Browse Rules

Search and filter across all detection sources

359 rules

sublime medium mql

Service abuse: Monday.com callback scam

Detects callback scam solicitations originating from Monday.com's notification system using natural language understanding to identify fraudulent callback language in the message body.

sublime medium mql

Credential phishing: 'Secure message' and engaging language

Body contains language resembling credential theft, and a "secure message" from an untrusted sender.

sublime high mql

beta.DLP: Luxembourg Non-Natural ID

Detects messages containing Luxembourg non-natural person identification numbers.

sublime medium mql

Service abuse: Elastic alerts extortion

Detects inbound messages impersonating Elastic alerts sender that contain extortion content identified through natural language processing with medium to high confidence.

sublime high mql

EML attachment with credential theft language (unknown sender)

Identifies EML attachments that use credential theft language from unknown senders.

sublime low mql

Brand impersonation: Exodus

Attack impersonating Exodus Wallet.

sublime medium mql

Link: Blogspot hosting explicit romance content

Detects inbound messages containing links to Blogspot domains that host explicit romance content, identified through natural language processing of the message body.

sublime medium mql

Service abuse: MongoDB Atlas callback scam

Detects inbound messages from MongoDB Atlas alert addresses that contain callback scam content identified through natural language analysis with medium or high confidence.

sublime medium mql

Service abuse: Calendly callback scam detection

Detects inbound messages from Calendly's notification system that contain callback scam content, as identified through natural language processing with medium or high confidence levels.

sublime high mql

beta.DLP: GitHub Token

Detects messages containing GitHub tokens.

sublime high mql

beta.DLP: Private Key

Detects messages containing private keys.

sublime high mql

Brand impersonation: Wise

Impersonating Wise Financial, an online banking platform.

sublime medium mql

Brand impersonation: Aramco

Impersonation of the petroleum and natural gas company Saudi Aramco.

sublime high mql

beta.DLP: US Passport Number

Detects messages containing US passport numbers.

sublime high mql

beta.DLP: MAC Address

Detects messages containing MAC addresses.

sublime medium mql

Service abuse: WeTransfer callback scam

Detects callback scams originating from legitimate WeTransfer noreply address using natural language processing to identify high-confidence callback scam intent in the message body.

sublime medium mql

Fake shipping notification with suspicious language

Body contains keywords for shipping, contains suspicious language, and addresses the recipient by their email, which is an indicator of phishing and/or spam.

sublime medium mql

Service abuse: SendThisFile with credential theft and financial language

Detects messages from sendthisfile.com containing credential theft language combined with financial communications topics.

sublime high mql

beta.DLP: AWS Access Key

Detects messages containing AWS access keys.

sublime high mql

beta.DLP: Basic Auth Header

Detects messages containing basic authentication headers.

sublime high mql

beta.DLP: Crypto Wallet Address

Detects messages containing cryptocurrency wallet addresses.

sublime high mql

beta.DLP: IBAN Code

Detects messages containing IBAN codes.

sublime high mql

beta.DLP: OAuth Client Secret

Detects messages containing OAuth client secrets.

sublime high mql

beta.DLP: UK Passport

Detects messages containing UK passport numbers.

sublime medium mql

Fake message thread with a suspicious link and engaging language from an unknown sender

Detects fake message threads with suspicious links and financial request language