Browse Rules

Search and filter across all detection sources

814 rules

sagan unknown other

[ZSCALER-ZIA] Scam destination blocked

[ZSCALER-ZIA] Scam destination blocked

sublime low mql

Suspicious display name: Gmail sender with engaging language

Detects Gmail senders using display names with suspicious language patterns commonly associated with social engineering tactics, including urgency indicators, contact requests, and verification prompts.

sublime high mql

Attachment: ICS calendar file with recipient address in UID field

Detects inbound messages containing ICS calendar attachments where the UID property matches the recipient's email address, indicating potential calendar-based social engineering.

sublime high mql

Brand impersonation: Apple

Impersonation of Apple.

sublime low mql

Brand impersonation: Spotify

Impersonation of Spotify.

sublime medium mql

Brand impersonation: Twitter

Impersonation of Twitter.

sublime low mql

Brand impersonation: Vanta

Impersonation of Vanta.

sublime medium mql

Brand impersonation: Venmo

Impersonation of Venmo

sublime medium mql

Attachment: PDF with suspicious document view lure

Detects PDF attachments containing a title box designed to lure recipients into viewing a document, a common social engineering technique used to direct users to malicious content.

sublime medium mql

Link: Shortened URL with fragment matching subject

Detects messages containing shortened links where the URL fragment appears in the email subject line, indicating potential targeted link tracking or social engineering tactics.

sublime high mql

Brand impersonation: DocSend

Attack impersonating DocSend.

sublime high mql

Brand impersonation: Github

Impersonation of Github.

sublime medium mql

Brand impersonation: LinkedIn

Impersonation of LinkedIn.

sublime high mql

Brand impersonation: Microsoft

Impersonation of the Microsoft brand.

sublime low mql

Brand impersonation: Netflix

Impersonation of Netflix.

sublime medium mql

Credential theft with 'safe content' deception and social engineering topics

Detects messages containing credential theft language combined with social engineering topics like secure messages, notifications, or authentication alerts. The rule specifically identifies emails that deceptively claim to be from a 'safe sender' or contain 'safe content' in the first line, which is a common tactic used to bypass security filters and gain user trust.

sublime medium mql

Brand impersonation: Dashlane

Impersonation of the password management software Dashlane.

sublime medium mql

Attachment: PDF contains W9 or invoice YARA signatures

PDF attachment contains YARA signatures commonly associated with fraudulent W9 tax forms or invoice documents, which are frequently used in social engineering attacks to steal sensitive information or facilitate business email compromise.

sublime medium mql

Brand impersonation: Charles Schwab

Impersonation of Charles Schwab & Co

sublime low mql

Brand impersonation: DHL

Impersonation of the shipping provider DHL.

sublime high mql

Brand impersonation: DigitalOcean

Impersonation of the cloud provider DigitalOcean.

sublime low mql

Brand impersonation: Exodus

Attack impersonating Exodus Wallet.

sublime low mql

Brand impersonation: FedEx

Impersonation of the shipping provider FedEx.

sublime low mql

Brand impersonation: Stellar Development Foundation (SDF)

Attack impersonating Stellar Development Foundation (SDF).

sublime high mql

Brand impersonation: Sublime Security

Possible attempt to impersonate Sublime Security executives.