Detection rules › By event
Sublime-Message-subject Event ID 7000025
Sublime MQL (378)
- Advance Fee Fraud (AFF) from freemail provider or suspicious TLD
- Attachment: Adobe image lure in body or attachment with suspicious link
- Attachment: Calendar file with invisible Unicode characters
- Attachment: Callback phishing solicitation via image file
- Attachment: Callback phishing solicitation via pdf file
- Attachment: Callback phishing solicitation via text-based file
- Attachment: Cold outreach with invitation subject and not attachment
- Attachment: Credit card application with WhatsApp contact
- Attachment: EML file contains HTML attachment with login portal indicators
- Attachment: EML file with HTML attachment (unsolicited)
- Attachment: EML with link to credential phishing page
- Attachment: Encrypted PDF with credential theft body
- Attachment: Encrypted zip file with payment-related lure
- Attachment: Fake attachment image lure
- Attachment: Fake voicemail via PDF
- Attachment: Legal themed message or PDF with suspicious indicators
- Attachment: Microsoft 365 credential phishing
- Attachment: PDF bid/proposal lure with credential theft indicators
- Attachment: PDF proposal with credential theft indicators
- Attachment: QR code link with base64-encoded recipient address
- Attachment: RFP/RFQ impersonating government entities
- Attachment: Suspicious employee policy update document lure
- Attachment: USDA bid invitation impersonation
- BEC/Fraud: Fake investment outreach from suspicious TLD
- BEC/Fraud: Job scam fake thread or plaintext pivot to freemail
- BEC/Fraud: Reply-chain manipulation with urgent keywords and self-reply
- BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns
- BEC: Employee impersonation with subject manipulation
- Benefits enrollment impersonation
- Body: Embedded email headers indicative of thread hijacking/abuse
- Body: PayApp transaction reference pattern
- Brand impersonation: Adobe (QR code)
- Brand impersonation: Adobe with suspicious language and link
- Brand impersonation: Amazon
- Brand impersonation: Aramco
- Brand impersonation: Automobile assistance associations
- Brand impersonation: Binance
- Brand impersonation: Box file sharing service
- Brand impersonation: Canada Revenue Agency
- Brand impersonation: Capital One
- Brand impersonation: Chase Bank
- Brand impersonation: DHL
- Brand impersonation: Discord notification
- Brand impersonation: DocuSign
- Brand impersonation: Enbridge
- Brand impersonation: Evite
- Brand impersonation: Fake Fax
- Brand impersonation: Figma with malicious document access overlay
- Brand impersonation: File sharing notification with template artifacts
- Brand Impersonation: Gemini Trust Company
- Brand impersonation: Github
- Brand impersonation: GitHub with callback scam indicators
- Brand Impersonation: Google (QR Code)
- Brand impersonation: Google Drive fake file share
- Brand impersonation: Google Workspace alert notification
- Brand impersonation: Greenvelope
- Brand impersonation: Interac
- Brand impersonation: Internal Revenue Service
- Brand impersonation: Mailgun
- Brand impersonation: Marriott with gift language
- Brand impersonation: McAfee
- Brand impersonation: Meta and subsidiaries
- Brand impersonation: Microsoft
- Brand impersonation: Microsoft (QR code)
- Brand impersonation: Microsoft fake sign-in alert
- Brand impersonation: Microsoft Teams invitation
- Brand impersonation: Microsoft with embedded logo and credential theft language
- Brand impersonation: Microsoft with low reputation links
- Brand impersonation: Navan
- Brand impersonation: Okta
- Brand impersonation: OpenAI with payment issues
- Brand impersonation: Paperless Post
- Brand impersonation: PNC
- Brand Impersonation: Procore
- Brand impersonation: QuickBooks dispute notification
- Brand impersonation: Robinhood
- Brand impersonation: SendGrid
- Brand Impersonation: ShareFile
- Brand impersonation: Sharepoint
- Brand impersonation: Sharepoint fake file share
- Brand impersonation: SharePoint PDF attachment with credential theft language
- Brand impersonation: Social Security Administration
- Brand impersonation: Toronto-Dominion Bank
- Brand impersonation: UK government Home Office
- Brand impersonation: ukr[.]net
- Brand impersonation: UPS
- Brand impersonation: USPS
- Brand impersonation: Wells Fargo
- Brand impersonation: WeTransfer
- Brand impersonation: Zoom
- Brand impersonation: Zoom via lookalike domain
- Brand impersonation: Zoom with deceptive link display
- Business Email Compromise (BEC) attempt from untrusted sender
- Business Email Compromise (BEC) attempt from untrusted sender (French/Français)
- Business Email Compromise (BEC) with request for mobile number
- Callback phishing via DocuSign comment
- Callback phishing via Google Meet
- Callback phishing via Intuit service abuse
- Callback phishing via Microsoft comment
- Callback phishing via Yammer comment
- Callback phishing via Zelle Service Abuse
- Callback phishing via Zoho service abuse
- Callback Phishing via Zoom comment
- Callback scam: Impersonation via TimeTrade infrastructure
- ClickFunnels link infrastructure abuse
- Cloud storage impersonation with credential theft indicators
- Commonly abused sender TLD with engaging language
- Compensation review with QR code in attached EML
- Constant Contact link infrastructure abuse
- COVID-19 themed fraud with sender and reply-to mismatch or compensation award
- Credential phishing language and suspicious indicators (unknown sender)
- Credential phishing link (unknown sender)
- Credential phishing: Blue button styled link with file-sharing template artifacts
- Credential phishing: Email delivery failure impersonation
- Credential phishing: Engaging language and other indicators (untrusted sender)
- Credential phishing: Fake card notification with tracking lure
- Credential phishing: Fake password expiration from new and unsolicited sender
- Credential phishing: Fake storage alerts (unsolicited)
- Credential phishing: Generic document sharing
- Credential phishing: Onedrive impersonation
- Credential phishing: Re-Authentication lure
- Credential phishing: Suspicious e-sign agreement document notification
- Credential Phishing: Suspicious language, link, recipients and other indicators
- Credential phishing: Suspicious subject with urgent financial request and link
- Credential phishing: Tax form impersonation with payment request
- Cyrillic vowel substitution in subject or display name from unknown sender
- Cyrillic vowel substitutions with suspicious subject from unknown sender
- Display name and subject impersonation using recipient SLD (new sender)
- Display Name Emoji with Financial Symbols
- DLP: Argentina DNI Number
- DLP: Australia Bank Account Number
- DLP: Australia Driver's License Number
- DLP: Australia Medical Account Number
- DLP: Australia Passport Number
- DLP: Australia SWIFT Code
- DLP: Australia Tax File Number
- DLP: Austria Identity Card
- DLP: Austria Social Security Number
- DLP: Austria Tax Identification Number
- DLP: AWS Credentials
- DLP: Azure Authentication Token
- DLP: Basic Authentication Header
- DLP: Belgium National Number
- DLP: Brazil CPF Number
- DLP: Brazil RG Number
- DLP: Bulgaria Uniform Civil Number
- DLP: Canada Bank Account Number
- DLP: Canada Driver's License Number
- DLP: Canada Health Service Number
- DLP: Canada Passport Number
- DLP: Canada Personal Health Identification Number (PHIN)
- DLP: Canada Social Insurance Number (SIN)
- DLP: Chile Identity Card Number
- DLP: China Resident ID Number
- DLP: Colombia Citizenship Card Number
- DLP: Croatia Personal Identification (OIB)
- DLP: Cyprus Identity Card
- DLP: Czech Personal Identity Number
- DLP: Denmark Personal Identification Number
- DLP: Estonia Personal Identification Code
- DLP: Finland National ID
- DLP: France Bank Account Number
- DLP: France Driver's License Number
- DLP: France National ID Card (CNI)
- DLP: France Passport Number
- DLP: France Social Security Number (INSEE)
- DLP: France Tax Identification Number (SPI)
- DLP: GCP API Key
- DLP: Germany Bank Account Number (IBAN)
- DLP: Germany Driver's License Number
- DLP: Germany Identity Card Number (Personalausweisnummer)
- DLP: Germany Passport Number
- DLP: Germany Tax Identification Number
- DLP: GitHub Token
- DLP: Greece National ID Card
- DLP: Greece Social Security Number (AMKA)
- DLP: Greece Tax Identification Number
- DLP: Hungary Personal Identification Number
- DLP: Hungary Social Security Number (TAJ)
- DLP: Hungary Tax Identification Number
- DLP: IMEI Number
- DLP: IMSI Number
- DLP: India Aadhaar Number
- DLP: India Bank Account Number
- DLP: India PAN Number
- DLP: India Passport Number
- DLP: IP Address
- DLP: Ireland Personal Public Service (PPS) Number
- DLP: Israel Bank Account Number
- DLP: Israel National ID
- DLP: Israel SWIFT Code
- DLP: Italy Fiscal Code
- DLP: Japan Bank Account Number
- DLP: Japan Driver's License Number
- DLP: Japan MyNumber ID
- DLP: Japan Passport Number
- DLP: Japan Social Insurance Number
- DLP: JSON Web Token (JWT)
- DLP: Latvia Personal Code
- DLP: Lithuania Personal Code
- DLP: Luxembourg National ID (Natural Persons)
- DLP: Luxembourg National ID (Non-Natural Persons)
- DLP: MAC Address
- DLP: Malta Identity Card Number
- DLP: Malta Tax ID Number
- DLP: Mexico CURP Number
- DLP: Mexico Passport Number
- DLP: Netherlands Citizen's Service (BSN) Number
- DLP: Netherlands Tax Identification Number
- DLP: OAuth Client Secret
- DLP: Poland Identity Card
- DLP: Poland Tax Identification Number
- DLP: Portugal Citizen Card Number
- DLP: Portugal Tax Identification Number
- DLP: Private Key
- DLP: Romania Personal Numerical Code
- DLP: Saudi Arabia IBAN
- DLP: Saudi Arabia National ID
- DLP: Saudi Arabia SWIFT Code
- DLP: Slack Token
- DLP: Slovakia Personal Number
- DLP: Slovenia Tax Identification Number
- DLP: Slovenia Unique Master Citizen Number
- DLP: South Korea Resident Registration Number (RRN)
- DLP: Spain Bank Account Number
- DLP: Spain DNI/NIE
- DLP: Spain Passport Number
- DLP: Spain Social Security Number
- DLP: Spain Tax Identification Number
- DLP: SSL Certificate
- DLP: Sweden National ID
- DLP: Sweden Tax Identification Number
- DLP: Taiwan ID Number
- DLP: Turkey ID Number
- DLP: UK National Health Service Number
- DLP: UK National Insurance Number (NINO)
- DLP: UK Passport Number
- DLP: UK SWIFT Code
- DLP: US Bank Account Number
- DLP: US Driver's License Number
- DLP: US ICD-10-CM Code
- DLP: US ICD-9-CM Code
- DLP: US Individual Taxpayer Identification Number (ITIN)
- DLP: US Insurance Claim Number
- DLP: US Passport Number
- DLP: US Social Security Number (SSN)
- DLP: Vehicle Identification Number (VIN)
- DocuSign impersonation via CloudHQ links
- DocuSign impersonation via spoofed Intuit sender
- EML attachment with credential theft language (unknown sender)
- Employee impersonation with urgent request (untrusted sender)
- Employee impersonation: Payroll fraud
- Extortion / sextortion (untrusted sender)
- Extortion / Sextortion - PDF attachment leveraging breach data from freemail sender
- Fake message thread - Untrusted sender with a mismatched freemail reply-to address
- Fake message thread with a suspicious link and engaging language from an unknown sender
- Fake request for tax preparation
- Fake scan-to-email message
- Fake thread with suspicious indicators
- Fake voicemail notification (untrusted sender)
- Fake Zoom meeting invite with suspicious link
- File sharing link with a suspicious subject
- Google Notification alert link from non-Google sender
- Headers: Fake in-reply-to with wildcard sender and missing thread context
- Headers: System account impersonation with empty sender address
- Impersonation: Australian Federal Police with criminal case language
- Impersonation: Chrome Web Store policy
- Impersonation: Employee using fabricated identity in initial contact
- Impersonation: Internal corporate services
- Impersonation: Legal firm with copyright infringement notice
- Impersonation: SharePoint reply header anomaly
- Investor solicitation with organization targeting
- Link: Apple TestFlight from suspicious sender
- Link: Base64 encoded recipient address in URL fragment with subject hash
- Link: BEC with newly registered domains and financial keywords
- Link: Display text matches subject line
- Link: Executable file download with suspicious message content
- Link: File sharing pretext with suspicious body and link
- Link: Google Calendar invite linking to an open redirect from an untrusted freemail sender
- Link: HR impersonation with suspicious domain indicators and credential theft
- Link: Job recruitment lure from unsolicited sender with suspicious hosting
- Link: Microsoft impersonation using hosted png with suspicious link
- Link: Multistage landing - Abused Adobe frame.io
- Link: Multistage landing - Abused Google Drive
- Link: Non-standard port 8443 in display URL
- Link: PDF and financial display text to free file host
- Link: Personalized URL with recipient address on commonly abused web service
- Link: Secure SharePoint file share from new or unusual sender
- Link: Self-sender with sender org in subject and credential theft indicator
- Link: Self-sent PDF lure with subject correlation
- Link: SharePoint filename matches org name
- Link: SharePoint files shared from GoDaddy federated tenants
- Link: Shortened URL with fragment matching subject
- Link: Suspicious SharePoint document name
- Link: Tax document lure Portuguese/Spanish with suspicious domains
- Link: Uncommon SharePoint document type with sender's display name
- Mass campaign: Cross Site Scripting (XSS) attempt
- Mass campaign: recipient address in subject, body, and link (untrusted sender)
- Mismatched links: Free file share with urgent language
- PayPal invoice abuse
- QR Code with suspicious indicators
- Reconnaissance: All recipients cc/bcc'd or undisclosed
- Reconnaissance: Email address harvesting attempt
- Reconnaissance: Empty message from uncommon sender
- Reconnaissance: Empty subject with mismatched reply-to from new sender
- Reconnaissance: Hotel booking reply-to redirect
- Reconnaissance: Large unknown recipient list
- Reconnaissance: Short generic greeting message
- Request for Quote or Purchase (RFQ|RFP) with HTML smuggling attachment
- Request for Quote or Purchase (RFQ|RFP) with suspicious sender or recipient pattern
- Salesforce infrastructure abuse
- Scam soliciting employer review/rating
- Self-sender with copy/paste instructions and suspicious domains (French/Français)
- Sendgrid voicemail phish
- Service abuse: Adobe Sign notification from an unsolicited reply-to address
- Service abuse: Amazon invitation with suspected callback phishing
- Service abuse: AWS SNS callback scam impersonation
- Service Abuse: Box file sharing with credential phishing intent
- Service abuse: Callback phishing via Microsoft Teams invite
- Service abuse: Cisco secure email service with financial request
- Service abuse: Demio notifications with suspicious content patterns
- Service abuse: DocuSign notification with suspicious sender or document name
- Service abuse: DocuSign share from an unsolicited reply-to address
- Service abuse: Dropbox share from an unsolicited reply-to address
- Service abuse: Dropbox share with suspicious sender or document name
- Service abuse: Facebook business with action required subject
- Service abuse: File sharing impersonation with external SharePoint links
- Service Abuse: GoDaddy infrastructure
- Service abuse: Google classroom solicitation
- Service abuse: Google Firebase sender address with suspicious content
- Service Abuse: HelloSign share with suspicious sender or document name
- Service abuse: Microsoft Power Apps callback scam
- Service abuse: Microsoft with suspicious indicators in subject
- Service abuse: Monday.com infrastructure with phishing intent
- Service abuse: PayPal manager account creation with callback scam indicators
- Service abuse: QuickBooks notification from new domain
- Service abuse: QuickBooks notification with suspicious comments
- Service abuse: SendGrid impersonation via Sendgrid from new sender
- Service abuse: Task management message sent via SendGrid
- Service abuse: Vimeo with external plain-text links in message
- Sharepoint file share with suspicious recipients pattern
- Spam: Attendee list solicitation
- Spam: BlackBaud infrastructure abuse
- Spam: Commonly observed formatting of unauthorized free giveaways
- Spam: Cryptocurrency airdrop/giveaway
- Spam: Default Microsoft Exchange Online sender domain (onmicrosoft.com)
- Spam: Fake photo share
- Spam: Ghostwriting services scam with manipulative language
- Spam: Mastercard promotional content with image-based body
- Spam: New job cold outreach from unsolicited sender
- Spam: New link domain (<=10d) and emojis
- Spam: Personalized subject and greetings via Salesforce Marketing Cloud
- Spam: Sexually explicit content with emoji in subject from freemail provider
- Spam: Sexually explicit Google Drive share
- Spam: Sexually explicit Google group invitation
- Spam: Sexually explicit Looker Studio report
- Spam: Single recipient duplicated in cc
- Spam: URL shortener with short body content and emojis
- Spam: Website errors solicitation
- Subject and sender display name contains matching long alphanumeric string
- Subject: Suspicious bracketed reference
- Suspected cross-site scripting (XSS) found in subject
- Suspected WordPress abuse with cross-site scripting (XSS) indicators
- Suspicious attachment with unscannable Cloudflare link
- Suspicious DocuSign share from new domain
- Suspicious invoice reference with missing or image-only attachments
- Suspicious message with unscannable Cloudflare link
- Suspicious message with unscannable Vercel link
- Suspicious request for financial information
- Suspicious SharePoint file sharing
- Suspicious subject with long procedurally generated text blob
- Tax Form: W-8BEN solicitation
- Vendor impersonation: Thread hijacking with typosquat domain
- VIP / Executive impersonation in subject (untrusted)
- VIP Impersonation via Google Group relay with suspicious indicators
- VIP impersonation with charitable donation fraud
- VIP impersonation with w2 request with reply-to mismatch
- Xero infrastructure abuse