Browse Rules

Search and filter across all detection sources

84 rules

sublime medium mql

Free email provider sender with mismatched provider reply-to

Detects when a sender using a free email provider includes a reply-to address from a different free email provider, which is a common social engineering tactic.

sublime medium mql

Service abuse: Free provider with SendGrid routing

Message From header includes a free email provider domain but is routed through SendGrid infrastructure, indicating potential service abuse for delivery evasion.

sublime medium mql

Link: Apple App Store malicious ad manager themed apps from free email provider

Detects messages containing Apple App Store links with sent from free email providers, indicating potential abuse of legitimate Apple services hosting malicious ad manager themed applications.

sublime low mql

Spam: Sexually explicit content with emoji in subject from freemail provider

Detects messages from free email providers that contain sexually explicit content and include emojis in the subject line.

sublime medium mql

Link: Apple TestFlight from suspicious sender

Detects messages containing Apple TestFlight links from free email providers or suspicious senders with no prior benign communication history.

sublime high mql

Brand impersonation: Zoom via lookalike domain

Message contains a single link which attempts to spoof a 'zoom' link, sent from a free email provider to a single recipient.

sublime high mql

Impersonation: Executive using numbered local part

Detects messages from free email providers where the sender's email address uses a pattern commonly associated with executive impersonation, containing 'chair' or 'ceo' followed by numbers in the local part.

sublime low mql

Spam: Fake dating profile notification

Detects dating-themed messages from free email providers containing links with the recipient's email address embedded in URL parameters, combined with suspicious language or topics in the message body.

sublime medium mql

Spam: SMTP & Proxy Communications in Email Body

An email containing SMTP and Proxy (socks5) command and control information within the body of the message.

sublime medium mql

Brand impersonation: Hulu

Impersonation of Hulu.

sublime medium mql

Brand impersonation: KnowBe4

Impersonation of KnowBe4.

sublime low mql

Link: Free file host from freemail sender with NLU intent

Detects free file host links sent by freemail senders with a short body and NLU indicators.

sublime high mql

Callback phishing via e-signature service

Detects messages containing e-signature topics combined with tech support keywords and phone numbers. Message includes brand impersonation (PayPal, Norton, McAfee, etc.) and transaction-related language, with no attachments and reply-to addresses from free email providers.

sublime high mql

Attachment: Calendar invite with suspicious link leading to an open redirect

Calendar invite contains a link to either a free file host or free subdomain host, and the resulting webpage contains another link to an open redirect.

sublime medium mql

Brand impersonation: SiriusXM

Impersonation of the broadcasting corporation SiriusXM.

sublime high mql

Link: PDF and financial display text to free file host

Detects messages containing a single link with PDF-named display text containing financial phrases that redirects to a free file hosting service, sent without previous message threads.

sublime medium mql

Reconnaissance: Hotel booking reply-to redirect

Detects messages impersonating hotel booking inquiries by identifying common hotel-related language patterns from senders where the reply-to is a free email provider and differs from the sender domain in an effort to validate whether a recipient address is valid or not, potentially preceding an attack.

sublime low mql

Brand impersonation: Norton

Scans files to detect Norton (Lifelock|360|Security) impersonation.

sublime high mql

Suspicious request for financial information

Email is from a suspicious sender and contains a request for financial information, such as AR reports.

sublime high mql

ClickFunnels link infrastructure abuse

Email contains a ClickFunnels (mass mailing platform) tracking link but does not originate from ClickFunnels sending infrastructure. The myclickfunnels.com domain has been abused by threat actors to attempt credential phishing.

sublime medium mql

Reconnaissance: Email address harvesting attempt

Detects potential email harvesting or credential phishing attempts where short messages contain email addresses in the body text. These messages often try to extract contact information or validate email addresses for future attacks.

sublime medium mql

Domain impersonation: Freemail reply-to local lookalike with financial request

This technique takes advantage of the use of free email services for the reply-to address. By incorporating the sender domain in the local part of the reply-to address, the attacker creates a visually similar appearance to a legitimate email address.

sublime medium mql

BEC/Fraud: Student loan callback phishing

This rule detects phishing emails that attempt to engage the recipient by soliciting a callback under the guise of student loan forgiveness or assistance. The messages often come from free email providers, lack a proper HTML structure, and include suspicious indicators such as phone numbers embedded in the text. These emails typically contain language urging the recipient to respond or take immediate action, leveraging urgency around student loan repayment to entice engagement.

sublime high mql

Link: Observed URL pattern with specific domain registrar

Detects messages using Element Email service infrastructure, identified by characteristic URL patterns with /f/ paths, unsubscribe links, single domain usage, and Cloudflare domain registration. This pattern indicates potential abuse of legitimate email marketing services.

sublime high mql

Employee impersonation: Payroll fraud

This rule detects messages impersonating employees, from unsolicited senders attempting to reroute payroll or alter payment details.