EXPLORE DETECTIONS
Service abuse: Settime.io sender with callback scam intent
Detects inbound messages from noreply@settime.io that exhibit callback scam characteristics, as identified by natural language understanding with medium or high confidence. Settime.io is a scheduling service that can be abused to send fraudulent messages prompting recipients to call a phone number controlled by threat actors.
Service abuse: Soundestlink redirect with suspicious indicators
Detects messages containing Soundestlink redirect links that lack proper unsubscribe mechanisms, and lack standard mailing list headers, indicating potential abuse of the service.
Service abuse: Soundestlink.com Microsoft impersonation
Detects links or extracted domains hosted on soundestlink.com where the subdomain contains Microsoft-related keywords such as 'microsoft', 'teams', 'login', 'office', '365', or 'outlook'. This pattern indicates abuse of a legitimate link redirection/tracking service to disguise malicious URLs as Microsoft login or authentication pages, a common technique used to harvest credentials.
Service abuse: Square marketing with suspicious QR code
Detects messages from Square's marketing domain containing QR codes that redirect to self-service creation platforms, file sharing services, or image hosting services.
Service abuse: Substack credential theft with confusable characters and branded button redirects
Detects messages from Substack that use confusable characters in the sender display name, contain purple buttons or typical button classes that redirect to non-Substack domains, and include credential theft content with urgency indicators.
Service abuse: SurveyMonkey survey from newly registered domain
This Attack Surface Reduction (ASR) rule matches on SurveyMonkey Surveys with recently registered reply-to domains.
Service abuse: SurveyMonkey with suspicious outbound links
Detects messages sent from SurveyMonkey's user domain that contain links to non-SurveyMonkey domains within nested table elements, excluding survey-related content.
Service abuse: Suspicious Datadog alert
Message from alert@dtdg.co containing links to URL shorteners or self-service creation platforms.
Service abuse: Suspicious Zoom Docs link
Detects messages from Zoom Docs in which the document originates from a newly observed email address or contains suspicious indicators.
Service abuse: Task management message sent via SendGrid
Detects messages impersonating task or productivity applications by using 'todo list' in the subject line or body while utilizing SendGrid infrastructure. The sender claims to be task-related through display name or body content but originates from non-legitimate domains without proper DMARC authentication.
Service abuse: Trello board invitation with VIP impersonation
Detects fraudulent Trello board invitations that impersonate organization VIPs by using organization domain names in board titles and including notes purportedly from legitimate company executives.
Service abuse: Vimeo with external plain-text links in message
Detects messages absuing Vimeo notifications about received messages that contain plain-text links redirecting to domains other than Vimeo, potentially leading users to malicious websites.
Service abuse: WeTransfer callback scam
Detects callback scams originating from legitimate WeTransfer noreply address using natural language processing to identify high-confidence callback scam intent in the message body.
Service abuse: Wix redirect through bulk mailer domains
Detects messages containing Wix-encoded links that redirect through bulk mailing service domains, potentially bypassing security controls through legitimate redirect services.
Service abuse: Wufoo credential theft
Detects malicious messages sent from Wufoo's sending address (no-reply@wufoo.com) that are abusing the platform to deliver credential theft content. This rule identifies messages that lack Wufoo's standard display name and structural HTML elements found in legitimate Wufoo emails, while containing links and content classified as credential theft by NLU analysis.
Service abuse: Zohodesk reply-to mismatch with job scam indicators
Detects inbound messages sent from Zohodesk infrastructure where the reply-to address points to a domain outside of Zohodesk, combined with natural language signals indicating job scam content. This technique abuses legitimate Zohodesk services to add credibility while redirecting responses to an external actor-controlled address.
Service abuse: Zoom Clips with suspicious reply-to address or links
Detects legitimate-looking Zoom 'Clips shared' notifications sent from Zoom's genuine no-reply infrastructure, where the underlying reply-to address or embedded links show signs of abuse. This includes reply-to domains that very recently created, links pointing to scheduling services like Cal.com, Calendly, or Vasta, or unsolicited reply-to senders — all indicating the legitimate clip-sharing feature is being leveraged to route victims to attacker-controlled contact points.
Service Abuse: Zoom with freemail reply-to and recipient address in greeting
Detects messages impersonating Zoom that use a freemail provider for the reply-to address, have a new and unsolicited reply-to profile, and contain the recipient's email address in the greeting line where a name would normally appear.
Service abuse: Zoom with newly registered reply-to domain
Detects messages from legitimate Zoom infrastructure (no-reply@zoom.us) that contain a reply-to address with a domain registered within the last 45 days, indicating potential abuse of Zoom's service for malicious purposes.
Sharepoint file share with suspicious recipients pattern
This rule detects messages originating from sharepoint.com with undisclosed recipients that are attempting to solicit the user to click a link. This has been observed in the event of an account compromise where the compromised account was utilizing legitimate file sharing services to share malicious links.
Sharepoint link likely unrelated to sender
Detects when a sender links to a Sharepoint file where the subdomain significantly differs from the sender's domain. The rule checks for OneNote, PDF, or unknown file types and includes various domain validation checks.
Sharepoint online with external recipients and external display name
An email from Sharepoint Online that was sent to multiple recipients that did not originate from a sender, by display name, in your organization.
SharePoint OTP for filename matching org name
Detects Microsoft One-Time Passcode (OTP) messages where the shared document’s filename matches the sending organization's name. This typically indicates the recipient has verified their email address and is about to access a SharePoint file. Matching the document name to the sender's org is a pattern observed in multi-stage credential phishing campaigns, where attackers use branded file names to increase credibility and lure users into interacting with malicious content.
Shopify infrastructure abuse
Attackers have been observed using myshopify.com links to bypass domain reputation checks.