Detection rules › By event
Sublime-Message-headers Event ID 7000012
Sublime MQL (73)
- Advance Fee Fraud (AFF) from freemail provider or suspicious TLD
- Attachment: EML with link to credential phishing page
- Attachment: Office document with VSTO add-in
- Attachment: PDF with credential theft language and invalid reply-to domain
- BEC with unusual reply-to or return-path mismatch
- BEC/Fraud: Generic scam attempt to undisclosed recipients
- BEC/Fraud: Penpal scam
- BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns
- Brand impersonation: Aramco
- Brand impersonation: Google Workspace alert notification
- Brand impersonation: LinkedIn
- Brand impersonation: Meta and subsidiaries
- Brand impersonation: Microsoft fake sign-in alert
- Brand impersonation: Norton
- Brand impersonation: QuickBooks notification from Intuit themed company name
- Business Email Compromise (BEC) attempt from unsolicited sender
- Business Email Compromise (BEC) attempt with masked recipients and reply-to mismatch (unsolicited)
- Callback phishing via e-signature service
- Callback phishing: Branded invoice from sender/reply-to domain less than 30 days old
- COVID-19 themed fraud with sender and reply-to mismatch or compensation award
- Cyrillic vowel substitution in subject or display name from unknown sender
- Cyrillic vowel substitutions with suspicious subject from unknown sender
- Domain impersonation: Freemail reply-to local lookalike with financial request
- Fake message thread - Untrusted sender with a mismatched freemail reply-to address
- Fake request for tax preparation
- Fraudulent order confirmation/shipping notification from Chinese sender domain
- Free email provider sender with mismatched provider reply-to
- Generic service abuse from newly registered domain
- Google share notification with suspicious comments
- Headers: Invalid recipient domain with mismatched reply-to from new sender
- Headers: X-Source-Auth mismatch with mismatched reply-to domain
- Honorific greeting BEC attempt with sender and reply-to mismatch
- HR impersonation via e-sign agreement comment
- Impersonation: Suspected supplier impersonation with suspicious content
- Inbound message from popular service via newly observed distribution list
- Investor solicitation with organization targeting
- Link: File sharing impersonation with suspicious language and sending patterns
- Link: Multistage landing - Abused Google Drive
- Link: Multistage landing - Published Google Doc
- Link: Romance/Sexual Language With Suspicious Link
- Newly registered sender or reply-to domain with newly registered linked domain
- Reconnaissance: Empty subject with mismatched reply-to from new sender
- Reconnaissance: Hotel booking reply-to redirect
- Request for Quote or Purchase (RFQ|RFP) with suspicious sender or recipient pattern
- Scam: Fake estate sale offering welding equipment and tools
- Scam: Piano giveaway
- Service abuse: AppSheet infrastructure with suspicious indicators
- Service abuse: Cisco secure email service with financial request
- Service abuse: DocSend share from newly registered domain
- Service abuse: DocuSign notification with suspicious sender or document name
- Service abuse: DocuSign share from an unsolicited reply-to address
- Service abuse: Dropbox share from new domain
- Service abuse: Dropbox share with suspicious sender or document name
- Service abuse: GitHub notification with excessive mentions and suspicious links
- Service abuse: Google Drive share from an unsolicited reply-to address
- Service abuse: Google Drive share from new reply-to domain
- Service abuse: Google Firebase sender address with suspicious content
- Service abuse: QuickBooks notification from new domain
- Service abuse: SurveyMonkey survey from newly registered domain
- Service Abuse: Zoom with freemail reply-to and recipient address in greeting
- Service abuse: Zoom with newly registered reply-to domain
- Spam: Sexually explicit Google Drive share
- Spam: Sexually explicit Looker Studio report
- Suspicious DocuSign share from new domain
- Suspicious newly registered reply-to domain with engaging financial or urgent language
- Suspicious request for financial information
- Suspicious SharePoint file sharing
- VIP / Executive impersonation (strict match, untrusted)
- VIP Impersonation via Google Group relay with suspicious indicators
- VIP impersonation with BEC language (near match, untrusted sender)
- VIP impersonation with invoicing request
- VIP impersonation with urgent request (strict match, untrusted sender)
- VIP impersonation with w2 request with reply-to mismatch