Browse Rules

Search and filter across all detection sources

129 rules

sublime low mql

Spam: Campaign with excessive space/char obfuscation and free file hosted link

This rule detects mass spam campaigns using excessive space padding with links utilizing free file hosting.

sublime low mql

Fake shipping notification with link to free file hosting

This rule detects spam emails impersonating FedEx, UPS, or USPS with links to free file hosting.

sublime low mql

Link: Free file host from freemail sender with NLU intent

Detects free file host links sent by freemail senders with a short body and NLU indicators.

sublime unknown mql

Attachment with free subdomain host URL (unsolicited)

Recursively scans files and archives to detect links to free subdomain hosts. Free subdomain hosts are commonly used to host credential phishing sites.

sublime high mql

Attachment: Calendar invite with suspicious link leading to an open redirect

Calendar invite contains a link to either a free file host or free subdomain host, and the resulting webpage contains another link to an open redirect.

sublime medium mql

Mass Outbound Group With Free File Host Domain

Detects when a sender contacts multiple unique domains and includes links to known free file hosting services.

sublime medium mql

Link: Commonly Abused Web Service redirecting to ZIP file

Detects messages containing links from URL shorteners, free file hosts, or suspicious domains that redirect to ZIP file downloads, potentially indicating malware distribution.

sublime high mql

Link: PDF and financial display text to free file host

Detects messages containing a single link with PDF-named display text containing financial phrases that redirects to a free file hosting service, sent without previous message threads.

sublime medium mql

Attachment: EML file with IPFS links

Attached EML uses engaging language and IPFS links were detected in the EML file. IPFS has been recently observed hosting phishing sites.

sublime medium mql

Service abuse: Google OAuth with suspicious redirect destination

Detects messages containing Google OAuth links with prompt=none parameter that redirect to suspicious domains including free file hosts, free subdomain providers, or self-service creation platforms.

sublime high mql

Service abuse: Google account notification with links to free file host

Detects messages impersonating Google Accounts that contain links redirecting to known file hosting services

sublime medium mql

Link: Free file hosting with undisclosed recipients

Detects messages containing links to free file hosting or subdomain services that are sent to undisclosed recipients or only CC/BCC recipients. The rule identifies suspicious distribution patterns where legitimate recipients are hidden, potentially indicating mass distribution of malicious content through file sharing platforms.

sublime medium mql

Service abuse: Google application integration redirecting to suspicious hosts

Detects legitimate Google application integration emails that contain links redirecting to free file hosting services or free subdomain hosts, including Microsoft OAuth redirects to suspicious domains. These could indicate abuse of Google's legitimate service for malicious redirects.

sublime high mql

Attachment: PDF with multistage landing - ClickUp abuse

Detects PDF attachments containing ClickUp document links that either redirect to unavailable pages or contain embedded links leading to newly registered domains, free file hosts, URL shorteners, or verified credential theft pages.

sublime high mql

Link: Multistage landing - ClickUp abuse

Detects ClickUp documents that contain external links to suspicious domains including new domains, free file hosts, URL shorteners, or links that redirect to phishing pages or contain captchas.

sublime medium mql

Link: Tax document lure Portuguese/Spanish with suspicious domains

Detects messages in Portuguese/Spanish containing tax document phrases that link to suspicious domains including URL shorteners, free file hosts, or newly registered domains.

sublime medium mql

Credential phishing: Hyper-linked image leading to free file host

This rule detects messages with short or null bodies, where all attachments are images, and the image is hyperlinking to a free_file_host from an unsolicited and untrusted sender.

sublime medium mql

Zoom Events newsletter abuse

Detects suspicious content in Zoom Events notifications that contain credential theft language and links to file hosting sites.

sublime medium mql

Link: Free file host links from suspicious support sender with credential theft language

Detects inbound messages from senders using the local part 'support' that contain a small number of links pointing exclusively to free file hosting services. The message contains NLU signals indicate credential theft intent related to file sharing or cloud services.

sublime medium mql

Link: Free file host link with 'Important Viewing Note' lure

Detects inbound messages containing links to free file hosting domains paired with the phrase 'important viewing note' in the message body. These messages often masquerade as institutional or educational communications — such as student conduct reports or advancement initiatives — to add legitimacy and encourage recipients to follow the hosted link.

sublime medium mql

Attachment: ICS file with credential theft indicators

Detects inbound emails containing calendar invite (.ics) attachments where the parsed event description is classified by NLU as having high-confidence credential theft intent and financial communication topics, and where embedded links point to domains that differ from the sender's domain and match known free file hosts, free subdomain hosts, self-service creation platforms, URL shorteners, suspicious TLDs, or newly registered domains (less than 90 days old).

sublime high mql

Credential phishing: Engaging language with IPFS link

Body contains credential theft indicators, and contains a link to an IPFS site. IPFS has been recently observed hosting phishing sites.

sublime medium mql

Link: IPFS

Detects messages containing links that have 'ipfs' in the domain, or unanalyzed links that contain 'ipfs' in the url. IPFS has been recently observed hosting phishing sites.

sublime high mql

Service abuse: GitHub notification with excessive mentions and suspicious links

Detects messages impersonating GitHub notifications that contain excessive @ mentions (over 20) and include a single suspicious external link. The suspicious link may be from free file hosts, free subdomain hosts, URL shorteners, or newly registered domains. The rule filters out legitimate GitHub domains and internal employee communications while identifying potential abuse of GitHub's notification system.

sublime medium mql

Link: Mismatched free file host links with document lure

Detects inbound emails containing mismatched hyperlinks where the displayed URL references a free file hosting service but the actual destination points to another free file host or a suspicious TLD. The rule combines this with NLU classification identifying BEC or credential theft intent, along with body text patterns common to fake document/scan notifications (e.g., 'scanned from', 'shared via', 'for your review') or short, urgency-driven messages. Trusted senders with passing DMARC are exclud