Browse Rules

Search and filter across all detection sources

1,328 rules

sagan unknown other

[MSAPI-THREATINTEL] Phishing attempt detected

[MSAPI-THREATINTEL] Phishing attempt detected

sagan unknown other

[ZSCALER-ZIA] Phishing threat blocked

[ZSCALER-ZIA] Phishing threat blocked

sagan medium other

[Barracuda] IMPERSONATION Spear Phishing - Email Found to be Phishing

[Barracuda] IMPERSONATION Spear Phishing - Email Found to be Phishing

panther high python

Proofpoint Phishing Email Detected

This rule alerts when Proofpoint detects phishing attempts in email. It triggers when emails are quarantined with the phish rule, have a high phish score (90+), or contain active phishing threats in the threats map.

sentinel medium kql

Trend Micro CAS - Possible phishing mail

'Detects possible phishing mail.'

yara unknown yara

PHISH_02Dez2015_dropped_p0o6543f [maldocs]

Phishing Wave - file p0o6543f.exe

sagan critical other

[CISCO-SCA] Suspected Phishing Domain

[CISCO-SCA] Suspected Phishing Domain

sagan medium other

[PALO-ALTO] Phishing URL Blocked

[PALO-ALTO] Phishing URL Blocked

sagan critical other

[PROOFPOINT] Phish Classification Messages Blocked

[PROOFPOINT] Phish Classification Messages Blocked

sagan critical other

[PROOFPOINT] Phish Classification Messages ClicksBlocked

[PROOFPOINT] Phish Classification Messages ClicksBlocked

sagan critical other

[PROOFPOINT] Phish Classification Messages Delivered

[PROOFPOINT] Phish Classification Messages Delivered

sagan critical other

[PROOFPOINT] Phish Classification Messages Delivered

[PROOFPOINT] Phish Classification Messages Delivered

signature-base unknown yara

PHISH_02Dez2015_dropped_p0o6543f_1 [yara]

Phishing Wave - file p0o6543f.exe

sekoia unknown yara

apt_apt28_ukrnet_phishing_page [yara_rules]

Detects APT28 Phishing page

sigma high sigma

Okta FastPass Phishing Detection

Detects when Okta FastPass prevents a known phishing site.

signature-base unknown yara

Brooxml_Phishing [yara]

Detects PDF and OOXML files leading to AiTM phishing

signature-base unknown yara

Saudi_Phish_Trojan [yara]

Detects a trojan used in Saudi Aramco Phishing

sublime medium mql

Callback phishing via calendar invite

Detects calendar invites containing callback phishing language in the DESCRIPTION or SUMMARY of the invite.

sublime medium mql

Callback phishing via Zelle Service Abuse

Callback phishing campaigns have been observed abusing Zelle services to send fraudulent payment requests with callback phishing contents.

sagan medium other

[Barracuda] Email Gateway Phishing Event Detected

[Barracuda] Email Gateway Phishing Event Detected

sagan critical other

[BitdefenderGZ] Phishing/Fraud Link Detected (blocked)

[BitdefenderGZ] Phishing/Fraud Link Detected (blocked)

sagan critical other

[PROOFPOINT] CRITICAL - Phish Classification Messages ClicksPermitted

[PROOFPOINT] CRITICAL - Phish Classification Messages ClicksPermitted

sagan high other

[WINDOWS-SYSMON] Evilginx2 Phishing Framework Execution

[WINDOWS-SYSMON] Evilginx2 Phishing Framework Execution

sekoia unknown yara

apt_apt28_document_phishing_webpage [yara_rules]

Detects APT28 document phishing webpage

sekoia unknown yara

apt_reaper_2fa_phishing_webpage [yara_rules]

Detects Reaper 2FA phishing webpage