EXPLORE

EXPLORE DETECTIONS

🔍
1,254 detections found

Service abuse: Microsoft Power Apps callback scam

Detects callback scam messages sent through Microsoft Power Apps that impersonate well-known brands like McAfee, Norton, Geek Squad, PayPal, or other services, containing suspicious transaction-related language and phone numbers to solicit victim contact.

T1566.003T1598T1566.002T1598.003T1566
Sublimemedium

Service abuse: Microsoft Power Automate callback scam impersonation

Detects callback scam attempts using the legitimate Microsoft Power Automate service email address with high-confidence callback scam language in the message body.

T1566.003T1598T1566
Sublimemedium

Service abuse: Microsoft Power BI callback scam

Detects callback scam content sent from the legitimate Microsoft Power BI service email address, indicating potential service abuse to distribute fraudulent callback solicitations.

T1566.003T1598T1566
Sublimemedium

Service abuse: Microsoft with suspicious indicators in subject

Detects messages impersonating Microsoft account verification that contain suspicious indicators in the subject line, including phone numbers, monetary amounts, suspicious domains, explicit content, or lengthy action-oriented phrases.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium

Service abuse: Mimecast URL with excessive path length

Detects messages containing the second stage Mimecast redirect URL with unusually long paths, potentially indicating abuse of the Mimecast URL redirection service to obfuscate malicious destinations.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimehigh

Service abuse: Monday.com callback scam

Detects callback scam solicitations originating from Monday.com's notification system using natural language understanding to identify fraudulent callback language in the message body.

T1566.003T1598T1566
Sublimemedium

Service abuse: Monday.com infrastructure with phishing intent

Detects unauthorized use of Monday.com tracking links in messages, attachments, or QR codes from unusual senders who lack proper authentication. Excludes legitimate replies and messages from trusted domains with valid DMARC.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Service abuse: MongoDB Atlas callback scam

Detects inbound messages from MongoDB Atlas alert addresses that contain callback scam content identified through natural language analysis with medium or high confidence.

T1566.003T1598T1566.002T1598.003T1566
Sublimemedium

Service Abuse: Nifty.com with impersonation

Detects emails from nifty.com where the sender's local part matches a recipient's local part or organizational SLD, which has been observed in credential harvesting campaigns

T1566T1566.001T1566.002T1598
Sublimemedium

Service abuse: Notion free-tier account impersonating VIP

Detects messages sent from Notion's legitimate notification address (notify@mail.notion.so), but where the sender's display name matches an internal VIP, and the embedded links resolve to a Notion workspace associated with a free-tier subscription. This pattern indicates abuse of Notion's free tier to craft convincing internal impersonation lures.

T1566T1566.001T1566.002T1598T1534
Sublimemedium

Service abuse: Nylas tracking subdomain with suspicious content

Detects messages containing links to Nylas tracking subdomains with display text and suspicious language patterns, indicating potential abuse of the email tracking service.

T1566.002T1534T1656T1566T1566.001+3
Sublimemedium

Service abuse: Oracle Cloud Workflow callback scam

Detects inbound messages sent through Oracle Cloud's workflow mail service (workflow.mail.us2.cloud.oracle.com) that contain callback scam content within styled HTML table cells. Natural language understanding is used to identify callback scam intent with medium or high confidence within the message body, indicating misuse of legitimate Oracle infrastructure to deliver fraudulent content.

T1566.003T1598T1566T1566.002T1598.003
Sublimemedium

Service abuse: Outlook Groups with Google Sites link and evasion tag

Detects inbound messages sent via Outlook Groups (groups.outlook.com) that contain links to Google Sites, combined with a suspicious short alphanumeric tag appended to either the message body or subject line. This pattern is commonly used to evade detection while redirecting recipients to credential harvesting pages hosted on Google Sites.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Service abuse: Payoneer callback scam

A fraudulent invoice/receipt found in the body of the message sent by leveraging Payoneer's invoicing service. Callback Phishing is an attempt by an attacker to solicit the victim (recipient) to call a phone number. The resulting interaction could lead to a multitude of attacks ranging from Financial theft, Remote Access Trojan (RAT) Installation or Ransomware Deployment.

T1566.003T1598T1566.002T1534T1656+3
Sublimemedium

Service abuse: PayPal manager account creation with callback scam indicators

Detects inbound messages abusing PayPal's noreply address with subjects about PayPal Manager user account creation that contain callback scam intent patterns identified through natural language analysis.

T1566.003T1598T1566T1566.001T1566.002+1
Sublimemedium

Service abuse: Postman reply-to mismatch with credential theft intent

Detects inbound messages sent from Postman.io where the reply-to address belongs to a different domain than the sender, combined with high or medium confidence credential theft intent detected in the message body. This technique leverages a legitimate service to deliver messages while redirecting replies to an attacker-controlled address.

T1566T1566.001T1566.002T1598
Sublimemedium

Service abuse: QuickBooks notification from new domain

This Attack Surface Reduction (ASR) rule matches on QuickBooks notifications with recently registered reply-to domains.

T1566.003T1598T1566T1566.001T1566.002+4
Sublimemedium

Service abuse: QuickBooks notification with suspicious comments

This detection rule matches QuickBooks notifications that contain suspicious keywords within the comments section of the notification

T1566.003T1598T1566T1566.001T1566.002+4
Sublimemedium

Service abuse: Recruiting with suspicious language patterns from legitimate platforms

Detects suspicious recruiting messages from legitimate services like Salesforce, LADesk, or AWS Apps with unusually long sender email addresses and recruiting-specific language patterns that may indicate abuse of trusted platforms for social engineering.

T1566.002T1534T1656T1566T1598
Sublimemedium

Service abuse: Roomsy with unrelated body content

Detects messages from Roomsy.com with a structured noreply sender pattern that contain content unrelated to travel, transportation, or order confirmations.

T1566.002T1534T1656T1566T1566.001+2
Sublimemedium

Service abuse: Sendgrid credential theft with personalized request targeting single recipient

Detects messages sent through Sendgrid from new sender domains that contain credential theft language with high confidence. The message targets a single recipient whose email address appears in both the message body and link display text, indicating personalization tactics commonly used in targeted attacks.

T1566T1566.001T1566.002T1598
Sublimemedium

Service abuse: SendGrid impersonation via Sendgrid from new sender

Detects messages impersonating SendGrid from new senders, while routing through legitimate SendGrid infrastructure. This pattern is commonly used to abuse trusted email services for malicious purposes.

T1566T1566.001T1566.002T1598T1598.003
Sublimehigh

Service abuse: SendGrid-formatted link with actor-controlled fragment

Detects messages containing SendGrid or SendGrid-like links with base64-encoded zlib-compressed JSON in the URL fragment, indicating potential abuse of legitimate email services for malicious purposes.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Service abuse: SendThisFile with credential theft and financial language

Detects messages from sendthisfile.com containing credential theft language combined with financial communications topics.

T1566.002T1534T1656T1566T1566.001+1
Sublimemedium
PreviousPage 47 of 53Next