Browse Rules

Search and filter across all detection sources

206 rules

sagan informational other

[SOPHOS] Credential theft attempt resolved

[SOPHOS] Credential theft attempt resolved

sagan informational other

[SOPHOS] We prevented credential theft

[SOPHOS] We prevented credential theft

sagan medium other

[EXTRAHOP] AD Credential Theft with ntdsutil

[EXTRAHOP] AD Credential Theft with ntdsutil

sublime high mql

Impersonation: DMARC failure with high confidence credential theft intent

Detects DMARC failures and messages with a high confidence of credential theft

sublime high mql

EML attachment with credential theft language (unknown sender)

Identifies EML attachments that use credential theft language from unknown senders.

panther high python

GAIA GCPW Credential Theft Attack Chain

Detects the GAIA (Google Account Information and Authentication) credential theft attack chain: credential dumping tool execution on Windows followed by anomalous Google Workspace authentication. This pattern indicates an attacker has extracted OAuth refresh tokens from a Windows machine and is using them to authenticate to Google Workspace.

sublime medium mql

Service abuse: SendThisFile with credential theft and financial language

Detects messages from sendthisfile.com containing credential theft language combined with financial communications topics.

sublime medium mql

Attachment: PDF with credential theft language and link to a free subdomain (unsolicited)

Detects messages with credential theft PDFs linking to free subdomains.

sublime high mql

Brand impersonation: Microsoft with embedded logo and credential theft language

This rule detects messages impersonating Microsoft via a logo and contains credential theft language. From a new and unsolicited sender.

sublime high mql

Link: Credential theft with Cloudflare tunnel and recipient targeting

Detects messages containing credential theft language and links to trycloudflare.com tunnels that include the recipient's email address in the URL path, indicating personalized targeting for credential harvesting.

sublime medium mql

Attachment: Encrypted PDF with credential theft body

Attached PDF is encrypted, and email body contains credential theft language. Seen in-the-wild impersonating e-fax services.

sublime medium mql

Link: Google Forms link with credential theft language

Detects messages containing Google Forms links paired with credential theft language from new senders. This technique abuses Google's trusted domain to host malicious forms designed to steal user credentials.

sublime high mql

Attachment: PDF proposal with credential theft indicators

PDF attachment with 'proposal' in filename contains sender or recipient domain, credential theft language detected via OCR, and includes a single URL link.

sublime medium mql

Brand impersonation: Survey request with credential theft indicators

Detects messages containing credential theft language disguised as survey requests from promotional content, targeting organizations from untrusted or spoofed high-trust domains.

sublime medium mql

Service abuse: FlipHTML5 with attachment deception and credential theft language

Detects messages that reference attachments without including any, contain links to FlipHTML5 services, and exhibit high-confidence credential theft language patterns.

sublime high mql

Brand Impersonation: Stripe

Impersonation of Stripe, usually for credential theft.

sublime high mql

Link: Self-sender credential theft with configuration placeholder

Detects messages where the sender and recipient are the same address, containing credential theft language and links with configuration placeholder text indicating a phishing lure.

sublime medium mql

Suspicious recipients pattern with NLU credential theft indicators

Detects messages with undisclosed recipients (likely all bcc) and NLU identified a credential theft intent with medium to high confidence from a suspicious low reputation link domain

sublime medium mql

Service abuse: Wufoo credential theft

Detects malicious messages sent from Wufoo's sending address (no-reply@wufoo.com) that are abusing the platform to deliver credential theft content. This rule identifies messages that lack Wufoo's standard display name and structural HTML elements found in legitimate Wufoo emails, while containing links and content classified as credential theft by NLU analysis.

sublime medium mql

Attachment: PDF with credential theft language and invalid reply-to domain

Detects PDF attachments containing high-confidence credential theft language that references the recipient's email address, combined with an invalid reply-to domain header.

sublime high mql

Headers: Self-sender using Microsoft CompAuth bypass with credential theft content

Detects messages sent to self or invalid domains containing credential theft content that bypass Microsoft's CompAuth while failing both SPF and DMARC authentication checks.

sublime low mql

Link: URL shortener with copy-paste instructions and credential theft language

Detects messages containing only URL shorteners with copy-paste instructions and high-confidence credential theft language, typically used to evade URL analysis by requiring manual URL entry.

sublime medium mql

Brand impersonation: Blockchain.com

Impersonation of Blockchain.com, usually for credential theft.

sublime high mql

Link: HR impersonation with suspicious domain indicators and credential theft

Detects messages impersonating HR departments containing many links with malformed domains, suspicious TLD patterns, and credential theft language detected through URL analysis.

sublime medium mql

Credential phishing: 'Secure message' and engaging language

Body contains language resembling credential theft, and a "secure message" from an untrusted sender.