Browse Rules

Search and filter across all detection sources

55 rules

sublime low mql

BEC/Fraud: Scam lure with freemail pivot

This message detects BEC/Fraud lures attempting to solicit the victim to pivot out of band via a freemail address in the body.

sublime medium mql

BEC/Fraud: Job scam fake thread or plaintext pivot to freemail

Detects potential job scams using plaintext or fake threads attempting to pivot to a freemail address from an unsolicited sender.

sublime medium mql

Impersonation: IT Department mailbox storage alert

Detects inbound messages impersonating an internal IT Department by presenting a fake mailbox storage alert.

sublime medium mql

Credential Phishing via Dropbox comment abuse

This rule detects Credential Phishing attacks exploiting familiar brands via Dropbox comments. These attacks originate from legitimate Dropbox infrastructure and attempt to pivot to external freemail addresses.

sublime medium mql

Service abuse: GetAccept callback scam content

Detects callback scam language in messages sent through legitimate GetAccept infrastructure, indicating potential abuse of the service for fraudulent solicitation.

sublime medium mql

Callback phishing in body or attachment (untrusted sender)

Detects callback scams by analyzing text within images of receipts or invoices from untrusted senders.

sublime medium mql

Service abuse: EventCreate links to newly registered domains

Flags inbound messages containing links to eventcreate.com where the final rendered page includes outbound links to domains registered within the last 30 days, indicating the use of a legitimate service to pivot traffic to freshly created phishing infrastructure.

sublime high mql

Service abuse: Callback phishing via Microsoft Teams invite

Detects abuse of legitimate Microsoft Teams invites containing callback scam content, including brand references and financial transaction language with phone numbers.

sublime medium mql

Link: chatbot.page platform abuse

Detects abuse of chatbot.page where configurations suggest malicious intent, including incomplete contact information, free-tier usage, and suspicious question content.

sublime medium mql

Attachment: Callback phishing solicitation via text-based file

Callback Phishing via a text-based file attachment and a short body and subject from an unknown sender.

sublime medium mql

Service abuse: WeTransfer callback scam

Detects callback scams originating from legitimate WeTransfer noreply address using natural language processing to identify high-confidence callback scam intent in the message body.

sublime medium mql

Callback phishing via Google Meet

Detects Google Meet invitations that include callback phishing content in the body, impersonating brands like McAfee, Norton, PayPal, or Best Buy with purchase-related language and phone numbers to solicit victim contact.

sublime high mql

Link: ScreenConnect installer with suspicious relay domain

Detects when a link leads to a ConnectWise ScreenConnect installer and references a relay domain that doesn't match sender or organizational domains.

sublime medium mql

Service abuse: Microsoft Power BI callback scam

Detects callback scam content sent from the legitimate Microsoft Power BI service email address, indicating potential service abuse to distribute fraudulent callback solicitations.

sublime medium mql

Service abuse: Monday.com callback scam

Detects callback scam solicitations originating from Monday.com's notification system using natural language understanding to identify fraudulent callback language in the message body.

sublime medium mql

Service abuse: Microsoft Power Automate callback scam impersonation

Detects callback scam attempts using the legitimate Microsoft Power Automate service email address with high-confidence callback scam language in the message body.

sublime medium mql

Service abuse: IBM IAM account notification with callback scam indicators

Detects inbound messages abusing IBM's IAM account notification address that contain callback scam intent patterns identified through natural language analysis.

sublime medium mql

Service abuse: Google Calendar notification with callback scam language

Detects messages sent from Google's legitimate calendar notification service that contain callback scam language, indicating potential abuse of the calendar sharing feature to distribute fraudulent content.

sublime medium mql

Attachment: Credit card application with WhatsApp contact

Detects messages containing promotional credit card offers with attached forms requesting extensive personal information (PII) and directing victims to contact via WhatsApp, indicating potential fraud.

sublime medium mql

Brand impersonation: GitHub with callback scam indicators

Detects messages using GitHub's noreply address that contain callback scam language, brand impersonation tactics, or fraudulent purchase/payment content with phone numbers for victim contact.

sublime medium mql

Callback phishing: Social Security Administration fraud

Detects phishing attempts that impersonate the Social Security Administration, using a single PDF attachment containing specific fraud-related language and a callback number.

sublime high mql

HR impersonation via e-sign agreement comment

This rule inspects messages originating from legitimate e-signature platform infrastructure, with engaging language in the body that matches HR Impersonation criteria.

sublime high mql

Benefits enrollment impersonation

Detects messages about benefit enrollment periods and healthcare selections from external senders that contain urgent language or requests for action. Excludes legitimate HR communications, marketing mailers, and trusted sender domains with valid authentication.

sublime medium mql

Service abuse: Amazon invitation with suspected callback phishing

Detects Amazon's no-reply address with a subject about invitation sending, containing phone numbers within HTML header elements. This pattern is commonly used to trick recipients into calling fraudulent customer service numbers.

sublime medium mql

Service abuse: Microsoft Power Apps callback scam

Detects callback scam messages sent through Microsoft Power Apps that impersonate well-known brands like McAfee, Norton, Geek Squad, PayPal, or other services, containing suspicious transaction-related language and phone numbers to solicit victim contact.