Browse Rules

Search and filter across all detection sources

34 rules

sagan medium other

[Barracuda] Email Gateway Extortion Event Detected

[Barracuda] Email Gateway Extortion Event Detected

yara unknown yara

extortion_email [email]

Detects the possible extortion scam on the basis of subjects and keywords

sagan critical other

[PRISMA] Prisma Access Extortion/Ransomware Activity - Critical Severity

[PRISMA] Prisma Access Extortion/Ransomware Activity - Critical Severity

sagan critical other

[PRISMA] Prisma Access Extortion/Ransomware Activity - High Severity

[PRISMA] Prisma Access Extortion/Ransomware Activity - High Severity

sagan critical other

[PRISMA] Prisma Access Extortion/Ransomware Activity - Medium Severity

[PRISMA] Prisma Access Extortion/Ransomware Activity - Medium Severity

sublime low mql

Extortion / sextortion (untrusted sender)

Detects extortion and sextortion attempts by analyzing the email body text from an untrusted sender.

sublime medium mql

Service abuse: Elastic alerts extortion

Detects inbound messages impersonating Elastic alerts sender that contain extortion content identified through natural language processing with medium to high confidence.

sublime low mql

Extortion / sextortion in attachment from untrusted sender

Detects extortion and sextortion attempts by analyzing attachment text from an untrusted sender.

sublime medium mql

Service Abuse: GoDaddy infrastructure

Detects messages from legitimate GoDaddy domains with suspicious indicators. Observed abused for call back phishing and extortion campaigns.

sublime medium mql

Impersonation: Legal firm with copyright infringement notice

Detects messages impersonating legal firms or copyright enforcement entities with extensive legal terminology, threatening language, and urgent compliance demands.

chronicle unknown yara-l

nemty_successor_nefilimnephilim_ransomware

Ransomware families NEMTY, Nefilim and Nephilim continue to evolve and merge, taking on aspects of other successful variants that aim to encrypt and extort. License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.

sublime high mql

Potential prompt injection attack in body HTML

Detects messages containing references to major AI tools (like Gemini, Copilot, ChatGPT, or Claude) in non-standard HTML elements.

sublime medium mql

Mismatched links: Free file share with urgent language

Detects messages from first-time senders containing free file sharing links, multiple urgent language indicators, and mismatched link text.

elastic medium kql

PowerShell Script with Webcam Video Capture Capabilities

Detects PowerShell script block content that references webcam capture APIs or video capture device objects. Attackers use webcam recording to surveil victims or collect sensitive footage for extortion.

sublime high mql

Extortion / Sextortion - PDF attachment leveraging breach data from freemail sender

Detects sextortion attempts leveraging breach data, including names, addresses, phone numbers and frequently using Google Maps/Bing Maps streetview images to bolster confidence and fear.

elastic high kql

PowerShell Suspicious Script with Audio Capture Capabilities

Detects PowerShell script block content that invokes microphone capture routines or WinMM audio APIs. Adversaries may use audio recording to surveil users or capture sensitive conversations for theft or extortion.

sublime high mql

Brand impersonation: WeTransfer

Detects messages claiming to be from WeTransfer that contain suspicious indicators, including misspelled domains, non-standard TLDs, suspicious file reference numbers, and French language variations. Excludes legitimate WeTransfer traffic with valid DMARC authentication.

sublime high mql

Impersonation: Australian Federal Police with criminal case language

Detects messages impersonating the Australian Federal Police using law enforcement terminology in the subject and sender display name, combined with official correspondence language including case references, investigation details, and compliance demands.

sublime medium mql

Encrypted Microsoft Office files from untrusted sender

Detects encrypted Microsoft Office document attachments (Word, Excel, PowerPoint, Access) from untrusted senders or high-trust senders failing DMARC authentication, which may indicate an effort to bypass security scanning.

sublime medium mql

Brand impersonation: Vanguard

Detects inbound messages from senders using Vanguard-like display names or domains, excluding legitimate Vanguard domains and authenticated communications. Additional checks ensure the sender is not from trusted organizational domains or high-trust sender domains with proper authentication.

sublime medium mql

Suspicious Links to Cloudflare R2 and Edge Services

Detects links to Cloudflare R2 storage buckets, Pages, and Workers domains from unsolicited or previously malicious senders who are not on a trusted sender list or have failed DMARC authentication.

sentinel medium kql

CYFIRMA - Data Breach and Web Monitoring - Ransomware Exposure Detected Rule

"This analytics rule detects high-severity ransomware threats targeting the organization, as reported by CYFIRMA's Dark Web and Data Breach Intelligence feeds. The alert is generated when threat actors post, claim, or associate ransomware activity with corporate domains, brands, or subsidiaries, indicating a potential data breach, extortion attempt, or unauthorized access."

sentinel high kql

CYFIRMA - Data Breach and Web Monitoring - Ransomware Exposure Detected Rule

"This analytics rule detects high-severity ransomware threats targeting the organization, as reported by CYFIRMA's Dark Web and Data Breach Intelligence feeds. The alert is generated when threat actors post, claim, or associate ransomware activity with corporate domains, brands, or subsidiaries, indicating a potential data breach, extortion attempt, or unauthorized access."

sentinel high kql

Abnormal Security - High-risk email attack detected

'Identifies email attacks detected by Abnormal Security whose attack type maps to a high-risk category (credential phishing, Business Email Compromise, invoice/payment fraud, malware, extortion, sensitive-data phishing, internal account-takeover attacks, or scams). Lower-risk categories such as Spam, Graymail, and Reconnaissance are intentionally excluded. Use this to triage targeted email threats that reached a mailbox.'

sublime medium mql

Attachment: Legal themed message or PDF with suspicious indicators

Detects messages with short body content or emoji containing PDF attachments from suspicious creators that include legal and compliance language with embedded malicious links, URL shorteners, or newly registered domains.