Detection rules › By event
Sublime-Message-headers Event ID 7000010
Sublime MQL (50)
- Attachment: EML with Sharepoint link likely unrelated to sender
- Attachment: Fake secure message and suspicious indicators
- Brand impersonation: Adobe with suspicious language and link
- Brand impersonation: AliExpress
- Brand impersonation: Aquent
- Brand impersonation: Box file sharing service
- Brand impersonation: DocuSign
- Brand impersonation: Mailgun
- Brand impersonation: Microsoft with embedded logo and credential theft language
- Brand impersonation: Microsoft with low reputation links
- Brand impersonation: Morgan Stanley
- Brand impersonation: Okta
- Brand impersonation: Wix
- Callback phishing in body or attachment (untrusted sender)
- ClickFunnels link infrastructure abuse
- Compensation review with QR code in attached EML
- Credential phishing: 'Secure message' and engaging language
- Credential phishing: Email delivery failure impersonation
- Credential phishing: Fake storage alerts (unsolicited)
- EML attachment with credential theft language (unknown sender)
- Fake email quarantine notification
- Fake message thread with a suspicious link and engaging language from an unknown sender
- Fake thread with suspicious indicators
- Fake voicemail notification (untrusted sender)
- Impersonation: Internal corporate services
- Link: Credential phishing traversing Russian infrastructure
- Link: Referrer anonymization service from untrusted sender
- Link: Squarespace infrastructure abuse
- Open redirect: bubblelife.com
- Open redirect: convertcart.com
- Open redirect: magic4media.com
- Open redirect: pmifunds.com
- Open redirect: predictiveresponse.net
- Open redirect: qrxtech.com
- Open redirect: secondstreetapp.com
- Open redirect: Signature Travel Network
- Open redirect: smartadserver.com
- Open redirect: tuttocauzioni.it
- Open redirect: weblinkconnect.com
- Service Abuse: ExactTarget with suspicious sender indicators
- Service abuse: Free provider with SendGrid routing
- Service abuse: Monday.com infrastructure with phishing intent
- Service abuse: Sendgrid credential theft with personalized request targeting single recipient
- Service abuse: SendGrid impersonation via Sendgrid from new sender
- Spam/fraud: Predatory journal/research paper request
- Spam: BlackBaud infrastructure abuse
- Spam: Personalized subject and greetings via Salesforce Marketing Cloud
- Spam: Sendersrv.com with financial communications and unsubscribe language
- Spoofable internal domain with suspicious signals
- Vendor compromise: GovDelivery message with suspicious link