Browse Rules

Search and filter across all detection sources

108 rules

sublime high mql

Attachment: Office document with VSTO add-in

Recursively scans files and archives to detect Office documents with VSTO Add-ins.

sublime high mql

Attachment: HTML smuggling with setTimeout

Recursively scans files and archives to detect HTML smuggling techniques.

sublime high mql

Attachment: HTML attachment with Javascript location

Recursively scans files and archives to detect HTML smuggling techniques.

sublime high mql

Attachment: HTML smuggling with unescape

Recursively scans files and archives to detect HTML smuggling techniques.

sublime high mql

Attachment: HTML smuggling with eval and atob

Recursively scans files and archives to detect HTML smuggling techniques.

sublime high mql

Attachment: HTML smuggling with concatenation obfuscation

Recursively scans files and archives to detect HTML smuggling techniques.

sublime high mql

Attachment: HTML smuggling with fromCharCode and other signals

Recursively scans files and archives to detect HTML smuggling techniques.

sublime medium mql

Attachment with encrypted zip (unsolicited)

Recursively scans files and archives to detect encrypted zip files.

sublime high mql

Attachment: HTML smuggling with high entropy and other signals

Recursively scans files and archives to detect HTML smuggling techniques.

sublime medium mql

Attachment with auto-opening VBA macro (unsolicited)

Recursively scans files and archives to detect embedded VBA files with an auto open exec.

sublime medium mql

Attachment: HTML smuggling with hex strings

Recursively scans files and archives to detect HTML smuggling using hex-encoded string content.

sublime high mql

Attachment: HTML smuggling with atob and high entropy

Recursively scans files and archives to detect HTML smuggling techniques using Javascript atob functions.

sublime medium mql

Attachment: Office document loads remote document template

Recursively scans archives and Office documents to detect remote document template injection.

sublime high mql

Attachment: HTML smuggling with raw array buffer

Recursively scans files and archives to detect HTML smuggling techniques.

sublime low mql

Attachment: Archive containing disallowed file type

Recursively scans archives to detect disallowed file types. File extensions can be detected within password-protected archives. Attackers often embed malicious files within archives to bypass email gateway controls.

sublime medium mql

Link to auto-downloaded DMG in archive

A link in the body of the message downloads an archive containing a DMG file. The message is not from a common or trusted sender and is unsolicited.

sublime medium mql

Attachment: RTF file with suspicious link

This rule detects RTF attachments directly attached or within an archive, containing an external link to a suspicious low reputation domain.

sublime medium mql

Attachment: 7z Archive Containing RAR File

Detects 7z archive attachments that contain RAR files, which may be used to evade detection by nesting compressed file formats.

sublime medium mql

Attachment: Any HTML file within archive (unsolicited)

Recursively scans archives to detect HTML files from unsolicited senders. HTML files can be used for HTML smuggling and embedded in archives to evade detection.

sublime medium mql

Attachment: HTML attachment with login portal indicators

Recursively scans files and archives to detect indicators of login portals implemented in HTML files. This is a known credential theft technique used by threat actors.

sublime high mql

Attachment soliciting user to enable macros

Recursively scans files and archives to detect documents that ask the user to enable macros, including if that text appears within an embedded image.

sublime high mql

Attachment: PowerShell content

Recursively scans files and archives to detect PowerShell content. While scripts are often blocked by mail filtering, alternative file formats and archived content may be employed to bypass such controls.

sublime high mql

MalwareBazaar: Malicious attachment hash in archive (trusted reporters)

Detects if an arhive attachments contains a file that matches a SHA256 hash reported as malware on MalwareBazaar by trusted reporters.

sublime medium mql

Attachment with unscannable encrypted zip

Recursively scans files and archives to detect embedded ZIP files that are encrypted and could not be opened/scanned.

sublime high mql

Attachment: Archive contains DLL-loading macro

An attacker could send a trusted and signed document that references an untrusted DLL file, which will be loaded by the signed document.