550 detection rules reference this event. View event page.
642 detection rules reference this event. View event page.Sublime MQL (642)
- Advance Fee Fraud (AFF) from freemail provider or suspicious TLD severity medium
- Attachment: Adobe image lure in body or attachment with suspicious link severity medium
- Attachment: Calendar file with invisible Unicode characters severity high
- Attachment: Calendar invite with Google redirect and invoice request severity medium
- Attachment: Callback phishing solicitation via pdf file severity high
- Attachment: Callback phishing solicitation via text-based file severity medium
- Attachment: Cold outreach with invitation subject and not attachment severity high
- Attachment: Compensation review lure with QR code severity high
- Attachment: Compensation-themed DOCX with QR code credential theft severity high
- Attachment: Credit card application with WhatsApp contact severity medium
- Attachment: EML containing a base64 encoded script severity high
- Attachment: EML with link to credential phishing page severity high
- Attachment: EML with suspicious indicators severity medium
- Attachment: Employment contract update with suspicious file naming severity high
- Attachment: Encrypted PDF with credential theft body severity medium
- Attachment: Encrypted zip file with payment-related lure severity medium
- Attachment: Fake scan-to-email severity medium
- Attachment: Fake secure message and suspicious indicators severity medium
- Attachment: Fake voicemail via PDF severity medium
- Attachment: Fictitious invoice using LinkedIn's address severity medium
- Attachment: Identity Confirmation With Document Unlock Code severity medium
- Attachment: Legal themed message or PDF with suspicious indicators severity medium
- Attachment: PDF bid/proposal lure with credential theft indicators severity medium
- Attachment: PDF file with low reputation link to ZIP file (unsolicited) severity medium
- Attachment: PDF file with low reputation links to suspicious filetypes (unsolicited) severity medium
- Attachment: PDF with credential theft language and link to a free subdomain (unsolicited) severity medium
- Attachment: PDF with password in filename matching body text severity medium
- Attachment: PDF with suspicious HeadlessChrome metadata severity medium
- Attachment: QR code link with base64-encoded recipient address severity high
- Attachment: QR code with credential phishing indicators severity medium
- Attachment: RFP/RFQ impersonating government entities severity high
- Attachment: Romance scam with image lure and advance-fee or suspicious link indicators severity medium
- Attachment: Self-sender PDF with minimal content and view prompt severity high
- Attachment: USDA bid invitation impersonation severity medium
- BEC with unusual reply-to or return-path mismatch severity high
- BEC/Fraud: Fake investment outreach from suspicious TLD severity medium
- BEC/Fraud: Generic scam attempt to undisclosed recipients severity low
- BEC/Fraud: Job scam fake thread or plaintext pivot to freemail severity medium
- BEC/Fraud: Penpal scam severity medium
- BEC/Fraud: Reply-chain manipulation with urgent keywords and self-reply severity medium
- BEC/Fraud: Romance scam severity medium
- BEC/Fraud: Scam lure with freemail pivot severity low
- BEC/Fraud: Student loan callback phishing severity medium
- BEC/Fraud: Unsolicited business acquisition offer severity medium
- BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns severity medium
- BEC: Employee impersonation with subject manipulation severity high
- BEC: Executive coaching vendor impersonation severity medium
- BEC: Financial fraud from newly registered sender domain severity medium
- BEC: Tax document request severity medium
- Benefits enrollment impersonation severity high
- beta.DLP: AWS Access Key severity high
- beta.DLP: Basic Auth Header severity high
- beta.DLP: Canadian Social Insurance Number (SIN) severity high
- beta.DLP: Crypto Wallet Address severity high
- beta.DLP: Date of Birth severity high
- beta.DLP: GitHub Token severity high
- beta.DLP: IBAN Code severity high
- beta.DLP: ICD-10 Code severity high
- beta.DLP: ICD-9 Code severity high
- beta.DLP: IP Address severity low
- beta.DLP: NHS Number severity high
- beta.DLP: OAuth Client Secret severity high
- beta.DLP: PCI US Credit Card Number (Any Network) severity high
- beta.DLP: Person Name severity medium
- beta.DLP: Phone Number severity low
- beta.DLP: Private Key severity high
- beta.DLP: SSL/TLS Certificate severity high
- beta.DLP: SWIFT/BIC Code severity high
- beta.DLP: UK Driver's License severity high
- beta.DLP: UK Electoral Roll severity high
- beta.DLP: UK National Insurance Number severity high
- beta.DLP: UK Passport severity high
- beta.DLP: UK UTR (Tax) severity high
- beta.DLP: US ABA Routing Number severity high
- beta.DLP: US Bank Account Number severity medium
- beta.DLP: US Driver's License severity high
- beta.DLP: US Individual Taxpayer Identification Number (ITIN) severity high
- beta.DLP: US Passport Number severity high
- beta.DLP: US Physical Address severity medium
- beta.DLP: US Social Security Number (SSN) severity high
- Body: Fake secure email portal with HTML obfuscation severity high
- Body: HTML whitespace stuffing with short initial message severity medium
- Body: PayApp transaction reference pattern severity medium
- Body: Suspicious date format severity medium
- Brand impersonation: AARP severity medium
- Brand impersonation: Adobe (QR code) severity high
- Brand impersonation: Adobe with suspicious language and link severity high
- Brand impersonation: AliExpress severity medium
- Brand impersonation: Amazon severity low
- Brand impersonation: Amazon Web Services (AWS) severity medium
- Brand impersonation: Amazon with suspicious attachment severity medium
- Brand impersonation: American Express (AMEX) severity low
- Brand impersonation: Anthropic/Claude with newly registered domain severity medium
- Brand impersonation: Aquent severity medium
- Brand impersonation: Aramco severity medium
- Brand impersonation: AuthentiSign severity medium
- Brand impersonation: Automobile assistance associations severity high
- Brand impersonation: Bids & Tenders severity high
- Brand impersonation: Binance severity medium
- Brand impersonation: Blockchain.com severity medium
- Brand impersonation: Booking.com severity medium
- Brand impersonation: Box file sharing service severity medium
- Brand impersonation: Canada Revenue Agency severity medium
- Brand impersonation: Capital One severity high
- Brand impersonation: Chase Bank severity high
- Brand impersonation: Chase bank with credential phishing indicators severity medium
- Brand impersonation: Cloud services with credential theft intent severity medium
- Brand impersonation: DHL severity low
- Brand Impersonation: Disney severity medium
- Brand impersonation: DocSend severity high
- Brand impersonation: DocuSign severity high
- Brand impersonation: DocuSign branded attachment lure with no DocuSign links severity high
- Brand impersonation: DocuSign with embedded QR code severity high
- Brand impersonation: Dotloop severity medium
- Brand impersonation: Dropbox severity medium
- Brand impersonation: Exodus severity low
- Brand impersonation: Fake Fax severity medium
- Brand impersonation: FedEx severity low
- Brand impersonation: File sharing notification with template artifacts severity low
- Brand impersonation: FINRA severity medium
- Brand Impersonation: Gemini Trust Company severity medium
- Brand impersonation: GitHub with callback scam indicators severity medium
- Brand Impersonation: Google (QR Code) severity high
- Brand impersonation: Google Careers severity high
- Brand impersonation: Google Drive fake file share severity medium
- Brand impersonation: Google Meet with malicious link severity medium
- Brand impersonation: Google Workspace alert notification severity medium
- Brand impersonation: Government / Tax Authority document lure severity medium
- Brand impersonation: Greenvelope severity medium
- Brand impersonation: Interac severity medium
- Brand impersonation: Internal Revenue Service severity high
- Brand impersonation: LastPass severity high
- Brand impersonation: LinkedIn severity medium
- Brand impersonation: Mailchimp severity medium
- Brand impersonation: Mailgun severity medium
- Brand impersonation: Marriott with gift language severity medium
- Brand impersonation: McAfee severity medium
- Brand impersonation: Meta and subsidiaries severity medium
- Brand impersonation: MetaMask severity high
- Brand impersonation: Microsoft severity high
- Brand impersonation: Microsoft (QR code) severity high
- Brand impersonation: Microsoft fake sign-in alert severity medium
- Brand impersonation: Microsoft logo in HTML with fake quarantine release notification severity high
- Brand impersonation: Microsoft Planner with suspicious link severity medium
- Brand impersonation: Microsoft quarantine release notification in body severity high
- Brand impersonation: Microsoft Teams invitation severity high
- Brand impersonation: Microsoft with embedded logo and credential theft language severity high
- Brand impersonation: Microsoft with low reputation links severity medium
- Brand impersonation: Morgan Stanley severity medium
- Brand impersonation: Navan severity medium
- Brand impersonation: Netflix severity low
- Brand Impersonation: OpenAI with ChatGPT Ads lure severity high
- Brand impersonation: OpenAI with payment issues severity high
- Brand Impersonation: PayPal severity medium
- Brand Impersonation: Procore severity medium
- Brand impersonation: Proofpoint secure messaging without legitimate indicators severity high
- Brand impersonation: Punchbowl severity medium
- Brand impersonation: Purdue ePlanroom with suspicious links severity medium
- Brand impersonation: Quickbooks severity medium
- Brand impersonation: QuickBooks dispute notification severity high
- Brand impersonation: Robert Half severity medium
- Brand impersonation: Robinhood severity medium
- Brand impersonation: SendGrid severity medium
- Brand Impersonation: ShareFile severity medium
- Brand impersonation: Sharepoint severity high
- Brand impersonation: Sharepoint fake file share severity medium
- Brand Impersonation: Shein severity medium
- Brand impersonation: SiriusXM severity medium
- Brand impersonation: Social Security Administration severity medium
- Brand impersonation: SoFi severity medium
- Brand impersonation: Spotify severity low
- Brand impersonation: Square severity medium
- Brand impersonation: Survey request with credential theft indicators severity medium
- Brand impersonation: TikTok severity medium
- Brand impersonation: Toronto-Dominion Bank severity medium
- Brand impersonation: Trust Wallet severity high
- Brand impersonation: Twitter severity medium
- Brand impersonation: UK government Home Office severity high
- Brand impersonation: United Healthcare severity medium
- Brand impersonation: UPS severity low
- Brand impersonation: USPS severity high
- Brand impersonation: Vanguard severity medium
- Brand impersonation: WeTransfer severity high
- Brand impersonation: Wise severity high
- Brand impersonation: Wix severity medium
- Brand impersonation: Xodo Sign severity medium
- Brand impersonation: Zoom severity medium
- Brand impersonation: Zoom via lookalike domain severity high
- Brand impersonation: Zoom with deceptive link display severity medium
- Business Email Compromise (BEC) attempt from unsolicited sender severity medium
- Business Email Compromise (BEC) attempt from untrusted sender severity medium
- Business Email Compromise (BEC) attempt from untrusted sender (French/Français) severity medium
- Business Email Compromise (BEC) with request for mobile number severity medium
- Callback phishing in body or attachment (untrusted sender) severity medium
- Callback phishing solicitation in message body severity medium
- Callback phishing via Adobe Sign comment severity high
- Callback phishing via Apple ID display name abuse severity high
- Callback phishing via DocuSign comment severity high
- Callback phishing via e-signature service severity high
- Callback phishing via extensionless rfc822 attachment severity high
- Callback phishing via Google Group abuse severity high
- Callback phishing via Google Meet severity medium
- Callback phishing via Intuit service abuse severity medium
- Callback phishing via Microsoft comment severity medium
- Callback Phishing via Signable E-Signature Request severity high
- Callback phishing via SignFree e-signature request severity high
- Callback phishing via Xodo Sign comment severity high
- Callback phishing via Yammer comment severity medium
- Callback phishing via Zelle Service Abuse severity medium
- Callback phishing via Zoho service abuse severity medium
- Callback Phishing via Zoom comment severity medium
- Callback phishing: Branded invoice from sender/reply-to domain less than 30 days old severity medium
- Callback phishing: SumUp infrastructure abuse severity high
- Callback phishing: Zero-width character obfuscation from freemail sender severity medium
- Callback scam: Impersonation via TimeTrade infrastructure severity medium
- Canva infrastructure abuse severity medium
- Cloud storage impersonation with credential theft indicators severity medium
- Commonly abused sender TLD with engaging language severity medium
- COVID-19 themed fraud with sender and reply-to mismatch or compensation award severity medium
- Credential phishing content and link (untrusted sender) severity high
- Credential phishing language and suspicious indicators (unknown sender) severity medium
- Credential Phishing via Dropbox comment abuse severity medium
- Credential phishing: 'Secure message' and engaging language severity medium
- Credential phishing: Blue button styled link with file-sharing template artifacts severity low
- Credential phishing: Email delivery failure impersonation severity high
- Credential phishing: Engaging language and other indicators (untrusted sender) severity medium
- Credential phishing: Engaging language with IPFS link severity high
- Credential phishing: Fake card notification with tracking lure severity medium
- Credential phishing: Fake password expiration from new and unsolicited sender severity medium
- Credential phishing: Fake storage alerts (unsolicited) severity medium
- Credential phishing: Financial lure via ActiveCampaign infrastructure severity medium
- Credential phishing: Generic document share with unicode and proceedural greeting template severity low
- Credential phishing: Generic document sharing severity medium
- Credential phishing: Hyper-linked image leading to free file host severity medium
- Credential phishing: Image as content, short or no body contents severity medium
- Credential phishing: Onedrive impersonation severity high
- Credential phishing: Personalized document signing request severity medium
- Credential phishing: Re-Authentication lure severity high
- Credential phishing: Suspicious e-sign agreement document notification severity medium
- Credential Phishing: Suspicious language, link, recipients and other indicators severity medium
- Credential phishing: Suspicious subject with urgent financial request and link severity medium
- Credential phishing: Tax form impersonation with payment request severity medium
- Credential Phishing: W-2 lure with inline SVG Windows logo severity high
- Credential theft with 'safe content' deception and social engineering topics severity medium
- Credential theft: JavaScript date manipulation in HTML body severity medium
- Cyrillic vowel substitution in subject or display name from unknown sender severity medium
- Deceptive Dropbox mention severity medium
- DLP - Clear-Text Credentials Outbound severity critical
- DLP - PCI: American Express Credit Card Number severity high
- DLP - PCI: Discover Credit Card Number severity high
- DLP - PCI: Mastercard Credit Card Number severity high
- DLP - PCI: US Credit Card Number (Any Network) severity high
- DLP - PCI: Visa Credit Card Number severity high
- DLP: Argentina DNI Number severity high
- DLP: Australia Bank Account Number severity medium
- DLP: Australia Driver's License Number severity medium
- DLP: Australia Medical Account Number severity high
- DLP: Australia Passport Number severity high
- DLP: Australia SWIFT Code severity medium
- DLP: Australia Tax File Number severity medium
- DLP: Austria Identity Card severity high
- DLP: Austria Social Security Number severity high
- DLP: Austria Tax Identification Number severity medium
- DLP: AWS Credentials severity high
- DLP: Azure Authentication Token severity high
- DLP: Basic Authentication Header severity medium
- DLP: Belgium National Number severity high
- DLP: Brazil CPF Number severity high
- DLP: Brazil RG Number severity high
- DLP: Bulgaria Uniform Civil Number severity high
- DLP: Canada Bank Account Number severity medium
- DLP: Canada Credit Card Number severity high
- DLP: Canada Driver's License Number severity medium
- DLP: Canada Health Service Number severity high
- DLP: Canada Passport Number severity high
- DLP: Canada Personal Health Identification Number (PHIN) severity high
- DLP: Canada Social Insurance Number (SIN) severity high
- DLP: Chile Identity Card Number severity high
- DLP: China Resident ID Number severity high
- DLP: Colombia Citizenship Card Number severity high
- DLP: Croatia Personal Identification (OIB) severity high
- DLP: Cyprus Identity Card severity high
- DLP: Czech Personal Identity Number severity high
- DLP: Denmark Personal Identification Number severity high
- DLP: Estonia Personal Identification Code severity high
- DLP: Finland National ID severity high
- DLP: France Bank Account Number severity medium
- DLP: France Credit Card Number severity high
- DLP: France Debit Card Number severity high
- DLP: France Driver's License Number severity medium
- DLP: France National ID Card (CNI) severity high
- DLP: France Passport Number severity high
- DLP: France Social Security Number (INSEE) severity high
- DLP: France Tax Identification Number (SPI) severity medium
- DLP: GCP API Key severity high
- DLP: Germany Bank Account Number (IBAN) severity medium
- DLP: Germany Driver's License Number severity medium
- DLP: Germany Identity Card Number (Personalausweisnummer) severity high
- DLP: Germany Passport Number severity high
- DLP: Germany Tax Identification Number severity medium
- DLP: GitHub Token severity high
- DLP: Greece National ID Card severity high
- DLP: Greece Social Security Number (AMKA) severity high
- DLP: Greece Tax Identification Number severity medium
- DLP: Hungary Personal Identification Number severity high
- DLP: Hungary Social Security Number (TAJ) severity high
- DLP: Hungary Tax Identification Number severity medium
- DLP: IMEI Number severity medium
- DLP: IMSI Number severity medium
- DLP: India Aadhaar Number severity high
- DLP: India Bank Account Number severity medium
- DLP: India PAN Number severity high
- DLP: India Passport Number severity high
- DLP: IP Address severity low
- DLP: Ireland Personal Public Service (PPS) Number severity high
- DLP: Israel Bank Account Number severity medium
- DLP: Israel Credit Card Number severity high
- DLP: Israel National ID severity high
- DLP: Israel SWIFT Code severity medium
- DLP: Italy Fiscal Code severity high
- DLP: Japan Bank Account Number severity medium
- DLP: Japan Credit Card Number severity high
- DLP: Japan Driver's License Number severity medium
- DLP: Japan MyNumber ID severity high
- DLP: Japan Passport Number severity high
- DLP: Japan Social Insurance Number severity high
- DLP: JSON Web Token (JWT) severity medium
- DLP: Latvia Personal Code severity high
- DLP: Lithuania Personal Code severity high
- DLP: Luxembourg National ID (Natural Persons) severity high
- DLP: Luxembourg National ID (Non-Natural Persons) severity medium
- DLP: MAC Address severity low
- DLP: Malta Identity Card Number severity high
- DLP: Malta Tax ID Number severity medium
- DLP: Mexico CURP Number severity high
- DLP: Mexico Passport Number severity high
- DLP: Netherlands Citizen's Service (BSN) Number severity high
- DLP: Netherlands Tax Identification Number severity medium
- DLP: OAuth Client Secret severity high
- DLP: Poland Identity Card severity high
- DLP: Poland Tax Identification Number severity medium
- DLP: Portugal Citizen Card Number severity high
- DLP: Portugal Tax Identification Number severity medium
- DLP: Private Key severity high
- DLP: Romania Personal Numerical Code severity high
- DLP: Saudi Arabia IBAN severity medium
- DLP: Saudi Arabia National ID severity high
- DLP: Saudi Arabia SWIFT Code severity medium
- DLP: Slack Token severity high
- DLP: Slovakia Personal Number severity high
- DLP: Slovenia Tax Identification Number severity medium
- DLP: Slovenia Unique Master Citizen Number severity high
- DLP: South Korea Resident Registration Number (RRN) severity high
- DLP: Spain Bank Account Number severity medium
- DLP: Spain DNI/NIE severity high
- DLP: Spain Passport Number severity high
- DLP: Spain Social Security Number severity high
- DLP: Spain Tax Identification Number severity medium
- DLP: SSL Certificate severity medium
- DLP: Sweden National ID severity high
- DLP: Sweden Tax Identification Number severity medium
- DLP: Taiwan ID Number severity high
- DLP: Turkey ID Number severity high
- DLP: UK National Health Service Number severity high
- DLP: UK National Insurance Number (NINO) severity high
- DLP: UK Passport Number severity high
- DLP: UK SWIFT Code severity medium
- DLP: US Bank Account Number severity medium
- DLP: US Driver's License Number severity medium
- DLP: US ICD-10-CM Code severity medium
- DLP: US ICD-9-CM Code severity medium
- DLP: US Individual Taxpayer Identification Number (ITIN) severity high
- DLP: US Insurance Claim Number severity medium
- DLP: US Passport Number severity high
- DLP: US Social Security Number (SSN) severity high
- DLP: Vehicle Identification Number (VIN) severity medium
- Domain impersonation: Freemail reply-to local lookalike with financial request severity medium
- Employee impersonation with urgent request (untrusted sender) severity medium
- Employee impersonation: Payroll fraud severity high
- Extortion / sextortion (untrusted sender) severity low
- Extortion / Sextortion - PDF attachment leveraging breach data from freemail sender severity high
- Extortion / sextortion in attachment from untrusted sender severity low
- Fake email quarantine notification severity high
- Fake message thread - Untrusted sender with a mismatched freemail reply-to address severity medium
- Fake message thread with a suspicious link and engaging language from an unknown sender severity medium
- Fake request for tax preparation severity high
- Fake scan-to-email message severity medium
- Fake shipping notification with suspicious language severity medium
- Fake thread with suspicious indicators severity medium
- Fake voicemail notification (untrusted sender) severity medium
- Fake warning banner using confusable characters severity medium
- Fake Zoho Sign template abuse severity medium
- Fake Zoom meeting invite with suspicious link severity medium
- File sharing link with a suspicious subject severity medium
- Fraudulent order confirmation/shipping notification from Chinese sender domain severity medium
- Google Drive abuse: Credential phishing link severity high
- Google presentation open redirect phishing severity medium
- Google services using g.co shortlinks severity medium
- Headers: Self-sender using Microsoft CompAuth bypass with credential theft content severity high
- Headers: System account impersonation with empty sender address severity medium
- Headers: X-Source-Auth mismatch with mismatched reply-to domain severity high
- Honorific greeting BEC attempt with sender and reply-to mismatch severity low
- HR impersonation via e-sign agreement comment severity high
- HTML content with print styling and credential theft language severity high
- Image as content with a link to an open redirect severity high
- Impersonation: Australian Federal Police with criminal case language severity high
- Impersonation: Chrome Web Store policy severity low
- Impersonation: Employee using fabricated identity in initial contact severity high
- Impersonation: Fake Gmail attachment severity high
- Impersonation: Fake product discount promotion severity medium
- Impersonation: Human Resources with link or attachment and engaging language severity medium
- Impersonation: Internal corporate services severity high
- Impersonation: IT Department mailbox storage alert severity medium
- Impersonation: Legal firm with copyright infringement notice severity medium
- Impersonation: Recipient organization in sender display name with credential theft image severity medium
- Impersonation: Salesforce fake campaign failure notification severity medium
- Impersonation: SAM/SBA federal registration severity high
- Impersonation: SharePoint reply header anomaly severity medium
- Impersonation: Suspected supplier impersonation with suspicious content severity high
- Investor solicitation with organization targeting severity medium
- Job scam (unsolicited sender) severity low
- Job scam with specific salary pattern severity low
- Link abuse: Self-service creation platform link with suspicious recipient behavior severity high
- Link: /index.php enclosed in three asterisks severity medium
- Link: Adobe share with suspicious indicators severity high
- Link: Apple App Store link to apps impersonating AI adveristing severity high
- Link: Apple App Store malicious ad manager themed apps from free email provider severity medium
- Link: BEC with newly registered domains and financial keywords severity medium
- Link: Blogspot hosting explicit romance content severity medium
- Link: Compromised WordPress site redirecting to suspicious root domain severity high
- Link: Concatenated display text concealing duplicate URLs with PDF reference severity medium
- Link: Credential harvesting with excess padding evasion severity low
- Link: Credential phishing traversing Russian infrastructure severity high
- Link: Credential theft with Cloudflare tunnel and recipient targeting severity high
- Link: Credential theft with invisible Unicode character in page title from unsolicited sender severity high
- Link: Cryptocurrency fraud with suspicious links severity high
- Link: Direct download of executable file severity low
- Link: Direct link to Dropbox Paper file severity low
- Link: Direct MSI download from low reputation domain severity low
- Link: Display text matches subject line severity medium
- Link: Document sharing invitation template severity high
- Link: Document-themed link to newly registered domain severity medium
- Link: Excessive URL rewrite encoders severity high
- Link: Executable file download with suspicious message content severity high
- Link: Fake forwarded message with suspicious URL in plain text severity medium
- Link: File sharing impersonation with suspicious language and sending patterns severity medium
- Link: File sharing pretext with suspicious body and link severity medium
- Link: Financial account issue with suspicious indicators severity medium
- Link: Flare-branded credential harvesting via Cloudflare tunnels severity high
- Link: Fraudulent state business filing notice severity medium
- Link: Free file host link with 'Important Viewing Note' lure severity medium
- Link: Free file host links from suspicious support sender with credential theft language severity medium
- Link: Free file hosting with undisclosed recipients severity medium
- Link: Free subdomain host with undisclosed recipients severity medium
- Link: Generic financial document with proceedural timeline template severity medium
- Link: Google Drawings link from new sender severity medium
- Link: Google Forms link with credential theft language severity medium
- Link: Hotel booking spoofed display URL severity medium
- Link: HR impersonation with suspicious domain indicators and credential theft severity high
- Link: Intuit link abuse with file share context severity medium
- Link: Invalid reply-to with recipient details in subject, body, and encoded link severity medium
- Link: Job recruitment lure from unsolicited sender with suspicious hosting severity medium
- Link: Mamba 2FA phishing kit severity high
- Link: Microsoft Dynamics 365 form phishing severity high
- Link: Mismatched free file host links with document lure severity medium
- Link: Multiple HTTP protocols in single URL severity medium
- Link: Multistage landing - Abused Google Drive severity high
- Link: Multistage landing - ClickUp abuse severity high
- Link: MyActiveCampaign Link Abuse severity medium
- Link: Observed URL pattern with specific domain registrar severity high
- Link: PDF file disguised as HTML page severity medium
- Link: PDF filename impersonation with credential theft language severity medium
- Link: Personal SharePoint with invalid recipients and credential theft language severity medium
- Link: Personalized URL with recipient address on commonly abused web service severity medium
- Link: QR Code with suspicious language (untrusted sender) severity medium
- Link: QuickBooks image lure with suspicious link severity medium
- Link: RFI document reference pattern in display text severity medium
- Link: Romance/Sexual Language With Suspicious Link severity low
- Link: Secure SharePoint file share from new or unusual sender severity low
- Link: Self-sender credential theft with configuration placeholder severity high
- Link: Self-sender with IP geolocation check and suspicious link behavior severity medium
- Link: Self-sender with sender org in subject and credential theft indicator severity high
- Link: Self-sent message with quarterly document review request severity critical
- Link: SharePoint filename matches org name severity medium
- Link: SharePoint OneNote or PDF link with self sender behavior severity medium
- Link: Shortened URL with fragment matching subject severity medium
- Link: Single character path with credential theft body and self sender behavior or invalid recipient severity medium
- Link: Suspicious go.php redirect with document lure severity medium
- Link: Suspicious Loom HTML file path severity medium
- Link: Suspicious recipient with timeout redirect severity medium
- Link: Suspicious SharePoint document name severity low
- Link: Suspicious single-domain link with suspicious path and financial lure indicators severity medium
- Link: Tax document lure Portuguese/Spanish with suspicious domains severity medium
- Link: Tycoon2FA phishing kit (non-exhaustive) severity high
- Link: Uncommon SharePoint document type with sender's display name severity medium
- Link: Unformatted template with literal placeholder in mailto link severity medium
- Link: URL path containing /moni/index severity high
- Link: URL scheme obfuscation via split HTML anchors severity high
- Link: URL shortener with copy-paste instructions and credential theft language severity low
- Link: WordPress login page with Blogspot Binance scam severity medium
- Link: Zoho form link from unsolicited sender severity medium
- Malformed URL prefix severity high
- Mass campaign: Cross Site Scripting (XSS) attempt severity medium
- Mass campaign: recipient address in subject, body, and link (untrusted sender) severity medium
- Message content: Request for author engagement severity low
- Microsoft infrastructure abuse with suspicious patterns severity high
- Mismatched links: Free file share with urgent language severity medium
- Open Redirect: Google domain with /url path and suspicious indicators severity medium
- Open redirect: Recipient address embedded in redirect URL pointing to newly registered domain severity medium
- QR Code with suspicious indicators severity high
- Reconnaissance: All recipients cc/bcc'd or undisclosed severity low
- Reconnaissance: Email address harvesting attempt severity medium
- Reconnaissance: Hotel booking reply-to redirect severity medium
- Reconnaissance: Large unknown recipient list severity low
- Reconnaissance: Short generic greeting message severity medium
- Recruitee Infrastructure Abuse severity high
- Request for Quote or Purchase (RFQ|RFP) with HTML smuggling attachment severity high
- Request for Quote or Purchase (RFQ|RFP) with suspicious sender or recipient pattern severity medium
- Salesforce infrastructure abuse severity medium
- Scam soliciting employer review/rating severity low
- Scam: Fake estate sale offering welding equipment and tools severity high
- Scam: Piano giveaway severity medium
- Self-sender with copy/paste instructions and suspicious domains (French/Français) severity medium
- Self-sent fake PDF attachment with misleading link severity low
- Sender: IP address in local part severity medium
- Sendgrid voicemail phish severity high
- Service abuse: Adobe legitimate domain with document approval language severity medium
- Service abuse: Apple TestFlight with suspicious developer reference severity high
- Service abuse: AppSheet infrastructure with suspicious indicators severity medium
- Service abuse: AWS SNS callback scam impersonation severity medium
- Service abuse: Behance document sharing with suspicious language severity medium
- Service Abuse: Box file sharing with credential phishing intent severity medium
- Service abuse: Calendly callback scam detection severity medium
- Service abuse: Callback phishing via Microsoft Teams invite severity high
- Service abuse: Cisco secure email service with financial request severity high
- Service abuse: Cognito Forms with short body from unknown sender severity medium
- Service abuse: Coursera callback scam severity high
- Service abuse: Dropbox Paper with copy-paste instructions severity medium
- Service abuse: Elastic alerts extortion severity medium
- Service abuse: Evernote link severity low
- Service abuse: Facebook business with action required subject severity medium
- Service abuse: Facebook mail notification callback scam severity medium
- Service abuse: Fake loan/funding verification lure via Mailgun severity medium
- Service abuse: File sharing impersonation with external SharePoint links severity medium
- Service abuse: FileMail callback scam severity medium
- Service abuse: FlipHTML5 with attachment deception and credential theft language severity medium
- Service abuse: Formester with suspicious link behavior severity medium
- Service abuse: Free provider with SendGrid routing severity medium
- Service abuse: GetAccept callback scam content severity medium
- Service abuse: GitHub notification with excessive mentions and suspicious links severity high
- Service Abuse: GoDaddy infrastructure severity medium
- Service abuse: Google Calendar notification with callback scam language severity medium
- Service abuse: Google classroom solicitation severity medium
- Service abuse: Google Firebase sender address with suspicious content severity low
- Service abuse: Google Groups callback scam severity medium
- Service Abuse: HelloSign share with suspicious sender or document name severity medium
- Service abuse: HungerRush domain with SendGrid tracking targeting ProtonMail severity high
- Service abuse: IBM IAM account notification with callback scam indicators severity medium
- Service abuse: Linode Objects HTML file hosting severity medium
- Service abuse: Microsoft Forms Pro with suspicious links or QR codes severity medium
- Service abuse: Microsoft Power Apps callback scam severity medium
- Service abuse: Microsoft Power Automate callback scam impersonation severity medium
- Service abuse: Microsoft Power BI callback scam severity medium
- Service abuse: Monday.com callback scam severity medium
- Service abuse: Monday.com infrastructure with phishing intent severity high
- Service abuse: MongoDB Atlas callback scam severity medium
- Service Abuse: Nifty.com with impersonation severity medium
- Service abuse: Notion free-tier account impersonating VIP severity medium
- Service abuse: Nylas tracking subdomain with suspicious content severity medium
- Service abuse: Outlook Groups with Google Sites link and evasion tag severity medium
- Service abuse: Payoneer callback scam severity medium
- Service abuse: PayPal manager account creation with callback scam indicators severity medium
- Service abuse: Postman reply-to mismatch with credential theft intent severity medium
- Service abuse: Recruiting with suspicious language patterns from legitimate platforms severity medium
- Service abuse: Roomsy with unrelated body content severity medium
- Service abuse: Sendgrid credential theft with personalized request targeting single recipient severity medium
- Service abuse: SendGrid impersonation via Sendgrid from new sender severity high
- Service abuse: SendThisFile with credential theft and financial language severity medium
- Service abuse: Settime.io sender with callback scam intent severity medium
- Service abuse: Soundestlink redirect with suspicious indicators severity medium
- Service abuse: Substack credential theft with confusable characters and branded button redirects severity medium
- Service abuse: Suspicious Datadog alert severity high
- Service abuse: Task management message sent via SendGrid severity medium
- Service abuse: Vimeo with external plain-text links in message severity high
- Service abuse: WeTransfer callback scam severity medium
- Service abuse: Wufoo credential theft severity medium
- Service abuse: Zohodesk reply-to mismatch with job scam indicators severity medium
- Service Abuse: Zoom with freemail reply-to and recipient address in greeting severity medium
- Sharepoint file share with suspicious recipients pattern severity medium
- SharePoint OTP for filename matching org name severity medium
- Spam/fraud: Predatory journal/research paper request severity medium
- Spam: Attendee list solicitation severity low
- Spam: Cold outreach from Cloudflare-hosted newly registered domain severity low
- Spam: Cryptocurrency airdrop/giveaway severity low
- Spam: Fake dating profile notification severity low
- Spam: Fake photo share severity low
- Spam: Ghostwriting services scam with manipulative language severity medium
- Spam: New job cold outreach from unsolicited sender severity low
- Spam: Personalized subject and greetings via Salesforce Marketing Cloud severity low
- Spam: Sendersrv.com with financial communications and unsubscribe language severity medium
- Spam: Sexually explicit content with emoji in subject from freemail provider severity low
- Spam: Sexually explicit Google Drive share severity low
- Spam: Sexually explicit Google group invitation severity low
- Spam: Sexually explicit Looker Studio report severity low
- Spam: Single recipient duplicated in cc severity medium
- Spam: SMTP & Proxy Communications in Email Body severity medium
- Spam: Suspicious toll-free phone number severity low
- Spam: Unsolicited malformed PDF severity low
- Spam: Website errors solicitation severity low
- Spoofable internal domain with suspicious signals severity medium
- Stripe invoice abuse severity medium
- Suspected lookalike domain with suspicious language severity medium
- Suspected WordPress abuse with cross-site scripting (XSS) indicators severity high
- Suspicious display name: Gmail sender with engaging language severity low
- Suspicious invoice reference with missing or image-only attachments severity high
- Suspicious link to Looker Studio (lookerstudio.google.com) from a new and unsolicited sender severity medium
- Suspicious Links to Cloudflare R2 and Edge Services severity medium
- Suspicious newly registered reply-to domain with engaging financial or urgent language severity medium
- Suspicious Office 365 app authorization (OAuth) link severity high
- Suspicious recipient pattern and language with low reputation link to login severity medium
- Suspicious recipients pattern with NLU credential theft indicators severity medium
- Suspicious recipients pattern with no Compauth pass and suspicious content severity medium
- Suspicious request for financial information severity high
- Suspicious SharePoint file sharing severity medium
- Suspicious subject with long procedurally generated text blob severity medium
- Tax Form: W-8BEN solicitation severity medium
- Unicode QR code severity medium
- Vendor impersonation: Thread hijacking with typosquat domain severity high
- Venmo payment request abuse severity medium
- VIP / Executive impersonation (strict match, untrusted) severity high
- VIP Impersonation via Google Group relay with suspicious indicators severity high
- VIP impersonation with BEC language (near match, untrusted sender) severity medium
- VIP impersonation with charitable donation fraud severity high
- VIP impersonation with invoicing request severity high
- VIP impersonation with urgent request (strict match, untrusted sender) severity high
- VIP impersonation with w2 request with reply-to mismatch severity high
- VIP impersonation: Fake forwarded indicator with VIP recipient impersonation severity high
- VIP impersonation: Fake thread with display name match, email mismatch severity medium
- VIP impersonation: VIP name within a delimited subject with fake previous threads severity high
- X (Twitter) impersonation with credential phishing motives severity medium
- Xero infrastructure abuse severity medium
- Xero invoice abuse severity medium
130 detection rules reference this event. View event page.
1 detection rules reference this event. View event page.
444 detection rules reference this event. View event page.
34 detection rules reference this event. View event page.
23 detection rules reference this event. View event page.