EXPLORE

EXPLORE DETECTIONS

🔍
1,254 detections found

Service abuse: Settime.io sender with callback scam intent

Detects inbound messages from noreply@settime.io that exhibit callback scam characteristics, as identified by natural language understanding with medium or high confidence. Settime.io is a scheduling service that can be abused to send fraudulent messages prompting recipients to call a phone number controlled by threat actors.

T1566.003T1598T1566
Sublimemedium

Service abuse: Soundestlink redirect with suspicious indicators

Detects messages containing Soundestlink redirect links that lack proper unsubscribe mechanisms, and lack standard mailing list headers, indicating potential abuse of the service.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimemedium

Service abuse: Soundestlink.com Microsoft impersonation

Detects links or extracted domains hosted on soundestlink.com where the subdomain contains Microsoft-related keywords such as 'microsoft', 'teams', 'login', 'office', '365', or 'outlook'. This pattern indicates abuse of a legitimate link redirection/tracking service to disguise malicious URLs as Microsoft login or authentication pages, a common technique used to harvest credentials.

T1566T1566.001T1566.002T1598T1598.003+1
Sublimemedium

Service abuse: Square marketing with suspicious QR code

Detects messages from Square's marketing domain containing QR codes that redirect to self-service creation platforms, file sharing services, or image hosting services.

T1566T1566.001T1566.002T1598
Sublimehigh

Service abuse: Substack credential theft with confusable characters and branded button redirects

Detects messages from Substack that use confusable characters in the sender display name, contain purple buttons or typical button classes that redirect to non-Substack domains, and include credential theft content with urgency indicators.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Service abuse: SurveyMonkey survey from newly registered domain

This Attack Surface Reduction (ASR) rule matches on SurveyMonkey Surveys with recently registered reply-to domains.

T1566T1566.001T1566.002T1598T1036+1
Sublimehigh

Service abuse: SurveyMonkey with suspicious outbound links

Detects messages sent from SurveyMonkey's user domain that contain links to non-SurveyMonkey domains within nested table elements, excluding survey-related content.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium

Service abuse: Suspicious Datadog alert

Message from alert@dtdg.co containing links to URL shorteners or self-service creation platforms.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimehigh

Service abuse: Suspicious Zoom Docs link

Detects messages from Zoom Docs in which the document originates from a newly observed email address or contains suspicious indicators.

T1566T1566.001T1566.002T1598T1036+1
Sublimelow

Service abuse: Task management message sent via SendGrid

Detects messages impersonating task or productivity applications by using 'todo list' in the subject line or body while utilizing SendGrid infrastructure. The sender claims to be task-related through display name or body content but originates from non-legitimate domains without proper DMARC authentication.

T1566T1566.001T1566.002T1598T1598.003+2
Sublimemedium

Service abuse: Trello board invitation with VIP impersonation

Detects fraudulent Trello board invitations that impersonate organization VIPs by using organization domain names in board titles and including notes purportedly from legitimate company executives.

T1566T1566.001T1566.002T1598T1534
Sublimemedium

Service abuse: Vimeo with external plain-text links in message

Detects messages absuing Vimeo notifications about received messages that contain plain-text links redirecting to domains other than Vimeo, potentially leading users to malicious websites.

T1566T1566.001T1566.002T1598T1598.003
Sublimehigh

Service abuse: WeTransfer callback scam

Detects callback scams originating from legitimate WeTransfer noreply address using natural language processing to identify high-confidence callback scam intent in the message body.

T1566.003T1598T1566
Sublimemedium

Service abuse: Wix redirect through bulk mailer domains

Detects messages containing Wix-encoded links that redirect through bulk mailing service domains, potentially bypassing security controls through legitimate redirect services.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimelow

Service abuse: Wufoo credential theft

Detects malicious messages sent from Wufoo's sending address (no-reply@wufoo.com) that are abusing the platform to deliver credential theft content. This rule identifies messages that lack Wufoo's standard display name and structural HTML elements found in legitimate Wufoo emails, while containing links and content classified as credential theft by NLU analysis.

T1566T1566.001T1566.002T1598
Sublimemedium

Service abuse: Zohodesk reply-to mismatch with job scam indicators

Detects inbound messages sent from Zohodesk infrastructure where the reply-to address points to a domain outside of Zohodesk, combined with natural language signals indicating job scam content. This technique abuses legitimate Zohodesk services to add credibility while redirecting responses to an external actor-controlled address.

T1566.002T1534T1656T1566T1598
Sublimemedium

Service abuse: Zoom Clips with suspicious reply-to address or links

Detects legitimate-looking Zoom 'Clips shared' notifications sent from Zoom's genuine no-reply infrastructure, where the underlying reply-to address or embedded links show signs of abuse. This includes reply-to domains that very recently created, links pointing to scheduling services like Cal.com, Calendly, or Vasta, or unsolicited reply-to senders — all indicating the legitimate clip-sharing feature is being leveraged to route victims to attacker-controlled contact points.

T1566T1598T1036T1027
Sublimelow

Service Abuse: Zoom with freemail reply-to and recipient address in greeting

Detects messages impersonating Zoom that use a freemail provider for the reply-to address, have a new and unsolicited reply-to profile, and contain the recipient's email address in the greeting line where a name would normally appear.

T1566T1598
Sublimemedium

Service abuse: Zoom with newly registered reply-to domain

Detects messages from legitimate Zoom infrastructure (no-reply@zoom.us) that contain a reply-to address with a domain registered within the last 45 days, indicating potential abuse of Zoom's service for malicious purposes.

T1566T1598T1036T1027
Sublimemedium

Sharepoint file share with suspicious recipients pattern

This rule detects messages originating from sharepoint.com with undisclosed recipients that are attempting to solicit the user to click a link. This has been observed in the event of an account compromise where the compromised account was utilizing legitimate file sharing services to share malicious links.

T1566T1566.001T1566.002T1598T1204.002+3
Sublimemedium

Sharepoint link likely unrelated to sender

Detects when a sender links to a Sharepoint file where the subdomain significantly differs from the sender's domain. The rule checks for OneNote, PDF, or unknown file types and includes various domain validation checks.

T1566.002T1534T1656T1566T1566.001+2
Sublimemedium

Sharepoint online with external recipients and external display name

An email from Sharepoint Online that was sent to multiple recipients that did not originate from a sender, by display name, in your organization.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

SharePoint OTP for filename matching org name

Detects Microsoft One-Time Passcode (OTP) messages where the shared document’s filename matches the sending organization's name. This typically indicates the recipient has verified their email address and is about to access a SharePoint file. Matching the document name to the sender's org is a pattern observed in multi-stage credential phishing campaigns, where attackers use branded file names to increase credibility and lure users into interacting with malicious content.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium

Shopify infrastructure abuse

Attackers have been observed using myshopify.com links to bypass domain reputation checks.

T1566T1566.001T1566.002T1598T1036+2
Sublimemedium
PreviousPage 48 of 53Next