Detection rules › By event
Sublime-Message-headers Event ID 7000011
Sublime MQL (90)
- AnonymousFox indicators
- Attachment: Adobe image lure in body or attachment with suspicious link
- Attachment: Calendar invite with suspicious link leading to an open redirect
- Attachment: Callback phishing solicitation via text-based file
- Attachment: DocuSign impersonation via PDF linking to new domain
- Attachment: EML file contains HTML attachment with login portal indicators
- Attachment: Fake secure message and suspicious indicators
- Attachment: Microsoft 365 credential phishing
- Attachment: Microsoft impersonation via PDF with link and suspicious language
- Attachment: RFC822 containing suspicious file sharing language with links from untrusted sender
- BEC with unusual reply-to or return-path mismatch
- Benefits enrollment impersonation
- Brand impersonation: Adobe (QR code)
- Brand impersonation: Adobe Sign with suspicious indicators
- Brand impersonation: Amazon
- Brand impersonation: Booking.com
- Brand impersonation: Capital One
- Brand impersonation: Cloud services with credential theft intent
- Brand impersonation: DocuSign
- Brand impersonation: DocuSign branded attachment lure with no DocuSign links
- Brand impersonation: Dropbox
- Brand impersonation: Fake DocuSign HTML table not linking to DocuSign domains
- Brand impersonation: Github
- Brand Impersonation: Google (QR Code)
- Brand impersonation: Google Workspace alert notification
- Brand impersonation: Internal Revenue Service
- Brand impersonation: Mailgun
- Brand impersonation: Microsoft (QR code)
- Brand impersonation: Microsoft fake sign-in alert
- Brand impersonation: Microsoft logo in HTML with fake quarantine release notification
- Brand impersonation: Microsoft with embedded logo and credential theft language
- Brand impersonation: Morgan Stanley
- Brand Impersonation: ShareFile
- Brand impersonation: Sharepoint
- Brand impersonation: SharePoint PDF attachment with credential theft language
- Brand Impersonation: Stripe
- Brand impersonation: TikTok
- ClickFunnels link infrastructure abuse
- Constant Contact link infrastructure abuse
- Credential phishing content and link (untrusted sender)
- Credential phishing language and suspicious indicators (unknown sender)
- Credential phishing: 'Secure message' and engaging language
- Credential phishing: DocuSign embedded image lure with no DocuSign domains in links
- Credential phishing: Fake password expiration from new and unsolicited sender
- Credential phishing: Hyper-linked image leading to free file host
- Credential phishing: Onedrive impersonation
- Credential phishing: Suspicious e-sign agreement document notification
- Employee impersonation: Payroll fraud
- Encrypted Microsoft Office files from untrusted sender
- Extortion / sextortion (untrusted sender)
- Extortion / sextortion in attachment from untrusted sender
- Fake message thread - Untrusted sender with a mismatched freemail reply-to address
- Fake thread with suspicious indicators
- Fake voicemail notification (untrusted sender)
- Free email provider sender with mismatched provider reply-to
- Headers: Self-sender using Microsoft CompAuth bypass with credential theft content
- Headers: X-Source-Auth mismatch with mismatched reply-to domain
- HTML smuggling containing recipient email address
- Impersonation: Human Resources with link or attachment and engaging language
- Impersonation: Internal corporate services
- Inbound message from popular service via newly observed distribution list
- Link: Credential phishing traversing Russian infrastructure
- Link: File sharing impersonation with suspicious language and sending patterns
- Link: Free file hosting with undisclosed recipients
- Link: Free subdomain host with undisclosed recipients
- Link: Google Calendar invite linking to an open redirect from an untrusted freemail sender
- Link: Uncommon SharePoint document type with sender's display name
- Mass campaign: Cross Site Scripting (XSS) attempt
- Message traversed multiple onmicrosoft.com tenants
- Microsoft infrastructure abuse with suspicious patterns
- Open redirect: predictiveresponse.net
- Salesforce infrastructure abuse
- Service abuse: HelloSign from an unsolicited sender address
- Service Abuse: HelloSign share with suspicious sender or document name
- Service abuse: Monday.com infrastructure with phishing intent
- Service abuse: Trello board invitation with VIP impersonation
- SharePoint OTP for filename matching org name
- Spam/fraud: Predatory journal/research paper request
- Spam: BlackBaud infrastructure abuse
- Spam: Default Microsoft Exchange Online sender domain (onmicrosoft.com)
- Spam: Fake photo share
- Spam: Personalized subject and greetings via Salesforce Marketing Cloud
- Spam: Single recipient duplicated in cc
- SPF temp error
- Spoofable internal domain with suspicious signals
- Suspected cross-site scripting (XSS) found in subject
- Suspicious mailer received from Gmail servers
- Suspicious recipients pattern with no Compauth pass and suspicious content
- VIP Impersonation via Google Group relay with suspicious indicators
- Xero infrastructure abuse