EXPLORE

EXPLORE DETECTIONS

🔍
1,254 detections found

Suspicious invoice reference with missing or image-only attachments

This rule flags emails that reference invoices or payments but have suspicious characteristics: attachments are either missing or only images. It also checks for misleading links disguised as attachments and the presence of invoice-related keywords. The rule looks for potential credential theft or unusual requests, making it a strong indicator of phishing attempts.

T1566T1566.001T1566.002T1598
Sublimehigh

Suspicious link to Looker Studio (lookerstudio.google.com) from a new and unsolicited sender

This rule detects messages containing links to lookerstudio with a non standard lookerstudio template from a new and unsolicited sender.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Suspicious Link to TLD with Iranian Manticore Signals

Detects messages containing links to specific top-level domains (.online, .best, .info, .xyz, .fashion, .fit) that also exhibit technical indicators associated with Iranian Educated Manticore activity, including specific API calls and React debug messages.

T1566T1566.001T1566.002T1598T1036+1
Sublimelow

Suspicious Links to Cloudflare R2 and Edge Services

Detects links to Cloudflare R2 storage buckets, Pages, and Workers domains from unsolicited or previously malicious senders who are not on a trusted sender list or have failed DMARC authentication.

T1566.002T1534T1656T1566.003T1598+5
Sublimemedium

Suspicious mailer received from Gmail servers

Mailer is atypical of sends from Gmail infrastructure. Observed sending callback phishing and general spam.

T1566.003T1598T1566
Sublimelow

Suspicious message with unscannable Cloudflare link

This rule detects messages with unscannable links to cloudflare infrastructure with suspicious indicators in the subject or display name from an unsolicited sender.

T1566T1566.001T1566.002T1598
Sublimemedium

Suspicious message with unscannable Vercel link

This rule detects messages with unscannable links to Vercel infrastructure with suspicious indicators in the subject or display name from an unsolicited sender.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Suspicious newly registered reply-to domain with engaging financial or urgent language

Detects messages from a mismatched newly registered Reply-to domain that contain a financial or urgent request, or a request and an NLU tag with medium to high confidence, from an untrusted sender. This technique is typically observed in Vendor impersonation.

T1566.002T1534T1656T1566T1598
Sublimemedium

Suspicious Office 365 app authorization (OAuth) link

Message contains a suspicious Office 365 app authorization (OAuth) link. The app may be compromised or was stood up for malicious purposes. Once the app has been authorized, the attacker will have read or write permissions to the user's Office 365 account.

T1566T1566.001T1566.002T1598
Sublimehigh

Suspicious recipient pattern and language with low reputation link to login

Message contains a suspicious recipient pattern, financial or urgent language, and a suspicious link, with a login page and confusable characters or multiple redirects.

T1566T1566.001T1566.002T1598
Sublimemedium

Suspicious recipients pattern with NLU credential theft indicators

Detects messages with undisclosed recipients (likely all bcc) and NLU identified a credential theft intent with medium to high confidence from a suspicious low reputation link domain

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Suspicious recipients pattern with no Compauth pass and suspicious content

Detects messages with undisclosed recipients (likely all bcc), where the Compauth verdict is not 'pass', and ML has identified suspicious language or credential phishing links.

Sublimemedium

Suspicious request for financial information

Email is from a suspicious sender and contains a request for financial information, such as AR reports.

T1566.002T1534T1656T1566T1598
Sublimehigh

Suspicious sender display name with long procedurally generated text blob

This rule identifies sender display names containing long strings of nonsensical or procedurally generated characters, which are often used in phishing or spam campaigns for campaign tracking and identification, as well as to bypass detection filters.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Suspicious SharePoint file sharing

This rule detect potential credential phishing leveraging SharePoint file sharing to deliver a PDF, OneNote, or Unknown file type file using indicators such as suspicious sender analysis and link characteristics.

T1566T1566.001T1566.002T1598
Sublimemedium

Suspicious subject with long procedurally generated text blob

This rule identifies subjects containing long strings of nonsensical or procedurally generated characters, which are often used in phishing or spam campaigns for campaign tracking and identification, as well as to bypass detection filters.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Suspicious VBA macros from untrusted sender

Detects any VBA macro attachment that scores above a medium confidence threshold in the Sublime Macro Classifier.

T1566.001T1204.002T1486T1059.005
Sublimehigh

Targeting: Specific AOL address

Message targeting a specific AOL address (me@aol.com) with a single recipient.

T1566T1598
Sublimemedium

Tax Form: W-8BEN solicitation

Detects messages containing references to W-8BEN tax forms, commonly used in tax-related fraud schemes targeting individuals and businesses.

T1566.002T1534T1656T1566T1566.001+1
Sublimemedium

Truth Social infrastructure abuse via link redirect

Email contains a Truth Social link (links.truthsocial.com) but does not originate from a Truth Social domain. This is a known malicious tactic.

T1566T1566.001T1566.002T1598T1204.002+4
Sublimemedium

Twitter infrastructure abuse via link shortener

Email contains Twitter shortened link (t.co) but does not originate from a Twitter domain. This is a known malicious and spam tactic.

T1566T1566.001T1566.002T1598T1204.002+4
Sublimemedium

Unicode QR code

Identifies messages leveraging Unicode block characters (between U+2580 - U+259F) arranged on consecutive lines to create QR codes. The rule inspects both the overall quantity and specific formatting of these characters, while considering the sender's historical behavior and reputation.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Unusually long local part from untrusted sender address

Detects messages with unusually long local address parts (before the @) from senders outside trusted domains and without verified authentication.

T1566T1566.001T1566.002T1598T1036+1
Sublimelow

URI protocol handler: search-ms

Detects HTML attachments using the search-ms URI protocol handler, a technique observed ITW to deliver malicious payloads. This rule can be updated to analyze links in PDF attachments and message bodies

T1566.001T1204.002T1486T1036T1027
Sublimehigh
PreviousPage 51 of 53Next