Search and filter across all detection sources
359 rules
Service abuse: Monday.com callback scam
Detects callback scam solicitations originating from Monday.com's notification system using natural language understanding to identify fraudulent callback language in the message body.
Credential phishing: 'Secure message' and engaging language
Body contains language resembling credential theft, and a "secure message" from an untrusted sender.
beta.DLP: Luxembourg Non-Natural ID
Detects messages containing Luxembourg non-natural person identification numbers.
Service abuse: Elastic alerts extortion
Detects inbound messages impersonating Elastic alerts sender that contain extortion content identified through natural language processing with medium to high confidence.
EML attachment with credential theft language (unknown sender)
Identifies EML attachments that use credential theft language from unknown senders.
Brand impersonation: Exodus
Attack impersonating Exodus Wallet.
Link: Blogspot hosting explicit romance content
Detects inbound messages containing links to Blogspot domains that host explicit romance content, identified through natural language processing of the message body.
Service abuse: MongoDB Atlas callback scam
Detects inbound messages from MongoDB Atlas alert addresses that contain callback scam content identified through natural language analysis with medium or high confidence.
Service abuse: Calendly callback scam detection
Detects inbound messages from Calendly's notification system that contain callback scam content, as identified through natural language processing with medium or high confidence levels.
beta.DLP: GitHub Token
Detects messages containing GitHub tokens.
beta.DLP: Private Key
Detects messages containing private keys.
Brand impersonation: Wise
Impersonating Wise Financial, an online banking platform.
Brand impersonation: Aramco
Impersonation of the petroleum and natural gas company Saudi Aramco.
beta.DLP: US Passport Number
Detects messages containing US passport numbers.
beta.DLP: MAC Address
Detects messages containing MAC addresses.
Service abuse: WeTransfer callback scam
Detects callback scams originating from legitimate WeTransfer noreply address using natural language processing to identify high-confidence callback scam intent in the message body.
Fake shipping notification with suspicious language
Body contains keywords for shipping, contains suspicious language, and addresses the recipient by their email, which is an indicator of phishing and/or spam.
Service abuse: SendThisFile with credential theft and financial language
Detects messages from sendthisfile.com containing credential theft language combined with financial communications topics.
beta.DLP: AWS Access Key
Detects messages containing AWS access keys.
beta.DLP: Basic Auth Header
Detects messages containing basic authentication headers.
beta.DLP: Crypto Wallet Address
Detects messages containing cryptocurrency wallet addresses.
beta.DLP: IBAN Code
Detects messages containing IBAN codes.
beta.DLP: OAuth Client Secret
Detects messages containing OAuth client secrets.
beta.DLP: UK Passport
Detects messages containing UK passport numbers.
Fake message thread with a suspicious link and engaging language from an unknown sender
Detects fake message threads with suspicious links and financial request language