EXPLORE

EXPLORE DETECTIONS

🔍
1,254 detections found

Service abuse: Callback phishing via Microsoft Teams invite

Detects abuse of legitimate Microsoft Teams invites containing callback scam content, including brand references and financial transaction language with phone numbers.

T1566.003T1598T1566.002T1598.003T1566
Sublimehigh

Service abuse: Cisco secure email service with financial request

Detects messages abusing Cisco's secure email service (res.cisco.com) that contain financial topics or invoice requests, with mismatched reply-to domains and undisclosed recipients.

T1566.002T1534T1656T1598.003T1566+3
Sublimehigh

Service abuse: Citrix ShareFile impersonation via Outlook plugin

Detects inbound messages with Word document attachments containing references to sharefile.com and Outlook plugin system indicators, suggesting abuse of legitimate file sharing services to deliver malicious content.

T1566.002T1534T1656T1566T1566.001+1
Sublimemedium

Service abuse: Cognito Forms with short body from unknown sender

Detects messages with a very short body (under 200 characters) that contain a link to Cognito Forms, where the sender is not Cognito Forms itself.

T1566T1566.001T1566.002T1598
Sublimemedium

Service abuse: Coursera callback scam

Detects inbound messages spoofing Coursera transactional notifications - such as email confirmation requests or account change alerts - sent from Coursera's legitimate sending infrastructure, but targeting recipients on newly registered domains or containing mailto links pointing to newly registered non-Coursera domains. The combination of authentic-looking Coursera branding with anomalous recipient or embedded contact domains suggests account takeover or credential harvesting activity targeting Coursera users.

T1566.003T1598T1566.002T1598.003T1583.001+1
Sublimehigh

Service abuse: Demio notifications with suspicious content patterns

Detects messages from Demio notifications service containing suspicious patterns including phone numbers, monetary amounts, suspicious domain references, explicit content lures, or lengthy action-oriented subjects designed to manipulate recipients.

T1566T1598T1566.002T1598.003
Sublimemedium

Service abuse: DocSend share from an unsolicited reply-to address

DocSend shares which contain a reply-to address or domain that has not been previously observed by the recipient organization.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Service abuse: DocSend share from newly registered domain

This Attack Surface Reduction (ASR) rule matches on DocSend notifications with recently registered reply-to domains.

T1566.002T1534T1656T1566T1566.001+4
Sublimehigh

Service abuse: DocuSign notification with suspicious sender or document name

The detection rule is intended to match on messages sent from Docusign from a newly observed reply-to address which contains suspicious content within the document or sender display name.

T1566.003T1598T1566.002T1534T1656+3
Sublimemedium

Service abuse: DocuSign share from an unsolicited reply-to address

DocuSign shares which contain a reply-to address or domain that has not been previously observed by the recipient organization.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Service abuse: Domains By Proxy sender

Message originates from a sender using Domains By Proxy's domain privacy service, commonly used to hide domain ownership information.

T1566T1566.001T1566.002T1598T1534+3
Sublimemedium

Service abuse: Dropbox Paper with copy-paste instructions

Detects messages containing copy-paste instructions with links to Dropbox Paper documents, commonly used to bypass security controls by instructing users to manually navigate to malicious content.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Service abuse: Dropbox share from an unsolicited reply-to address

This rule detects Dropbox share notifications which contain a reply-to address or domain that has not been previously observed sending messages to or receiving messages from the recipient organization.

T1566.003T1598T1566.002T1534T1656+3
Sublimemedium

Service abuse: Dropbox share from new domain

This Attack Surface Reduction (ASR) rule matches on Dropbox notifications with recently registered reply-to domains.

T1566.003T1598T1566T1566.001T1566.002+4
Sublimemedium

Service abuse: Dropbox share with suspicious sender or document name

The detection rule is intended to match on messages sent from DropBox indicating a shared file to the recipient which contains suspicious content within the document or sender display name.

T1566.003T1598T1566.002T1534T1656+3
Sublimemedium

Service abuse: Elastic alerts extortion

Detects inbound messages impersonating Elastic alerts sender that contain extortion content identified through natural language processing with medium to high confidence.

T1486T1657T1566.002T1598.003T1566+1
Sublimemedium

Service abuse: EventCreate links to newly registered domains

Flags inbound messages containing links to eventcreate.com where the final rendered page includes outbound links to domains registered within the last 30 days, indicating the use of a legitimate service to pivot traffic to freshly created phishing infrastructure.

T1566T1566.001T1566.002T1598
Sublimemedium

Service abuse: Evernote link

Detects inbound messages containing a link whose effective destination resolves to evernote.com, where the link text uses document-sharing or e-signature language (e.g., view, open, download, review) and the sender is not from evernote.com. The message body is also classified by an NLU model as exhibiting credential theft or business email compromise intent, indicating abuse of Evernote's legitimate hosting infrastructure to deliver malicious content.

T1566T1566.001T1566.002T1598T1534+1
Sublimelow

Service Abuse: ExactTarget with suspicious sender indicators

Message originates from ExactTarget infrastructure but uses a suspicious sender domain, including overly long salesforce.com domains, awsapps.com domains, domains containing UTF-8 encoding characters, or a suspicious sender display name.

T1566T1566.001T1566.002T1598T1534+3
Sublimehigh

Service abuse: Facebook business with action required subject

Detects messages from the Facebook business domain containing 'action required' in the subject line, commonly used to create urgency in impersonation attacks.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium

Service abuse: Facebook mail notification callback scam

Detects inbound messages spoofing Facebook's official notification address that contain callback scam intent identified with medium or high confidence. Attackers leverage the trusted Facebook sender identity to deceive recipients into calling a fraudulent phone number.

T1566.003T1598T1566.002T1598.003T1566
Sublimemedium

Service abuse: Fake loan/funding verification lure via Mailgun

Detects inbound messages sent via Mailgun's sending infrastructure (mg subdomain) from common bulk sender addresses, where the body contains unresolved template placeholders like '[SOURCEID]', known Mailgun-associated physical addresses, or links pointing to Mailgun's campaign/list management subdomain (napp) on the same root domain as the sender. These indicators suggest automated bulk distribution with incomplete template rendering or suspicious infrastructure usage.

T1566T1566.001T1566.002T1598T1598.003+2
Sublimemedium

Service abuse: File sharing impersonation with external SharePoint links

Detects inbound messages claiming to share files or invite access, containing SharePoint or OneDrive links from external domains. The rule identifies suspicious sharing notifications where link display text matches the sender's name rather than a legitimate document name, indicating potential impersonation of legitimate file sharing services.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium

Service abuse: FileMail callback scam

Detects inbound messages from FileMail's no-reply address where the first line of the email body is classified with high confidence as a callback scam using natural language understanding. Attackers leverage legitimate file sharing services to deliver fraudulent messages that instruct recipients to call a phone number, often impersonating tech support or financial institutions.

T1566.003T1598T1566
Sublimemedium
PreviousPage 45 of 53Next