EXPLORE

EXPLORE DETECTIONS

🔍
1,254 detections found

Service abuse: FlipHTML5 with attachment deception and credential theft language

Detects messages that reference attachments without including any, contain links to FlipHTML5 services, and exhibit high-confidence credential theft language patterns.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Service abuse: Formester with suspicious link behavior

Detects abuse of the Formester form service where links either redirect to credential phishing pages, contain suspicious top-level domains in the final DOM and/or redirect history, or display 'secure message' text indicating potential credential theft.

T1566T1566.001T1566.002T1598T1534+1
Sublimemedium

Service abuse: Free provider with SendGrid routing

Message From header includes a free email provider domain but is routed through SendGrid infrastructure, indicating potential service abuse for delivery evasion.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Service abuse: GetAccept callback scam content

Detects callback scam language in messages sent through legitimate GetAccept infrastructure, indicating potential abuse of the service for fraudulent solicitation.

T1566.003T1598T1566
Sublimemedium

Service abuse: GitHub notification with excessive mentions and suspicious links

Detects messages impersonating GitHub notifications that contain excessive @ mentions (over 20) and include a single suspicious external link. The suspicious link may be from free file hosts, free subdomain hosts, URL shorteners, or newly registered domains. The rule filters out legitimate GitHub domains and internal employee communications while identifying potential abuse of GitHub's notification system.

T1566T1566.001T1566.002T1598T1204.002+1
Sublimehigh

Service Abuse: GoDaddy infrastructure

Detects messages from legitimate GoDaddy domains with suspicious indicators. Observed abused for call back phishing and extortion campaigns.

T1566.003T1598T1486T1657T1036+1
Sublimemedium

Service abuse: Google account notification with links to free file host

Detects messages impersonating Google Accounts that contain links redirecting to known file hosting services

T1566T1566.001T1566.002T1598T1598.003
Sublimehigh

Service abuse: Google application integration redirecting to suspicious hosts

Detects legitimate Google application integration emails that contain links redirecting to free file hosting services or free subdomain hosts, including Microsoft OAuth redirects to suspicious domains. These could indicate abuse of Google's legitimate service for malicious redirects.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimemedium

Service abuse: Google Calendar notification with callback scam language

Detects messages sent from Google's legitimate calendar notification service that contain callback scam language, indicating potential abuse of the calendar sharing feature to distribute fraudulent content.

T1566.003T1598T1566
Sublimemedium

Service abuse: Google classroom solicitation

Detects messages spoofing Google Classroom notifications that contain WhatsApp contact information, phone numbers, or sexually explicit content. The rule identifies emails from no-reply@classroom.google.com that include WhatsApp invitations, emojis in the subject line, or explicit sexual language, as well as phone numbers and WhatsApp references in message screenshots from first-time senders.

T1566.003T1598T1566.002T1534T1656+2
Sublimemedium

Service abuse: Google Drive share from an unsolicited reply-to address

Identifies messages appearing to come from Google Drive sharing notifications that contain a reply-to address not previously seen in organizational communications. This tactic exploits trust in legitimate Google services while attempting to establish unauthorized communication channels.

T1566.002T1534T1656T1566.003T1598+2
Sublimemedium

Service abuse: Google Drive share from new reply-to domain

A Google Drive sharing notification containing a reply-to address from a recently registered domain (less than 30 days old). The reply-to domain does not match any organizational domains.

T1566.002T1534T1656T1566.003T1598+2
Sublimemedium

Service abuse: Google Firebase sender address with suspicious content

Detects messages from Firebase hosted domains that contain suspicious indicators such as emojis, spam keywords, unusual link patterns, or freemail registrant information.

T1566T1566.001T1566.002T1598
Sublimelow

Service abuse: Google Groups callback scam

Detects inbound messages originating from Google Groups that contain high-confidence callback scam content, identifying abuse of the legitimate service to distribute fraudulent callback requests.

T1566.003T1598T1566
Sublimemedium

Service abuse: Google OAuth with suspicious redirect destination

Detects messages containing Google OAuth links with prompt=none parameter that redirect to suspicious domains including free file hosts, free subdomain providers, or self-service creation platforms.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Service abuse: Google Tag Manager debug cookie clearing with open redirect potential

Detects messages containing links to Google Tag Manager's debug cookie clearing endpoint with suspicious URL parameters that may be exploited for open redirects, or links that have been rewritten through Google Tag Manager encoding methods.

T1566T1566.001T1566.002T1598
Sublimehigh

Service abuse: HelloSign from an unsolicited sender address

Detects messages from HelloSign in which the document originates from a newly observed email address. The email address is extracted from across multiple message components, including HTML body templates and email header fields.

T1566T1566.001T1566.002T1598T1036+1
Sublimelow

Service Abuse: HelloSign share with suspicious sender or document name

The detection rule is designed to identify messages sent from HelloSign that notify recipients about a shared file and contain suspicious content either in the document or the sender's display name.

T1566.003T1598T1566.002T1534T1656+3
Sublimemedium

Service abuse: HungerRush domain with SendGrid tracking targeting ProtonMail

Detects inbound messages from hungerrush.com domain that contain SendGrid tracking pixels and reference redacted ProtonMail addresses, indicating potential abuse of legitimate services for suspicious targeting.

T1566.002T1534T1656T1036T1027
Sublimehigh

Service abuse: IBM IAM account notification with callback scam indicators

Detects inbound messages abusing IBM's IAM account notification address that contain callback scam intent patterns identified through natural language analysis.

T1566.003T1598T1566.002T1598.003T1566
Sublimemedium

Service abuse: Kagoya.net-hosted domains sending English business lures

Flags inbound mail routed through infrastructure tied to the Japanese hosting provider Kagoya.net where the message body is written in English, a mismatch that surfaces abuse of these mail servers for business-themed lures.

T1566.002T1534T1656T1566T1598.003+1
Sublimelow

Service abuse: Linode Objects HTML file hosting

Detects inbound messages containing links to HTML files hosted on Linode's object storage service (linodeobjects.com). This pattern is commonly used to host malicious content or bypass security controls by leveraging legitimate cloud storage infrastructure.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimemedium

Service abuse: Meetup.com redirect with brand impersonation

Detects messages abusing Meetup.com's click tracking service with lengthy redirect URLs while impersonating legitimate Meetup communications. The rule identifies suspicious links to clicks.meetup.com with URLs exceeding 300 characters, excludes legitimate Meetup emails by checking for their branding elements, and filters out high-trust authenticated senders.

T1566T1566.001T1566.002T1598T1598.003+2
Sublimemedium

Service abuse: Microsoft Forms Pro with suspicious links or QR codes

Detects messages sent from Microsoft Forms Pro (surveys@email.formspro.microsoft.com) that contain suspicious indicators, including links to suspicious TLDs, recipient email addresses embedded in URLs, OAuth authorization links, personal OneDrive paths, template placeholders, or QR codes pointing to recently registered or suspicious domains.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium
PreviousPage 46 of 53Next