Browse Rules

Search and filter across all detection sources

141 rules

sublime high mql

Attachment: .csproj with suspicious commands

Attached .csproj file contains suspicious commands.

sentinel medium kql

ProofpointPOD - Suspicious attachment

'Detects when email contains suspicious attachment (file type).'

sagan medium other

[MIMECAST] Suspicious Attachment Detected via Bluedot

[MIMECAST] Suspicious Attachment Detected via Bluedot

sagan medium other

[ZEEK] Sidejacking attach detected

[ZEEK] Sidejacking attach detected

signature-base unknown yara

SUSP_Email_Suspicious_OneNote_Attachment_Jan23_1 [yara]

Detects suspicious OneNote attachment that embeds suspicious payload, e.g. an executable (FPs possible if the PE is attached separately)

sublime unknown mql

Attachment: Suspicious VBA macro

Detects any VBA macro attachment that scores above a low confidence threshold in the Sublime Macro Classifier.

sublime medium mql

Attachment: Fake attachment image lure

Message (or attached message) contains an image impersonating an Outlook attachment button.

sagan medium other

[SONICWALL] Forbidden E-Mail Attachment

[SONICWALL] Forbidden E-Mail Attachment

sekoia-rules medium sigma

Suspicious Email Attachment Received

Detects email containing a suspicious file as an attachment, based on its extension.

sagan medium other

[MIMECAST] Attachment Sent From Malicious IP

[MIMECAST] Attachment Sent From Malicious IP

sagan medium other

[MIMECAST] Malicious Attachment Detected via Bluedot

[MIMECAST] Malicious Attachment Detected via Bluedot

signature-base unknown yara

SUSP_Email_Suspicious_OneNote_Attachment_Jan23_2 [yara]

Detects suspicious OneNote attachment that has a file name often used in phishing attacks

sagan medium other

[Barracuda] Email Gateway Attachment_Content Event Detected

[Barracuda] Email Gateway Attachment_Content Event Detected

sagan medium other

[Barracuda] Email Gateway Attachment_Filter Event Detected

[Barracuda] Email Gateway Attachment_Filter Event Detected

sublime high mql

Attachment: PowerPoint with suspicious hyperlink

Attached PowerPoint contains a suspicious hyperlink that can execute arbitrary code.

sagan medium other

[Barracuda] Email Gateway Predefined_Attachment_Content Event Detected

[Barracuda] Email Gateway Predefined_Attachment_Content Event Detected

sublime medium mql

Attachment: RTF file with suspicious link

This rule detects RTF attachments directly attached or within an archive, containing an external link to a suspicious low reputation domain.

sagan high other

[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet Add-AttachmentFilterEntry Successfully Executed

[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet Add-AttachmentFilterEntry Successfully Executed

sagan high other

[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet Get-AttachmentFilterEntry Successfully Executed

[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet Get-AttachmentFilterEntry Successfully Executed

sagan high other

[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet Get-AttachmentFilterListConfig Successfully Executed

[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet Get-AttachmentFilterListConfig Successfully Executed

sagan high other

[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet Remove-AttachmentFilterEntry Successfully Executed

[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet Remove-AttachmentFilterEntry Successfully Executed

sagan high other

[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet Set-AttachmentFilterListConfig Successfully Executed

[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet Set-AttachmentFilterListConfig Successfully Executed

sublime unknown mql

Attachment with URL shortener (unsolicited)

Recursively scans files and archives to detect links to URL shorteners.

sigma medium sigma

OneNote Attachment File Dropped In Suspicious Location

Detects creation of files with the ".one"/".onepkg" extension in suspicious or uncommon locations. This could be a sign of attackers abusing OneNote attachments

sublime medium mql

Attachment: EML with suspicious indicators

Attached EML contains suspicious indicators, such as a missing sender email or short HTML body.