EXPLORE

EXPLORE DETECTIONS

🔍
1,254 detections found

Scam soliciting employer review/rating

Detects scam content that impersonates employer review/rating platforms (e.g., Glassdoor, Indeed, Comparably, Great Place to Work) and solicits the recipient to review or rate their employer, while excluding legitimate review/rating platform senders.

T1566.002T1534T1656T1566T1566.001+2
Sublimelow

Scam: Fake estate sale offering welding equipment and tools

Detects fraudulent messages impersonating someone selling inherited or estate items, specifically targeting welding equipment, power tools, and machinery. These messages typically claim items are from a deceased relative's estate or due to relocation, require shipping arrangements, and use emotional manipulation to appear legitimate while requesting contact through alternative channels.

T1566.002T1534T1656T1566T1598
Sublimehigh

Scam: Piano giveaway

This rule is designed to identify and mitigate a specific type of fraudulent activity commonly targeted at educational institutions. This rule operates by analyzing incoming email content for certain characteristics indicative of a scam involving the offer of a free piano, often framed within the context of downsizing or a giveaway.

T1566.002T1534T1656
Sublimemedium

Self-impersonation: Sender matches recipient with bolded name and suspicious link

Detects messages where the sender's email address matches the recipient's email address, with the sender's display name appearing in bold text and a suspicious 'Read the Message' link present in the body.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Self-sender with copy/paste instructions and suspicious domains (French/Français)

Detects messages where the sender emails themselves with French text containing 'copier' (copy) and 'coller' (paste) instructions, along with suspicious domains like pages.dev or web.app. The subject line contains both the sender's email and display name, which are different values.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Self-sent fake PDF attachment with misleading link

Detects messages sent from a user to themselves containing a fake PDF icon from Google's CDN, claiming to have an attachment while only containing images, and including links that appear to be PDF files.

T1566T1566.001T1566.002T1598T1036+1
Sublimelow

Sender name contains Active Directory distinguished name

Sender's display name contains an Active Directory distinguished name or a similar string. This has been observed as a malicious indicator in the wild.

T1566T1566.001T1566.002T1598
Sublimemedium

Sender: IP address in local part

Detects messages where the sender's email local part contains an IPv4 address, which is commonly used in malicious campaigns to bypass filters or appear legitimate.

T1566T1566.001T1566.002T1598T1534+3
Sublimemedium

Sender: Local part built from recipient domain and mailbox

Flags inbound messages where the sender's local part is constructed by combining the recipient's domain name and mailbox name (e.g., domain_mailbox). This pattern is commonly used to make the sender address appear related to or originating from the recipient's own organization, helping the message blend in and evade scrutiny.

T1566.002T1534T1656T1566T1566.001+3
Sublimelow

Sendgrid onmicrosoft.com domain phishing

The message originates from an onmicrosoft.com email address being sent via Sendgrid.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Sendgrid voicemail phish

The message may contain a fake voicemail notification being sent via Sendgrid.

T1566T1566.001T1566.002T1598
Sublimehigh

Service abuse: Adobe Creative Cloud share from an unsolicited sender address

Detects messages from Adobe Creative Cloud in which the document originates from a newly observed email address. The email address is extracted from the HTML body.

T1566T1566.001T1566.002T1598T1036+1
Sublimelow

Service abuse: Adobe legitimate domain with document approval language

Detects messages from Adobe's legitimate email domain containing suspicious language about document or payment approval that may indicate service abuse.

T1566.002T1534T1656T1566T1566.001+1
Sublimemedium

Service abuse: Adobe message from newly registered domain

Detects messages legitimately sent through Adobe's messaging infrastructure that contain mailto links pointing to domains registered within the last 365 days.

T1566T1566.001T1566.002T1598T1036+2
Sublimemedium

Service abuse: Adobe share containing newly observed email address domain

Detects legitimate Adobe notification emails that contain a genuine Adobe-hosted document link alongside a mailto link with an external email address that is not the recipient, not part of the organization's domains, not associated with Adobe, and has never been observed in prior inbound or outbound mail. This pattern indicates abuse of Adobe's trusted email infrastructure to redirect victims into contacting an attacker-controlled address outside the normal mail flow.

T1566T1566.001T1566.002T1598T1534+1
Sublimehigh

Service abuse: Adobe Sign notification from an unsolicited reply-to address

Identifies messages appearing to come from Adobe Sign signature notifications that contain a reply-to address not previously seen in organizational communications. This tactic exploits trust in legitimate Adobe services while attempting to establish unauthorized communication channels.

T1566.002T1534T1656T1566.003T1598+2
Sublimemedium

Service abuse: Amazon invitation with suspected callback phishing

Detects Amazon's no-reply address with a subject about invitation sending, containing phone numbers within HTML header elements. This pattern is commonly used to trick recipients into calling fraudulent customer service numbers.

T1566.003T1598T1566
Sublimemedium

Service abuse: Apple TestFlight with suspicious developer reference

Detects legitimate Apple TestFlight emails that reference potentially suspicious developers or apps, including variations of OpenAI, ChatGPT, or Meta in the app description or developer name fields.

T1566T1598
Sublimehigh

Service abuse: AppSheet infrastructure with suspicious indicators

Identifies messages that resemble credential theft, originating from AppSheet. AppSheet infrastrcture abuse has been observed recently to send phishing attacks.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Service abuse: Arketa notification callback scam

Detects messages sent from Arketa's notification address (no-reply@notifications.arketa.co) that has been abused to deliver callback scam content. The rule flags messages where an NLU classifier identifies callback scam intent, or where the body references well-known brands (e.g., McAfee, Norton, PayPal, eBay, Best Buy) alongside scam-related keywords (purchase, invoice, refund, cancel, etc.) and includes a phone number formatted to evade detection through character substitution or spacing tricks.

T1566.003T1598T1566T1566.002T1598.003+2
Sublimemedium

Service abuse: AWS SNS callback scam impersonation

Detects callback scam messages sent through Amazon Web Services Simple Notification Service (SNS) that impersonate well-known brands like McAfee, Norton, PayPal, and others. The rule identifies fraudulent purchase receipts or service notifications containing phone numbers to solicit victim callbacks, potentially leading to financial theft or malware installation.

T1566.003T1598T1566.002T1598.003T1566
Sublimemedium

Service abuse: Behance document sharing with suspicious language

Detects messages containing document sharing language with a single Behance gallery link, potentially indicating abuse of the legitimate Adobe Behance platform for malicious purposes.

T1566T1566.001T1566.002T1598
Sublimemedium

Service Abuse: Box file sharing with credential phishing intent

Detects abuse of Box's legitimate infrastructure for credential phishing attacks.

T1566T1566.001T1566.002T1598T1534+4
Sublimemedium

Service abuse: Calendly callback scam detection

Detects inbound messages from Calendly's notification system that contain callback scam content, as identified through natural language processing with medium or high confidence levels.

T1566.003T1598T1566T1566.002T1598.003
Sublimemedium
PreviousPage 44 of 53Next