Browse Rules

Search and filter across all detection sources

165 rules

sagan medium other

[EXTRAHOP] Unusual Email Domain Length

[EXTRAHOP] Unusual Email Domain Length

sagan informational other

[GCP] *Critical and Call* Email Forwarding Outside Domain

[GCP] *Critical and Call* Email Forwarding Outside Domain

sentinel medium kql

TI Map Domain entity to EmailEvents

Identifies a match in EmailEvents table from any Domain IOC from TI

sentinel medium kql

TI map Domain entity to EmailEvents

Identifies a match in EmailEvents table from any Domain IOC from TI

sentinel medium kql

TI Map Domain entity to EmailUrlInfo

'Identifies a match in EmailUrlInfo table from any Domain IOC from TI.'

sentinel medium kql

TI map Domain entity to EmailUrlInfo

'Identifies a match in EmailUrlInfo table from any Domain IOC from TI.'

sagan medium other

[MSAPI-EXCHANGE] Domain Wide Emails Moved to Deleted Items v1

[MSAPI-EXCHANGE] Domain Wide Emails Moved to Deleted Items v1

sagan medium other

[MSAPI-EXCHANGE] Domain Wide Emails Moved to Deleted Items v2

[MSAPI-EXCHANGE] Domain Wide Emails Moved to Deleted Items v2

panther low python

Asana Workspace Email Domain Added

A new email domain has been added to an Asana workspace. Reviewer should validate that the new domain is a part of the organization.

sigma medium sigma

Google Workspace Out Of Domain Email Forwarding

Detects automatic email forwarding to external domains in Google Workspace, which may indicate data leakage or misuse.

splunk unknown spl

Gsuite Outbound Email With Attachment To External Domain

The following analytic detects outbound emails with attachments sent from an internal email domain to an external domain. It leverages Gsuite Gmail logs, parsing the source and destination email domains, and flags emails with fewer than 20 outbound instances. This activity is significant as it may indicate potential data exfiltration or insider threats. If confirmed malicious, an attacker could use this method to exfiltrate sensitive information, leading to data breaches and compliance violation

sublime high mql

Link: Observed URL pattern with specific domain registrar

Detects messages using Element Email service infrastructure, identified by characteristic URL patterns with /f/ paths, unsubscribe links, single domain usage, and Cloudflare domain registration. This pattern indicates potential abuse of legitimate email marketing services.

chronicle high yara-l

Google Workspace File Shared From Google Drive To Free Email Domain

Identifies when a user shares a file on Google Drive with a free email domain, which may indicate data exfiltration.

panther low python

GCP Corporate Email Not Used

Unexpected domain is being used instead of a corporate email

chronicle high yara-l

GitHub Invitation Sent To Non Company Email Domain

Detects when an invitation to join a GitHub enterprise or organization is sent to a non-company email address. This rule can be customized to alert you when a GitHub invitation is sent to an unexpected domain i.e. not one of your company's domains used for email.

panther medium python

Gsuite Mail forwarded to external domain

A user has configured mail forwarding to an external domain

elastic high kql

Elastic Defend and Email Alerts Correlation

This rule correlates any Elastic Defend alert with an email security related alert by target user name. This may indicate the successful execution of a phishing attack.

chronicle high yara-l

Google Workspace Multiple Files Sent As Email Attachments From Google Drive

Identifies when a user sends multiple files from Google Drive as an email attachment to a free email domain, which may indicate data exfiltration.

sublime low mql

Spam: Default Microsoft Exchange Online sender domain (onmicrosoft.com)

The default Microsoft Exchange Online sender domain, onmicrosoft.com, is commonly used to send unwanted and malicious email. Enable this rule in your environment if receiving email from the onmicrosoft.com domain is unexpected behaviour.

sentinel high kql

VTI - High Severity Domain Collision Detection

This will alert when a collision is detected for EmailUrlInfo events with VTI high severity domain IoCs

mdecrevoisier high sigma

Office 365 email forwarding rule to external domain

Detects scenarios where an attacker creates a forwarding rules to a non company email in order to collect information.

sentinel medium kql

Red Sift - Email with URL to previously unseen domain

'Detects email forensics events containing one or more URLs whose domain has not been seen in the previous 14 days, which may indicate newly observed phishing infrastructure or suspicious delivery patterns.'

sentinel medium kql

ProofpointPOD - Possible data exfiltration to private email

'Detects when sender sent email to the non-corporate domain and recipient's username is the same as sender's username.'

hayabusa high sigma

Suspicious Download from Office Domain

Detects suspicious ways to download files from Microsoft domains that are used to store attachments in Emails or OneNote documents

sigma high sigma

Suspicious Download from Office Domain

Detects suspicious ways to download files from Microsoft domains that are used to store attachments in Emails or OneNote documents