Browse Rules

Search and filter across all detection sources

832 rules

sublime medium mql

Attachment: HTML smuggling with hex strings

Recursively scans files and archives to detect HTML smuggling using hex-encoded string content.

sublime medium mql

Abuse: Robinhood injected content

Detects messages from Robinhood with injected HTML into one of the list fields, often the 'Device' field.

sublime medium mql

Brand Impersonation: Gemini Trust Company

Detects messages impersonating Gemini Trust Company through analysis of footer content, social media links, and address verification, excluding legitimate communications from authenticated Gemini domains.

sublime low mql

Spam: Sexually explicit content with emoji in subject from freemail provider

Detects messages from free email providers that contain sexually explicit content and include emojis in the subject line.

sublime medium mql

Brand impersonation: Microsoft Planner with suspicious link

Impersonation of Microsoft Planner, a component of the Microsoft 365 software suite.

sublime medium mql

Brand impersonation: Dropbox

Impersonation of Dropbox, a file sharing service.

sublime medium mql

Brand Impersonation: PayPal

Impersonation of PayPal.

sublime high mql

Image as content with a link to an open redirect

Body contains little, no, or only disclaimer text, an image, and a link to an open redirect.

sublime high mql

Link: Executable file download with suspicious message content

Detects inbound messages containing links to executable files combined with high-confidence security, financial, or credential theft content indicators, while excluding legitimate trusted domains with proper DMARC authentication.

sublime high mql

Attachment: Emotet heavily padded doc in zip file

Detects a potential Emotet delivery method using padded .doc files that compress into small zip files. Contents may include Red Dawn templates exceeding 500MB.

sublime high mql

Link: Multistage landing - Trello board abuse

Detects suspicious Trello board links containing malicious indicators such as credential theft content, blocked users, malicious attachments, or boards with minimal content from unsolicited senders.

sublime medium mql

Attachment: Fake secure message and suspicious indicators

Body contains language resembling credential theft, and an attached "secure message" from an untrusted sender.

sublime medium mql

Brand impersonation: Coinbase with suspicious links

Detects messages impersonating Coinbase with low reputation or url shortened links.

sublime low mql

Spam: URL shortener with short body content and emojis

Detects spam from freemail senders, where the majority of the body is a URL shortener and emojis.

sublime high mql

Brand impersonation: USPS

Impersonation of the United States Postal Service.

sublime medium mql

Brand impersonation: Microsoft with low reputation links

Detects low reputation links with Microsoft specific indicators in the body.

sublime medium mql

Callback phishing via Zelle Service Abuse

Callback phishing campaigns have been observed abusing Zelle services to send fraudulent payment requests with callback phishing contents.

sublime medium mql

Service abuse: SurveyMonkey with suspicious outbound links

Detects messages sent from SurveyMonkey's user domain that contain links to non-SurveyMonkey domains within nested table elements, excluding survey-related content.

sublime low mql

Inline image as message with attachment or link

Using inline images in lieu of HTML or text content in the message is a known technique used to bypass content based scanning engines. We've observed this technique used to deliver malware via attachments and phish credentials.

sublime high mql

Brand impersonation: Microsoft

Impersonation of the Microsoft brand.

sublime medium mql

Brand impersonation: Robinhood

Detects messages impersonating Robinhood by analyzing sender display name, domain, body content including specific address references, and social media links, while excluding legitimate Robinhood communications with proper DMARC authentication.

sublime medium mql

Brand impersonation: Enbridge

Impersonation of the Canadian energy company Enbridge.

sublime medium mql

Brand impersonation: PNC

Impersonation of PNC Financial Services

sublime high mql

Attachment: Office document with VSTO add-in

Recursively scans files and archives to detect Office documents with VSTO Add-ins.

sublime high mql

Attachment: PowerShell content

Recursively scans files and archives to detect PowerShell content. While scripts are often blocked by mail filtering, alternative file formats and archived content may be employed to bypass such controls.