Browse Rules

Search and filter across all detection sources

256 rules

sublime low mql

BEC/Fraud: Scam lure with freemail pivot

This message detects BEC/Fraud lures attempting to solicit the victim to pivot out of band via a freemail address in the body.

sublime low mql

Honorific greeting BEC attempt with sender and reply-to mismatch

Detects generic BEC/Fraud scams by analyzing text within the email body from mismatched senders with other suspicious indicators.

sublime low mql

BEC/Fraud: Generic scam attempt to undisclosed recipients

Detects potential generic scams by analyzing text within the email body and other suspicious signals.

sublime medium mql

BEC/Fraud: Unsolicited business acquisition offer

Detects inbound messages with subjects referencing an offer to purchase, combined with body content mentioning private equity, acquiring companies, or discussing an opportunity. These messages are characteristic of fraudulent or unsolicited business acquisition solicitations designed to engage targets in fraudulent financial dealings.

sublime medium mql

Business Email Compromise (BEC) attempt from untrusted sender (French/Français)

Detects potential Business Email Compromise (BEC) attacks by searching for common French BEC language within the email body from first-time senders.

sublime high mql

BEC: Employee impersonation with subject manipulation

Subject matches the display name of someone in your organization, and the body resembles a BEC attack.

sublime medium mql

Business Email Compromise (BEC) attempt from unsolicited sender

Detects potential Business Email Compromise (BEC) attacks by analyzing text within the email body from unsolicited senders.

sublime medium mql

Brand impersonation: Mailgun

Impersonation of the Mailgun Email delivery platform.

sublime medium mql

Business Email Compromise (BEC) attempt from untrusted sender

Detects potential Business Email Compromise (BEC) attacks by analyzing text within the email body from first-time senders.

sublime medium mql

BEC/Fraud: Fake investment outreach from suspicious TLD

Detects unsolicited investment/funding outreach emails from suspicious TLDs. Targets mass-mailed spam campaigns offering business funding, capital allocation, and family office outreach.

sublime medium mql

BEC/Fraud: Job scam fake thread or plaintext pivot to freemail

Detects potential job scams using plaintext or fake threads attempting to pivot to a freemail address from an unsolicited sender.

sublime medium mql

COVID-19 themed fraud with sender and reply-to mismatch or compensation award

Detects potential COVID-19 themed BEC/Fraud scams by analyzing text within the email body for mentions of COVID-19 assistance, compensation, or awards from mismatched senders and other suspicious language.

sublime medium mql

BEC: Executive coaching vendor impersonation

Detects fraudulent messages impersonating leadership development coaching services. The rule identifies inbound messages referencing coaching and executive services terminology alongside financial indicators such as invoices and W-9 forms. Natural language understanding is used to confirm high-confidence financial communication intent and BEC signals.

sublime medium mql

File sharing link with a suspicious subject

A file sharing link in the body with a common BEC subject. This rule could be expanded to include additional BEC subjects.

sublime high mql

Employee impersonation: Payroll fraud

This rule detects messages impersonating employees, from unsolicited senders attempting to reroute payroll or alter payment details.

sublime medium mql

Advance Fee Fraud (AFF) from freemail provider or suspicious TLD

Advance Fee Fraud (AFF) is a type of BEC/Fraud involving upfront fees for promised future returns, such as lottery scams, inheritance payouts, and investment opportunities. This rule identifies messages from Freemail domains or suspicious TLDS, including those with suspicious reply-to addresses. It utilizes Natural Language Understanding to detect AFF language in their contents.

sublime medium mql

BEC/Fraud: Reply-chain manipulation with urgent keywords and self-reply

Detects suspicious reply messages with urgent language in sender name or email address, minimal body content, and the sender's email address appearing in previous thread content, indicating a self reply.

sublime high mql

Callback phishing: SumUp infrastructure abuse

A fraudulent invoice/receipt found in the body of the message sent by exploiting SumUp's receipt email service.

sublime medium mql

Callback phishing via Zelle Service Abuse

Callback phishing campaigns have been observed abusing Zelle services to send fraudulent payment requests with callback phishing contents.

sublime medium mql

Tax Form: W-8BEN solicitation

Detects messages containing references to W-8BEN tax forms, commonly used in tax-related fraud schemes targeting individuals and businesses.

sublime medium mql

Brand impersonation: Enbridge

Impersonation of the Canadian energy company Enbridge.

sublime medium mql

BEC/Fraud: Penpal scam

This rule detects messages from individuals looking to establish contact under the guise of seeking friendship or a penpal relationship. Over time, they build trust and then exploit this relationship by asking for money, personal information, or involvement in suspicious activities.

sublime medium mql

Business Email Compromise (BEC) with request for mobile number

This rule detects unsolicited messages with a small plain text body, that is attempting to solicit a mobile number.

sublime medium mql

BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns

Identifies inbound messages using urgent language patterns and sender behavioral traits common in social manipulation. Combines multiple indicators including urgent subject lines, characteristic message content, short message length, and suspicious sender attributes.

sublime high mql

Attachment: RFP/RFQ impersonating government entities

Attached RFP/RFQ impersonates a U.S. government department or entity to commit fraudulent transactions.