Search and filter across all detection sources
141 rules
Attachment: .csproj with suspicious commands
Attached .csproj file contains suspicious commands.
ProofpointPOD - Suspicious attachment
'Detects when email contains suspicious attachment (file type).'
[MIMECAST] Suspicious Attachment Detected via Bluedot
[ZEEK] Sidejacking attach detected
SUSP_Email_Suspicious_OneNote_Attachment_Jan23_1 [yara]
Detects suspicious OneNote attachment that embeds suspicious payload, e.g. an executable (FPs possible if the PE is attached separately)
Attachment: Suspicious VBA macro
Detects any VBA macro attachment that scores above a low confidence threshold in the Sublime Macro Classifier.
Attachment: Fake attachment image lure
Message (or attached message) contains an image impersonating an Outlook attachment button.
[SONICWALL] Forbidden E-Mail Attachment
Suspicious Email Attachment Received
Detects email containing a suspicious file as an attachment, based on its extension.
[MIMECAST] Attachment Sent From Malicious IP
[MIMECAST] Malicious Attachment Detected via Bluedot
SUSP_Email_Suspicious_OneNote_Attachment_Jan23_2 [yara]
Detects suspicious OneNote attachment that has a file name often used in phishing attacks
[Barracuda] Email Gateway Attachment_Content Event Detected
[Barracuda] Email Gateway Attachment_Filter Event Detected
Attachment: PowerPoint with suspicious hyperlink
Attached PowerPoint contains a suspicious hyperlink that can execute arbitrary code.
[Barracuda] Email Gateway Predefined_Attachment_Content Event Detected
Attachment: RTF file with suspicious link
This rule detects RTF attachments directly attached or within an archive, containing an external link to a suspicious low reputation domain.
[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet Add-AttachmentFilterEntry Successfully Executed
[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet Get-AttachmentFilterEntry Successfully Executed
[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet Get-AttachmentFilterListConfig Successfully Executed
[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet Remove-AttachmentFilterEntry Successfully Executed
[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet Set-AttachmentFilterListConfig Successfully Executed
Attachment with URL shortener (unsolicited)
Recursively scans files and archives to detect links to URL shorteners.
OneNote Attachment File Dropped In Suspicious Location
Detects creation of files with the ".one"/".onepkg" extension in suspicious or uncommon locations. This could be a sign of attackers abusing OneNote attachments
Attachment: EML with suspicious indicators
Attached EML contains suspicious indicators, such as a missing sender email or short HTML body.