Browse Rules

Search and filter across all detection sources

31 rules

sublime low mql

Attachment: ICS with embedded document

ICS invite contains an embedded document.

sublime high mql

Attachment: ICS file with meeting prefix

Detects incoming messages with a single ICS calendar file attachment that has a filename starting with 'meeting_'.

sublime medium mql

Attachment: ICS file with non-Gregorian calendar scale

Detects ICS calendar attachments that use a non-standard calendar scale other than GREGORIAN, which may indicate malicious calendar files attempting to exploit calendar parsing vulnerabilities or bypass security filters.

sublime medium mql

Attachment: ICS file with AWS Lambda URL

Detects ICS calendar files that contain references to AWS Lambda URLs, which may be used to deliver malicious content or redirect users to suspicious resources.

sublime high mql

Attachment: HTML smuggling with eval and atob via calendar invite

Scans calendar invites (.ics files) to detect HTML smuggling techniques.

sublime high mql

Attachment: ICS calendar with embedded file from internal sender with SPF failure

Detects calendar invitations (ICS files) from internal domains that fail SPF authentication and contain embedded attachments, with single attendee and organizer both from organizational domains.

sublime medium mql

Attachment: ICS calendar file with suspicious product identifier

Detects inbound messages containing ICS calendar attachments that have product identifiers matching patterns commonly associated with malicious calendar invitations. The rule identifies ICS files through multiple detection methods and analyzes the product_id field for suspicious formatting that may indicate automated generation or spoofing attempts.

sublime high mql

Attachment: HTML smuggling with atob and high entropy via calendar invite

Scans calendar invites (.ics files) to detect HTML smuggling techniques.

sublime high mql

Attachment: ICS with employee policy review lure

Detects ICS calendar attachments containing references to 'policy review' and 'secure access' terminology, which may be used in social engineering attacks to prompt users to take action under the guise of compliance or security requirements.

sublime medium mql

Attachment: ICS file with excessive custom properties

ICS calendar attachment contains an unusually high number of custom X- properties, which may indicate attempts to hide malicious content or exploit calendar parsing vulnerabilities.

sublime medium mql

Attachment: ICS Link With Valueless Base64 Query Parameter

Detects inbound emails containing ICS calendar attachments where embedded event links include a randomized 8-character base64 query parameter with no assigned value. The rule excludes messages from high-trust sender domains that pass DMARC authentication.

sublime high mql

Attachment: Calendar invite from recently registered domain

Detects calendar invites (.ics files) from organizers using domains registered within the last 90 days, which may indicate suspicious or malicious calendar invitations.

sublime medium mql

Callback phishing via calendar invite

Detects calendar invites containing callback phishing language in the DESCRIPTION or SUMMARY of the invite.

sublime medium mql

Attachment: ICS calendar file with suspicious UID domain

Detects inbound messages containing ICS calendar attachments where the event UID property ends with a specific domain (@example.com). Malicious actors may use calendar invites to socially engineer recipients into accepting fraudulent meetings or following malicious instructions embedded in calendar events.

sublime high mql

Attachment: ICS with embedded Javascript in SVG file

Detects incoming messages containing ICS attachments with embedded SVG files that contain malicious JavaScript code, including base64-encoded content and potentially harmful event handlers. The rule specifically watches for onload events, location redirects, error handlers, and iframe elements with base64 data URIs.

sublime high mql

Attachment: ICS calendar file with base64 encoded recipient address in URL parameters

Detects inbound messages containing ICS calendar attachments where event links have multiple URL parameters, and the base64 decoded combination of those parameters matches the recipient's email address. This technique may be used to personalize malicious links or track specific targets.

sublime high mql

Attachment: Calendar file with invisible Unicode characters

Detects calendar (.ics) attachments containing suspicious invisible Unicode characters, which may be used to hide malicious content or bypass security filters. The rule triggers on messages with calendar-related keywords in the subject or body.

sublime high mql

Attachment: ICS calendar file with recipient address in UID field

Detects inbound messages containing ICS calendar attachments where the UID property matches the recipient's email address, indicating potential calendar-based social engineering.

sublime medium mql

Non-RFC compliant calendar files from unsolicited sender

Detects calendar (.ics) files that do not follow RFC standards by lacking required UID identifiers while containing specific calendar components (VTODO, VJOURNAL, VFREEBUSY, or VEVENT). Forged ICS calendar invites can be spoofed to seemingly originate from any sender.

sublime medium mql

Attachment: ICS voicemail lure with suspicious link

Detects inbound emails containing an ICS calendar attachment whose event description mimics a voicemail notification (e.g., 'new voicemail', 'listen to your voicemail') and includes a link pointing to a free file hosting service, self-service creation platform, URL shortener, suspicious TLD, or a domain registered within the last 90 days. Excludes messages from high-trust sender domains that pass DMARC authentication.

sublime medium mql

Attachment: ICS file with links to newly registered domains

Detects calendar invite attachments (ICS files) containing links to domains registered within the last 30 days, which may indicate malicious calendar invitations designed to redirect users to suspicious websites.

sublime medium mql

Attachment: ICS file with credential theft indicators

Detects inbound emails containing calendar invite (.ics) attachments where the parsed event description is classified by NLU as having high-confidence credential theft intent and financial communication topics, and where embedded links point to domains that differ from the sender's domain and match known free file hosts, free subdomain hosts, self-service creation platforms, URL shorteners, suspicious TLDs, or newly registered domains (less than 90 days old).

sublime medium mql

Attachment: ICS invite meeting lure

Detects inbound messages carrying an .ics calendar attachment that impersonate meeting invites, referencing dial-in details such as PIN resets, local numbers, or conference IDs. These messages include a tracked link redirecting through the sender's own domain (e.g. /ls/click) and use generic, template-style subject lines like 'Management Progress Meeting' or 'Project Closeout Report', often appended with a machine-generated timestamp. The sending domains are typically unrelated or compromised bu

sublime medium mql

Attachment: Calendar invite with Google redirect and invoice request

Detects calendar file attachments containing Google redirect URLs in the location field combined with invoice-related language in the message body.

sublime medium mql

Attachment: ICS calendar invite with bid/RFP lure and suspicious link

Detects inbound messages containing an ICS calendar attachment whose embedded event description contains bid, RFP, or proposal-related language commonly used in procurement fraud lures. The rule parses the ICS file contents and flags cases where the event also includes a link pointing to a domain that differs from the sender's domain and matches indicators of risk, such as self-service site builders, free file hosting or subdomain services, suspicious TLDs, URL shorteners, or recently registered