Browse Rules

Search and filter across all detection sources

446 rules

sublime medium mql

Impersonation: SharePoint reply header anomaly

Detects messages with SharePoint reply headers that lack standard reply characteristics and contain inconsistencies in thread elements and recipient patterns

sublime high mql

beta.DLP: Basic Auth Header

Detects messages containing basic authentication headers.

sublime medium mql

Brand impersonation: Dropbox

Impersonation of Dropbox, a file sharing service.

sublime medium mql

Brand Impersonation: PayPal

Impersonation of PayPal.

sublime medium mql

Link: Squarespace infrastructure abuse

Detects inbound messages containing exactly one Squarespace tracking link but lacking authentic Squarespace email headers and sender patterns.

sublime high mql

Brand impersonation: Apple

Impersonation of Apple.

sublime high mql

Brand impersonation: DocSend

Attack impersonating DocSend.

sublime high mql

Brand impersonation: Github

Impersonation of Github.

sublime medium mql

Brand impersonation: LinkedIn

Impersonation of LinkedIn.

sublime low mql

Brand impersonation: Netflix

Impersonation of Netflix.

sublime high mql

Brand impersonation: Adobe Sign with suspicious indicators

Detects messages impersonating Adobe Sign that contain Adobe branding elements but are not sent from legitimate Adobe domains and lack proper Adobe Sign authentication headers.

sublime medium mql

Brand impersonation: Enbridge

Impersonation of the Canadian energy company Enbridge.

sublime medium mql

Brand impersonation: PNC

Impersonation of PNC Financial Services

sublime low mql

Russia return-path TLD (untrusted sender)

The return-path header is a .ru TLD from an untrusted sender.

sublime medium mql

Brand impersonation: Binance

Impersonation of the cryptocurrency exchange Binance.

sublime low mql

Brand impersonation: Norton

Scans files to detect Norton (Lifelock|360|Security) impersonation.

sublime high mql

Brand impersonation: DocuSign

Attack impersonating a DocuSign request for signature.

sublime high mql

Headers: Fake in-reply-to with wildcard sender and missing thread context

Detects messages claiming to be replies with In-Reply-To headers but lacking previous thread context, sent from addresses containing multiple wildcard characters in the local part.

sublime medium mql

Brand impersonation: Dashlane

Impersonation of the password management software Dashlane.

sublime high mql

Brand impersonation: Google using Microsoft Forms

Abuses Microsoft Forms to impersonate Google.

sublime medium mql

Brand impersonation: Quickbooks

Impersonation of the Quickbooks service from Intuit.

sublime medium mql

Brand impersonation: SiriusXM

Impersonation of the broadcasting corporation SiriusXM.

sublime medium mql

Brand impersonation: Aramco

Impersonation of the petroleum and natural gas company Saudi Aramco.

sublime medium mql

Link: Microsoft protected message with suspicious recipient patterns

Detects when a user receives a protected message (RPMSG) with the to and from headers matching or there is no TO header at all. Benign matches are possible, sender exclusions can be used to avoid matching on senders which commonly use Microsoft protected messages with suspicious recipient patterns

sublime medium mql

Brand impersonation: Charles Schwab

Impersonation of Charles Schwab & Co