EXPLORE

EXPLORE DETECTIONS

🔍
1,254 detections found

VIP impersonation: VIP recipient of previous thread with HTML generator

Detects inbound messages that impersonate invoice communications impersonating organizational VIPs, where the message appears in a thread previously involving VIP recipients. The rule identifies a specific template technique where the HTML body contains markers associated with 'Advanced HTML parser' tooling or a suspicious '<title>HTML Message</title>' tag. Both are artifacts commonly left by tools used to craft or obfuscate invoice lure content. Observed samples spoof leadership-recognition invoice themes naming specific executives as the invoiced party.

T1566.002T1534T1656T1566T1598+2
Sublimehigh

VIP local_part impersonation from unsolicited sender

This rule identifies potential impersonation attempts involving the local part of an $org_vip email address. Specifically, it checks for cases where the local part of an $org_vip email (e.g., local_part@domain.com) appears with a different domain (e.g., local_part@foreigndomain.com). Additionally, the rule flags messages that match an $org_vip address exactly but fail authentication.

T1566.002T1534T1566T1598
Sublimehigh

X (Twitter) impersonation with credential phishing motives

This rule is designed to identify impersonation attempts by analyzing the display name or sender's local part for the solitary use of "X" provided the email doesn't originate from twitter.com or x.com. Natural Language Understanding (NLU) is used to check for credential theft requiring a medium-to-high confidence level for flagging.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium

Xero infrastructure abuse

Identifies messages that resemble credential theft, originating from Xero. Xero infrastrcture abuse has been observed recently to send phishing attacks.

T1566T1566.001T1566.002T1598T1036+1
Sublimemedium

Xero invoice abuse

Detects suspicious Xero invoice communications containing urgent payment requests where the sender's display name contains either confusable characters or impersonates internal services like HR or IT support.

T1566.002T1534T1656T1566T1566.001+2
Sublimemedium

Zoom Events newsletter abuse

Detects suspicious content in Zoom Events notifications that contain credential theft language and links to file hosting sites.

T1566T1566.001T1566.002T1598T1598.003
Sublimemedium
PreviousPage 53 of 53