contains use of the stats.lib.pdx.edu open redirect. This has been exploited in the wild.
Open redirect: storematch.jp
Message contains use of the storematch.jp open redirect. This has been exploited in the wild.
Open redirect: Ticketmaster
Message contains use of the Ticketmaster open redirect, but the sender is not Ticketmaster. This has been exploited in the wild.
Open redirect: TikTok
Message contains use of an open redirect on TikTok. This has been exploited in the wild.
Open redirect: tkqlhce.com
Message contains use of the tkqlhce.com redirect. This has been exploited in the wild for phishing.
Open redirect: tuttocauzioni.it
Message contains use of the tuttocauzioni.it redirect. This has been exploited in the wild.
Open redirect: typedrawers.com
Detects messages containing links or QR codes pointing to typedrawers.com/home/leaving with target parameter, sent from non-trusted domains or authenticated sources failing DMARC checks. Considers sender reputation and requires either unsolicited contact or prior malicious activity without false positives.
Open redirect: U.S. Antarctic Program Data Center (USAP-DC)
Message contains use of the U.S. Antarctic Program Data Center (USAP-DC) open redirect.
Open redirect: unitedwaynwvt.org
Message contains use of the unitedwaynwvt.org open redirect. This has been exploited in the wild.
Open redirect: ust.hk
Message contains use of the ust.hk open redirect. This has been exploited in the wild.
Open redirect: vconfex.com
Message contains use of the vconfex.com redirect. This has been exploited in the wild.
Open redirect: VK
Message contains use of the VK open redirect, but the sender is not VK. This has been exploited in the wild.
Open redirect: weblinkconnect.com
Message contains use of the weblinkconnect.com open redirect, but the sender is not weblinkconnect.com. This has been exploited in the wild.
Open redirect: whitefox.pl
Message contains use of the whitefox.pl open redirect. This has been exploited in the wild.
Open redirect: Xfinity CMP Redirection to Google AMP
Detects when non-Xfinity senders abuse Xfinity's CMP redirection service to reach Google AMP pages. The rule specifically looks for targetURL parameters containing Google AMP paths in links from untrusted or previously malicious senders.
Open redirect: xfinity.com
Message contains use of the xfinity.com open redirect. This has been exploited in the wild.
Open redirect: YouTube
Looks for use of the YouTube open redirect coming from someone other than YouTube.
Open redirect: YouTube --> Google Redirection Chain
Message contains use of a redirect chain which involves YouTube and Google amp. This has been exploited in the wild.
Outbound message to disposable email provider
Possible exfiltration of sensitive information or files.
Outlook hyperlink bypass: left-to-right mark (LRM) in base HTML tag
The exploit involves tricking Outlook for Windows into displaying a fake domain while opening another one. This is achieved by adding a <base> HTML tag with a fake domain and a left-to-right mark (Unicode U+200E). Links within <a> tags will display the fake domain but open the actual domain when clicked on.