Browse Rules

Search and filter across all detection sources

67 rules

chronicle informational yara-l

WHOIS Recently Created Domain Access

Detects access attempts to a newly created domain via WHOIS enrichment.

chronicle low yara-l

WHOIS Expired Domain Accessed

Example usage of WHOIS data, detecting an executable file download from a domain that's recently expired

chronicle low yara-l

WHOIS DNS Query To Typesquatting Domain

Provides example usage of WHOIS data, detecting a DNS query for a domain that contains a specific string and is not registered with the defined domain registrar.

chronicle low yara-l

WHOIS Expired Domain Executable Downloaded

Detect web traffic to a recently expired domain followed by an exe file creation event

sublime medium mql

Brand impersonation: Silicon Valley Bank

Detects emails that impersonate Silicon Valley Bank

sublime medium mql

New sender domain (<=10d) from untrusted sender

Detects inbound emails where the sender domain is less than 10 days old from untrusted senders.

sentinel medium kql

Whisper Security - Domain Registrar Change Anomaly

Detects domains whose registrar has changed across WHOIS history snapshots within the last 30 days. Registrar changes may indicate domain hijacking or adversary infrastructure acquisition.

sublime high mql

Brand Impersonation: OpenAI with ChatGPT Ads lure

Detects messages impersonating OpenAI or ChatGPT, that contain specific references to ChatGPT Ads. Observed harvesting advertisting account credentials.

sublime medium mql

Spam: New link domain (<=10d) and emojis

Detects spam from freemail senders, where the linked domain is less than 10 days old and emojis present.

sublime low mql

Link: Romance/Sexual Language With Suspicious Link

Detects messages containing romantic or adult-themed language, combined with links to newly registered domains or suspicious reply-to addresses.

sublime medium mql

Brand impersonation: Microsoft fake sign-in alert

Detects messages impersonating Microsoft that mimic sign-in security alerts and attempt to solicit a response.

sublime medium mql

New link domain (<=10d) from untrusted sender

Detects links in the body of an email where the linked domain is less than 10 days old from untrusted senders.

sublime medium mql

Service abuse: AppSheet infrastructure with suspicious indicators

Identifies messages that resemble credential theft, originating from AppSheet. AppSheet infrastrcture abuse has been observed recently to send phishing attacks.

sublime high mql

Attachment: Calendar invite from recently registered domain

Detects calendar invites (.ics files) from organizers using domains registered within the last 90 days, which may indicate suspicious or malicious calendar invitations.

sublime medium mql

Brand impersonation: Stripe notification

Campaigns have been observed sending templated Stripe notification emails with the call-to-action button link replaced, clicking through to a malicious credential phishing page.

sublime high mql

Link: Multistage landing - Published Google Doc

A Google Docs document contains suspicious text and links that redirect to either newly registered domains, free subdomain hosts, URL shorteners, or domains with suspicious TLDs.

sublime medium mql

Service abuse: Adobe message from newly registered domain

Detects messages legitimately sent through Adobe's messaging infrastructure that contain mailto links pointing to domains registered within the last 365 days.

sublime medium mql

Link: Commonly Abused Web Service redirecting to ZIP file

Detects messages containing links from URL shorteners, free file hosts, or suspicious domains that redirect to ZIP file downloads, potentially indicating malware distribution.

sublime medium mql

Attachment: DocuSign impersonation via PDF linking to new domain

This rule detects PDF files containing a DocuSign logo linking to a newly created domain (Less than or equal to 3 days)

sublime medium mql

Attachment: ICS file with links to newly registered domains

Detects calendar invite attachments (ICS files) containing links to domains registered within the last 30 days, which may indicate malicious calendar invitations designed to redirect users to suspicious websites.

sublime medium mql

Link: Financial account issue with suspicious indicators

Detects messages to single recipients containing language about account or payment issues combined with suspicious links or high-confidence credential theft indicators related to financial communications.

sublime high mql

Link: Multistage landing - ClickUp abuse

Detects ClickUp documents that contain external links to suspicious domains including new domains, free file hosts, URL shorteners, or links that redirect to phishing pages or contain captchas.

sublime high mql

Link: Observed URL pattern with specific domain registrar

Detects messages using Element Email service infrastructure, identified by characteristic URL patterns with /f/ paths, unsubscribe links, single domain usage, and Cloudflare domain registration. This pattern indicates potential abuse of legitimate email marketing services.

sublime medium mql

Link: Fake video link from newly registered domain

Detects inbound messages from a sender using the local part 'support' whose domain was registered less than 30 days ago, containing a link with a path resembling a video file URL structure ('.mp4/views/').

sublime medium mql

Link: Tax document lure Portuguese/Spanish with suspicious domains

Detects messages in Portuguese/Spanish containing tax document phrases that link to suspicious domains including URL shorteners, free file hosts, or newly registered domains.