Browse Rules

Search and filter across all detection sources

799 rules

sublime low mql

Job scam (unsolicited sender)

Detects job scam attempts by analyzing the message body text from an unsolicited sender.

sublime low mql

Extortion / sextortion (untrusted sender)

Detects extortion and sextortion attempts by analyzing the email body text from an untrusted sender.

sublime medium mql

Business Email Compromise (BEC) attempt from unsolicited sender

Detects potential Business Email Compromise (BEC) attacks by analyzing text within the email body from unsolicited senders.

sublime high mql

EML attachment with credential theft language (unknown sender)

Identifies EML attachments that use credential theft language from unknown senders.

sublime medium mql

Credential phishing language and suspicious indicators (unknown sender)

Message contains various suspicious indicators as well as engaging language resembling credential theft from an unknown sender.

sublime medium mql

Credential phishing: Engaging language and other indicators (untrusted sender)

Message contains various suspicious indicators as well as engaging language resembling credential theft from an untrusted sender.

sublime low mql

Extortion / sextortion in attachment from untrusted sender

Detects extortion and sextortion attempts by analyzing attachment text from an untrusted sender.

sublime high mql

Credential phishing link (unknown sender)

Message contains a link to a credential phishing page from an unknown sender.

sublime medium mql

Business Email Compromise (BEC) attempt from untrusted sender

Detects potential Business Email Compromise (BEC) attacks by analyzing text within the email body from first-time senders.

sublime medium mql

Google Notification alert link from non-Google sender

This rule detects messages that leverage a link to notifications.google.com not from google and from an untrusted sender. Commonly abused in salesforce phishing campaigns.

sublime low mql

Russia return-path TLD (untrusted sender)

The return-path header is a .ru TLD from an untrusted sender.

sublime medium mql

Brand impersonation: AARP

Detects messages impersonating AARP by analyzing sender display name and body content for AARP references, address information, or survey-related language from unauthorized senders.

sublime medium mql

Commonly abused sender TLD with engaging language

Message is from a commonly abused sender TLD, contains various suspicious indicators resembling credential theft, and is unsolicited.

sublime medium mql

Business Email Compromise (BEC) attempt from untrusted sender (French/Français)

Detects potential Business Email Compromise (BEC) attacks by searching for common French BEC language within the email body from first-time senders.

sublime low mql

Spam: Firebase password reset from suspicious sender

Detects Firebase password reset messages from suspicious or new senders that may be attempting to abuse the Firebase authentication service.

sublime high mql

Suspicious VBA macros from untrusted sender

Detects any VBA macro attachment that scores above a medium confidence threshold in the Sublime Macro Classifier.

sublime low mql

Impersonation: Recipient SLD in sender's email address local part

The sender's email address local part contains the recipients SLD, the sender's domain is not a known org domain, and it's an untrusted sender.

sublime medium mql

Attachment: EML file with HTML attachment (unsolicited)

Detects HTML files in EML attachments from unsolicited senders. Reduces attack surface against HTML smuggling.

sublime medium mql

Attachment: EML with Sharepoint link likely unrelated to sender

Detects EML attachments containing SharePoint links where the subdomain differs significantly from the sender's domain, potentially indicating SharePoint impersonation or domain spoofing tactics.

sublime medium mql

Callback phishing in body or attachment (untrusted sender)

Detects callback scams by analyzing text within images of receipts or invoices from untrusted senders.

sublime low mql

Link: .onion From Unsolicited Sender

Detects messages containing .onion (Tor network) links from unsolicited senders that either lack proper DMARC authentication or are not from trusted domains.

sublime medium mql

File sharing link from suspicious sender domain

A file sharing link in the body sent from a suspicious sender domain.

sublime medium mql

Link: Job recruitment lure from unsolicited sender with suspicious hosting

Message contains job recruitment language with links to suspicious hosting services including free file hosts, subdomain hosts, or URL shorteners from an unsolicited sender.

sublime medium mql

New sender domain (<=10d) from untrusted sender

Detects inbound emails where the sender domain is less than 10 days old from untrusted senders.

sublime medium mql

Attachment with auto-executing macro (unsolicited)

Attachment from an unsolicited sender contains a macro that will auto-execute when the file is opened. Macros are a common phishing technique used to deploy malware.