Browse Rules

Search and filter across all detection sources

101 rules

sublime medium mql

Brand impersonation: Hulu

Impersonation of Hulu.

sublime medium mql

Brand impersonation: KnowBe4

Impersonation of KnowBe4.

sublime medium mql

Brand Impersonation: PayPal

Impersonation of PayPal.

sublime medium mql

Brand impersonation: PNC

Impersonation of PNC Financial Services

sublime medium mql

Brand impersonation: Quickbooks

Impersonation of the Quickbooks service from Intuit.

sublime medium mql

Brand impersonation: Gusto

Impersonation of Gusto, a cloud-based payroll management company.

sublime medium mql

Brand impersonation: Okta

Impersonation of Okta, an identity and access management company.

sublime high mql

Brand impersonation: USPS

Impersonation of the United States Postal Service.

sublime high mql

Credential phishing link (unknown sender)

Message contains a link to a credential phishing page from an unknown sender.

sublime medium mql

Link: Credential phishing link with undisclosed recipients

This rule detects messages with "Undisclosed Recipients" that contain a link to a credential phishing page.

sublime medium mql

Brand impersonation: Coinbase with suspicious links

Detects messages impersonating Coinbase with low reputation or url shortened links.

sublime high mql

Attachment: HTML smuggling - QR Code with suspicious links

This rule detects messages with HTML attachments containing QR codes

sublime high mql

Brand impersonation: Sharepoint

Body, attached images or pdf contains a Sharepoint logo. The message contains a link and credential theft language.

sublime low mql

Extortion / sextortion in attachment from untrusted sender

Detects extortion and sextortion attempts by analyzing attachment text from an untrusted sender.

sublime high mql

Brand impersonation: Adobe with suspicious language and link

Email contains an Adobe logo, at least one link, and suspicious link language from a new sender.

sublime medium mql

Brand impersonation: Microsoft fake sign-in alert

Detects messages impersonating Microsoft that mimic sign-in security alerts and attempt to solicit a response.

sublime medium mql

Brand impersonation: Sharepoint fake file share

This rule detects messages impersonating a Sharepoint file sharing email where no links point to known Microsoft domains.

sublime high mql

Link: Credential phishing via WordPress

Detects when non-WordPress senders link to suspended or malicious WordPress blog sites, commonly used to redirect users to credential harvesting pages.

sublime medium mql

Link: QuickBooks image lure with suspicious link

This rule detects messages with image attachments containing QuickBooks logo containing exactly 1 link to a suspicious URL.

sublime medium mql

Brand impersonation: Square

Impersonation of Square, typically containing security-related language, secure message notifications, or credential theft indicators from unauthorized senders.

sublime medium mql

Brand impersonation: Google Drive fake file share

This rule detects messages impersonating a Google Drive file sharing email where no links point to known Google domains.

sublime high mql

Brand impersonation: Google fake sign-in warning

Detects messages with image attachments containing fake Google sign-in warnings with no links leading to Google sites.

sublime high mql

Brand impersonation: Microsoft quarantine release notification in body

Message containing suspicious quarantine release language in the body, and a Microsoft logo attachment but did not come from Microsoft.

sublime low mql

Brand impersonation: UPS

Detects messages impersonating UPS (United Parcel Service) through display name, email address patterns, subject content, or HTML styling that mimics UPS branding, while excluding legitimate UPS domains.

sublime medium mql

Brand Impersonation: Disney

Detects messages from senders impersonating Disney through display name spoofing or brand logo usage, combined with security-themed content and suspicious authentication patterns.