Detection rules › By event
Sublime-Message-body Event ID 7000006
Sublime MQL (30)
- Anthropic Magic String in HTML
- Attachment: Callback phishing solicitation via pdf file
- Attachment: Legal themed message or PDF with suspicious indicators
- Body: Embedded email headers indicative of thread hijacking/abuse
- Brand impersonation: Google Drive fake file share
- Brand impersonation: Microsoft with low reputation links
- Brand impersonation: Sharepoint
- Brand impersonation: Sharepoint fake file share
- Brand impersonation: Wells Fargo
- Fake message thread - Untrusted sender with a mismatched freemail reply-to address
- Fake thread with suspicious indicators
- HTML smuggling with atob in message body
- Impersonation: Fake Gmail attachment
- Impersonation: SharePoint reply header anomaly
- Impersonation: Suspected supplier impersonation with suspicious content
- Link to Google Apps Script macro via comment tagging
- Link: Remittance payment request with timeline template
- Link: Secure SharePoint file share from new or unusual sender
- Link: Zoho form link from unsolicited sender
- Malformed URL prefix
- Reconnaissance: Empty message from uncommon sender
- Service abuse: Google Firebase sender address with suspicious content
- Spam: Attendee list solicitation
- Spam: Fake photo share
- Spam: New link domain (<=10d) and emojis
- Spam: URL shortener with short body content and emojis
- Suspicious invoice reference with missing or image-only attachments
- URL with Unicode U+2044 (⁄) or U+2215 (∕) characters
- VIP impersonation with charitable donation fraud
- VIP impersonation: Fake thread with display name match, email mismatch