Search and filter across all detection sources
101 rules
Brand impersonation: Hulu
Impersonation of Hulu.
Brand impersonation: KnowBe4
Impersonation of KnowBe4.
Brand Impersonation: PayPal
Impersonation of PayPal.
Brand impersonation: PNC
Impersonation of PNC Financial Services
Brand impersonation: Quickbooks
Impersonation of the Quickbooks service from Intuit.
Brand impersonation: Gusto
Impersonation of Gusto, a cloud-based payroll management company.
Brand impersonation: Okta
Impersonation of Okta, an identity and access management company.
Brand impersonation: USPS
Impersonation of the United States Postal Service.
Credential phishing link (unknown sender)
Message contains a link to a credential phishing page from an unknown sender.
Link: Credential phishing link with undisclosed recipients
This rule detects messages with "Undisclosed Recipients" that contain a link to a credential phishing page.
Brand impersonation: Coinbase with suspicious links
Detects messages impersonating Coinbase with low reputation or url shortened links.
Attachment: HTML smuggling - QR Code with suspicious links
This rule detects messages with HTML attachments containing QR codes
Brand impersonation: Sharepoint
Body, attached images or pdf contains a Sharepoint logo. The message contains a link and credential theft language.
Extortion / sextortion in attachment from untrusted sender
Detects extortion and sextortion attempts by analyzing attachment text from an untrusted sender.
Brand impersonation: Adobe with suspicious language and link
Email contains an Adobe logo, at least one link, and suspicious link language from a new sender.
Brand impersonation: Microsoft fake sign-in alert
Detects messages impersonating Microsoft that mimic sign-in security alerts and attempt to solicit a response.
Brand impersonation: Sharepoint fake file share
This rule detects messages impersonating a Sharepoint file sharing email where no links point to known Microsoft domains.
Link: Credential phishing via WordPress
Detects when non-WordPress senders link to suspended or malicious WordPress blog sites, commonly used to redirect users to credential harvesting pages.
Link: QuickBooks image lure with suspicious link
This rule detects messages with image attachments containing QuickBooks logo containing exactly 1 link to a suspicious URL.
Brand impersonation: Square
Impersonation of Square, typically containing security-related language, secure message notifications, or credential theft indicators from unauthorized senders.
Brand impersonation: Google Drive fake file share
This rule detects messages impersonating a Google Drive file sharing email where no links point to known Google domains.
Brand impersonation: Google fake sign-in warning
Detects messages with image attachments containing fake Google sign-in warnings with no links leading to Google sites.
Brand impersonation: Microsoft quarantine release notification in body
Message containing suspicious quarantine release language in the body, and a Microsoft logo attachment but did not come from Microsoft.
Brand impersonation: UPS
Detects messages impersonating UPS (United Parcel Service) through display name, email address patterns, subject content, or HTML styling that mimics UPS branding, while excluding legitimate UPS domains.
Brand Impersonation: Disney
Detects messages from senders impersonating Disney through display name spoofing or brand logo usage, combined with security-themed content and suspicious authentication patterns.