Browse Rules

Search and filter across all detection sources

47 rules

sublime high mql

Image as content with a link to an open redirect

Body contains little, no, or only disclaimer text, an image, and a link to an open redirect.

sublime low mql

Inline image as message with attachment or link

Using inline images in lieu of HTML or text content in the message is a known technique used to bypass content based scanning engines. We've observed this technique used to deliver malware via attachments and phish credentials.

sublime medium mql

Credential phishing: Image as content, short or no body contents

This rule identifies incoming messages with minimal links, all image attachments and either empty, brief or the body text is only a warning banner/disclaimer. It also checks for truncated PNG images or logos in addition to high-confidence credit theft intentions.

sublime medium mql

Attachment: Fake attachment image lure

Message (or attached message) contains an image impersonating an Outlook attachment button.

sublime high mql

Credential theft: Gophish abuse with hidden tracking image

Detects messages containing hidden tracking images with display:none style and tracking parameters in the source URL, commonly used for user tracking and engagement monitoring.

sublime high mql

Brand impersonation: USPS

Impersonation of the United States Postal Service.

sublime medium mql

Attachment: SVG file with hyperlinks and cursor styling

Detects inbound messages containing SVG attachments that include clickable hyperlink elements and CSS pointer cursor styling, which may be used to deceive recipients into clicking malicious links disguised as legitimate images.

sublime medium mql

Credential phishing: Hyper-linked image leading to free file host

This rule detects messages with short or null bodies, where all attachments are images, and the image is hyperlinking to a free_file_host from an unsolicited and untrusted sender.

sublime medium mql

Attachment: PDF with secure document acknowledgment prompt

Detects PDF attachments matching yara rules looking for fake secure document prompts, including acknowledgment-style lures and suspicious image sizing.

sublime low mql

Spam: Mastercard promotional content with image-based body

Detects messages promoting untrustworthy Mastercard credit cards that contain both financial communications and promotional content topics, with the message body primarily consisting of image content rather than text. Excludes legitimate payment-related Mastercard communications and applies additional scrutiny to high-trust sender domains that fail DMARC authentication.

sublime medium mql

Link: PDF display text with fake copyright claim template

Detects messages containing fake copyright claims with table rows with 25px height images and links where the display text references PDF content, potentially indicating malicious PDF delivery attempts through deceptive formatting.

sublime medium mql

Attachment: Adobe image lure in body or attachment with suspicious link

Detects Adobe phishing messages with an Adobe logo in the body or attachment, with suspicious link language.

sublime medium mql

Attachment: Image-only docx/pptx callback phishing

Detects inbound emails with docx or pptx attachments that contain no text but exactly one embedded image, a common tactic to evade text-based scanning by presenting content as a picture. The rule then inspects any extracted text from the image for a combination of callback phishing lures—such as references to subscriptions, invoices, refunds, or antivirus renewals alongside phone numbers or dollar amounts—paired with impersonation of well-known brands like PayPal, McAfee, Norton, or Best Buy, in

sublime high mql

Attachment: Cold outreach with invitation subject and not attachment

Detects inbound messages with invitation-related subjects that request recipients to view attachments, contain no links, and are classified as B2B cold outreach with high confidence. Messages either have no attachments or contain a single image attachment.

sublime high mql

Brand impersonation: Microsoft logo image linking to free file host

Detects inline images that display a Microsoft logo and contain text, used as clickable links within the message body. The link behind the image redirects to a self-service site creation platform or free file hosting domain rather than a legitimate Microsoft or tenant domain, a common technique for disguising credential phishing or malware delivery links as trusted Microsoft branded content.

sublime medium mql

Brand impersonation: Coinbase with suspicious links

Detects messages impersonating Coinbase with low reputation or url shortened links.

sublime high mql

Attachment: Microsoft SharePoint Impersonation via images in macro-enabled attachment

Detects macro-enabled Office documents (docx and similar extensions) that contain images with text mimicking Microsoft SharePoint file-sharing notifications. The embedded images reference SharePoint collaboration language such as invitations to edit or references to Microsoft 365 access controls, designed to deceive recipients into trusting the attachment.

sublime high mql

Attachment: Risk assessment PDF with inline image

Detects inbound messages containing a PDF attachment whose file name matches a 'risk assessment' naming pattern with an alphanumeric code, alongside an inline image attachment referenced via content ID in the HTML body. Messages from highly trusted sender domains that pass DMARC authentication are excluded.

sublime medium mql

Brand impersonation: Microsoft Planner with suspicious link

Impersonation of Microsoft Planner, a component of the Microsoft 365 software suite.

sublime medium mql

Impersonation: Recipient organization in sender display name with credential theft image

Sender display name contains the recipient's organization domain while the actual email address differs. Message includes a single image attachment with OCR-detected credential theft language referencing the recipient's domain, and has no body text.

sublime high mql

Attachment: Gzip-archived with nested HTML file containing image and button link

Flags messages containing a gzip attachment that unpacks to an HTML file (identified via YARA), or messages whose body contains a base64-encoded image alongside an anchor tag styled as a rounded button, where the link's underlying domain resolves to a valid address. This pattern is commonly used to disguise phishing content and evade detection by embedding the malicious link within an image-styled button or compressed HTML payload.

sublime medium mql

PHP Mailer with common phishing attachments

Mail coming from a PHP Mailer user agent that includes attachments with commonly used names in phishing campaigns

sublime medium mql

Attachment: Fake secure message and suspicious indicators

Body contains language resembling credential theft, and an attached "secure message" from an untrusted sender.

sublime medium mql

Invoicera infrastructure abuse

This rule is tailored to flag infrastructural abuse involving Invoicera, a SaaS-based invoicing and billing platform, which has been identified as a tool in widespread spam and credential phishing campaigns.

sublime medium mql

Cloud storage impersonation with credential theft indicators

Detects messages impersonating cloud storage services that contain hyperlinked images leading to free file hosts, where message screenshots reveal high-confidence credential theft language and storage-related urgency tactics.