Detection rules › By event
Sublime-Message-headers Event ID 7000013
Sublime MQL (36)
- BEC with unusual reply-to or return-path mismatch
- Brand impersonation: Google Drive fake file share
- Brand impersonation: Greenvelope
- Brand impersonation: Ledger
- Brand impersonation: LinkedIn
- Brand impersonation: Microsoft fake sign-in alert
- Brand impersonation: Microsoft with embedded logo and credential theft language
- Business Email Compromise (BEC) attempt from unsolicited sender
- Callback phishing: Branded invoice from sender/reply-to domain less than 30 days old
- Credential phishing: Engaging language and other indicators (untrusted sender)
- Cyrillic vowel substitution in subject or display name from unknown sender
- Fake request for tax preparation
- Fake shipping notification with link to free file hosting
- Fake thread with suspicious indicators
- Google Notification alert link from non-Google sender
- Inbound message from popular service via newly observed distribution list
- Invoicera infrastructure abuse
- Link: File sharing impersonation with suspicious language and sending patterns
- Link: Free file hosting with undisclosed recipients
- Link: Squarespace infrastructure abuse
- Message traversed multiple onmicrosoft.com tenants
- Microsoft infrastructure abuse with suspicious patterns
- Open redirect: bestdeals.today
- Open redirect: isadatalab.com
- Open redirect: queue.swytchbike.com
- Open redirect: Ticketmaster
- Russia return-path TLD (untrusted sender)
- Salesforce infrastructure abuse
- Sendgrid onmicrosoft.com domain phishing
- Sendgrid voicemail phish
- Service abuse: AWS SNS callback scam impersonation
- Service abuse: GitHub notification with excessive mentions and suspicious links
- Service abuse: Task management message sent via SendGrid
- Suspicious mailer received from Gmail servers
- Tax Form: W-8BEN solicitation
- VIP Impersonation via Google Group relay with suspicious indicators