EXPLORE DETECTIONS
Service abuse: Callback phishing via Microsoft Teams invite
Detects abuse of legitimate Microsoft Teams invites containing callback scam content, including brand references and financial transaction language with phone numbers.
Service abuse: Cisco secure email service with financial request
Detects messages abusing Cisco's secure email service (res.cisco.com) that contain financial topics or invoice requests, with mismatched reply-to domains and undisclosed recipients.
Service abuse: Citrix ShareFile impersonation via Outlook plugin
Detects inbound messages with Word document attachments containing references to sharefile.com and Outlook plugin system indicators, suggesting abuse of legitimate file sharing services to deliver malicious content.
Service abuse: Cognito Forms with short body from unknown sender
Detects messages with a very short body (under 200 characters) that contain a link to Cognito Forms, where the sender is not Cognito Forms itself.
Service abuse: Coursera callback scam
Detects inbound messages spoofing Coursera transactional notifications - such as email confirmation requests or account change alerts - sent from Coursera's legitimate sending infrastructure, but targeting recipients on newly registered domains or containing mailto links pointing to newly registered non-Coursera domains. The combination of authentic-looking Coursera branding with anomalous recipient or embedded contact domains suggests account takeover or credential harvesting activity targeting Coursera users.
Service abuse: Demio notifications with suspicious content patterns
Detects messages from Demio notifications service containing suspicious patterns including phone numbers, monetary amounts, suspicious domain references, explicit content lures, or lengthy action-oriented subjects designed to manipulate recipients.
Service abuse: DocSend share from an unsolicited reply-to address
DocSend shares which contain a reply-to address or domain that has not been previously observed by the recipient organization.
Service abuse: DocSend share from newly registered domain
This Attack Surface Reduction (ASR) rule matches on DocSend notifications with recently registered reply-to domains.
Service abuse: DocuSign notification with suspicious sender or document name
The detection rule is intended to match on messages sent from Docusign from a newly observed reply-to address which contains suspicious content within the document or sender display name.
Service abuse: DocuSign share from an unsolicited reply-to address
DocuSign shares which contain a reply-to address or domain that has not been previously observed by the recipient organization.
Service abuse: Domains By Proxy sender
Message originates from a sender using Domains By Proxy's domain privacy service, commonly used to hide domain ownership information.
Service abuse: Dropbox Paper with copy-paste instructions
Detects messages containing copy-paste instructions with links to Dropbox Paper documents, commonly used to bypass security controls by instructing users to manually navigate to malicious content.
Service abuse: Dropbox share from an unsolicited reply-to address
This rule detects Dropbox share notifications which contain a reply-to address or domain that has not been previously observed sending messages to or receiving messages from the recipient organization.
Service abuse: Dropbox share from new domain
This Attack Surface Reduction (ASR) rule matches on Dropbox notifications with recently registered reply-to domains.
Service abuse: Dropbox share with suspicious sender or document name
The detection rule is intended to match on messages sent from DropBox indicating a shared file to the recipient which contains suspicious content within the document or sender display name.
Service abuse: Elastic alerts extortion
Detects inbound messages impersonating Elastic alerts sender that contain extortion content identified through natural language processing with medium to high confidence.
Service abuse: EventCreate links to newly registered domains
Flags inbound messages containing links to eventcreate.com where the final rendered page includes outbound links to domains registered within the last 30 days, indicating the use of a legitimate service to pivot traffic to freshly created phishing infrastructure.
Service abuse: Evernote link
Detects inbound messages containing a link whose effective destination resolves to evernote.com, where the link text uses document-sharing or e-signature language (e.g., view, open, download, review) and the sender is not from evernote.com. The message body is also classified by an NLU model as exhibiting credential theft or business email compromise intent, indicating abuse of Evernote's legitimate hosting infrastructure to deliver malicious content.
Service Abuse: ExactTarget with suspicious sender indicators
Message originates from ExactTarget infrastructure but uses a suspicious sender domain, including overly long salesforce.com domains, awsapps.com domains, domains containing UTF-8 encoding characters, or a suspicious sender display name.
Service abuse: Facebook business with action required subject
Detects messages from the Facebook business domain containing 'action required' in the subject line, commonly used to create urgency in impersonation attacks.
Service abuse: Facebook mail notification callback scam
Detects inbound messages spoofing Facebook's official notification address that contain callback scam intent identified with medium or high confidence. Attackers leverage the trusted Facebook sender identity to deceive recipients into calling a fraudulent phone number.
Service abuse: Fake loan/funding verification lure via Mailgun
Detects inbound messages sent via Mailgun's sending infrastructure (mg subdomain) from common bulk sender addresses, where the body contains unresolved template placeholders like '[SOURCEID]', known Mailgun-associated physical addresses, or links pointing to Mailgun's campaign/list management subdomain (napp) on the same root domain as the sender. These indicators suggest automated bulk distribution with incomplete template rendering or suspicious infrastructure usage.
Service abuse: File sharing impersonation with external SharePoint links
Detects inbound messages claiming to share files or invite access, containing SharePoint or OneDrive links from external domains. The rule identifies suspicious sharing notifications where link display text matches the sender's name rather than a legitimate document name, indicating potential impersonation of legitimate file sharing services.
Service abuse: FileMail callback scam
Detects inbound messages from FileMail's no-reply address where the first line of the email body is classified with high confidence as a callback scam using natural language understanding. Attackers leverage legitimate file sharing services to deliver fraudulent messages that instruct recipients to call a phone number, often impersonating tech support or financial institutions.