1320 detection rules reference this event. View event page.Sublime MQL (1320)
- Abuse: Cloudflare Workers Hosted EvilTokens Domain Structure severity high
- Abuse: Robinhood injected content severity medium
- Adobe branded PDF file linking to a password-protected file from untrusted sender severity high
- Advance Fee Fraud (AFF) from freemail provider or suspicious TLD severity medium
- AnonymousFox indicators severity high
- Anthropic Magic String in HTML severity low
- Attachment soliciting user to enable macros severity high
- Attachment with auto-executing macro (unsolicited) severity medium
- Attachment with auto-opening VBA macro (unsolicited) severity medium
- Attachment with encrypted zip (unsolicited) severity medium
- Attachment with high risk VBA macro (unsolicited) severity high
- Attachment with macro calling executable severity high
- Attachment with suspicious author (unsolicited) severity high
- Attachment with unscannable encrypted zip severity medium
- Attachment with VBA macros from employee impersonation (unsolicited) severity high
- Attachment: .csproj with suspicious commands severity high
- Attachment: 7z Archive Containing RAR File severity medium
- Attachment: Adobe image lure in body or attachment with suspicious link severity medium
- Attachment: Adobe Sign lure PDF with embedded banner images severity medium
- Attachment: Any .sap file (unsolicited) severity low
- Attachment: Any HTML file (unsolicited) severity low
- Attachment: Any HTML file (untrusted sender) severity medium
- Attachment: Any HTML file within archive (unsolicited) severity medium
- Attachment: Archive containing disallowed file type severity low
- Attachment: Archive containing HTML file with file scheme link severity high
- Attachment: Archive contains DLL-loading macro severity high
- Attachment: Archive with embedded CHM file severity medium
- Attachment: Archive with embedded EXE file severity high
- Attachment: Archive with pdf, txt and wsf files severity medium
- Attachment: Base64 encoded bash command in filename severity high
- Attachment: Calendar file with invisible Unicode characters severity high
- Attachment: Calendar invite from recently registered domain severity high
- Attachment: Calendar invite with Google redirect and invoice request severity medium
- Attachment: Calendar invite with suspicious link leading to an open redirect severity high
- Attachment: Callback phishing solicitation via image file severity high
- Attachment: Callback phishing solicitation via pdf file severity high
- Attachment: Callback phishing solicitation via text-based file severity medium
- Attachment: Canva PDF with susupicious author metadata severity high
- Attachment: cmd file extension severity low
- Attachment: Cold outreach with invitation subject and not attachment severity high
- Attachment: Compensation review lure with QR code severity high
- Attachment: Compensation-themed DOCX with QR code credential theft severity high
- Attachment: Credit card application with WhatsApp contact severity medium
- Attachment: CVE-2021-40444 - MSHTML Remote Code Execution Vulnerability severity critical
- Attachment: CVE-2023-21716 - Microsoft Office Remote Code Execution Vulnerability severity high
- Attachment: CVE-2025-24071 - Microsoft Windows File Explorer Spoofing Vulnerability severity critical
- Attachment: Decoy PDF author (Julie P.) severity high
- Attachment: DocuSign impersonation via PDF linking to new domain severity medium
- Attachment: DocX embedded binary severity high
- Attachment: DOCX with hyperlink targeting recipient address severity medium
- Attachment: DOCX with malicious document template artifacts severity medium
- Attachment: Double base64-encoded zip file in HTML smuggling attachment severity high
- Attachment: Dropbox image lure with no Dropbox domains in links severity medium
- Attachment: Duplicated header pages in fraudulent multi-page PDF Request for Quotation severity medium
- Attachment: EICAR string present severity low
- Attachment: Embedded Javascript in SVG file severity high
- Attachment: Embedded VBScript in MHT file severity medium
- Attachment: EML containing a base64 encoded script severity high
- Attachment: EML file contains HTML attachment with login portal indicators severity high
- Attachment: EML file with HTML attachment (unsolicited) severity medium
- Attachment: EML file with IPFS links severity medium
- Attachment: EML with embedded Javascript in SVG file severity high
- Attachment: EML with Encrypted ZIP severity low
- Attachment: EML with link to credential phishing page severity high
- Attachment: EML with QR code redirecting to Cloudflare challenges severity low
- Attachment: EML with SharePoint files shared from GoDaddy federated tenants severity low
- Attachment: EML with Sharepoint link likely unrelated to sender severity medium
- Attachment: EML with suspicious indicators severity medium
- Attachment: Emotet heavily padded doc in zip file severity high
- Attachment: Employment contract update with suspicious file naming severity high
- Attachment: Encrypted Microsoft Office file (unsolicited) severity medium
- Attachment: Encrypted PDF With Credential Harvesting Indicators severity medium
- Attachment: Encrypted PDF with credential theft body severity medium
- Attachment: Encrypted PDF with credential theft language in EML severity medium
- Attachment: Encrypted ZIP containing VHDX file severity medium
- Attachment: Encrypted zip file with payment-related lure severity medium
- Attachment: Excel file with document sharing lure created by Go Excelize severity high
- Attachment: Excel file with suspicious template identifier severity high
- Attachment: Excel Web Query File (IQY) severity high
- Attachment: Fake attachment image lure severity medium
- Attachment: Fake lawyer & sports agent identities severity high
- Attachment: Fake PDF Invoices Yara severity medium
- Attachment: Fake scan-to-email severity medium
- Attachment: Fake secure message and suspicious indicators severity medium
- Attachment: Fake Slack installer severity high
- Attachment: Fake voicemail via PDF severity medium
- Attachment: Fake Zoom installer severity high
- Attachment: Fictitious invoice using LinkedIn's address severity medium
- Attachment: File execution via Javascript severity medium
- Attachment: Filename containing Unicode braille pattern blank character severity high
- Attachment: Filename containing Unicode right-to-left override character severity high
- Attachment: Finance themed PDF with observed phishing template severity medium
- Attachment: HTML attachment with Javascript location severity high
- Attachment: HTML attachment with login portal indicators severity medium
- Attachment: HTML file contains exclusively Javascript severity medium
- Attachment: HTML file with excessive 'const' declarations and abnormally long timeouts severity high
- Attachment: HTML file with excessive padding and suspicious patterns severity high
- Attachment: HTML file with reference to recipient and suspicious patterns severity high
- Attachment: HTML smuggling 'body onload' linking to suspicious destination severity high
- Attachment: HTML smuggling 'body onload' with high entropy and suspicious text severity high
- Attachment: HTML smuggling - QR Code with suspicious links severity high
- Attachment: HTML smuggling Microsoft sign in severity high
- Attachment: HTML smuggling with atob and high entropy severity high
- Attachment: HTML smuggling with atob and high entropy via calendar invite severity high
- Attachment: HTML smuggling with auto-downloaded file severity high
- Attachment: HTML smuggling with base64 encoded JavaScript function severity high
- Attachment: HTML smuggling with base64 encoded ZIP file severity medium
- Attachment: HTML smuggling with concatenation obfuscation severity high
- Attachment: HTML smuggling with decimal encoding severity high
- Attachment: HTML smuggling with embedded base64 streamed file download severity high
- Attachment: HTML smuggling with embedded base64-encoded executable severity high
- Attachment: HTML smuggling with embedded base64-encoded ISO severity high
- Attachment: HTML smuggling with eval and atob severity high
- Attachment: HTML smuggling with eval and atob via calendar invite severity high
- Attachment: HTML smuggling with excessive line break obfuscation severity high
- Attachment: HTML smuggling with excessive string concatenation and suspicious patterns severity medium
- Attachment: HTML smuggling with fromCharCode and other signals severity high
- Attachment: HTML smuggling with hex strings severity medium
- Attachment: HTML smuggling with high entropy and other signals severity high
- Attachment: HTML smuggling with raw array buffer severity high
- Attachment: HTML smuggling with RC4 decryption severity high
- Attachment: HTML smuggling with ROT13 severity high
- Attachment: HTML smuggling with setTimeout severity high
- Attachment: HTML smuggling with unescape severity high
- Attachment: HTML with emoji-to-character map severity high
- Attachment: HTML with hidden body severity high
- Attachment: HTML with JavaScript functions for HTTP requests severity high
- Attachment: HTML with obfuscation and recipient's email in JavaScript strings severity high
- Attachment: ICS calendar file with base64 encoded recipient address in URL parameters severity high
- Attachment: ICS calendar file with QR code containing recipient email address severity high
- Attachment: ICS calendar file with recipient address in UID field severity high
- Attachment: ICS calendar file with suspicious product identifier severity medium
- Attachment: ICS calendar file with suspicious UID domain severity medium
- Attachment: ICS calendar with embedded file from internal sender with SPF failure severity high
- Attachment: ICS file with AWS Lambda URL severity medium
- Attachment: ICS file with excessive custom properties severity medium
- Attachment: ICS file with links to newly registered domains severity medium
- Attachment: ICS file with meeting prefix severity high
- Attachment: ICS file with non-Gregorian calendar scale severity medium
- Attachment: ICS with embedded document severity low
- Attachment: ICS with embedded Javascript in SVG file severity high
- Attachment: ICS with employee policy review lure severity high
- Attachment: Identity Confirmation With Document Unlock Code severity medium
- Attachment: Invoice and W-9 PDFs with suspicious creators severity high
- Attachment: JavaScript file with suspicious base64-encoded executable severity high
- Attachment: JPEG with gd-jpeg creator and suspicious file name severity high
- Attachment: Legal themed message or PDF with suspicious indicators severity medium
- Attachment: Link file with UNC path severity medium
- Attachment: Link to Doubleclick.net open redirect severity medium
- Attachment: LNK file severity high
- Attachment: LNK with embedded content severity high
- Attachment: Macro files containing MHT content severity medium
- Attachment: Macro with suspected use of COM ShellBrowserWindow object for process creation severity high
- Attachment: Malformed OLE file severity high
- Attachment: Malicious OneNote commands severity high
- Attachment: Malicious zip file matching zipline campaign severity medium
- Attachment: Microsoft 365 credential phishing severity high
- Attachment: Microsoft impersonation via PDF with link and suspicious language severity high
- Attachment: Microsoft OAuth credential harvesting via EML with embedded malicious links severity high
- Attachment: Microsoft SharePoint Impersonation via images in macro-enabled attachment severity high
- Attachment: MS Office or RTF file with Shell.Explorer.1 com object with embedded LNK severity medium
- Attachment: MS OOXML file created by Administrator with zero edit time severity high
- Attachment: MSI installer file severity medium
- Attachment: Office document loads remote document template severity medium
- Attachment: Office document with VSTO add-in severity high
- Attachment: Office file contains OLE relationship to credential phishing page severity high
- Attachment: Office file with credential phishing URLs severity medium
- Attachment: Office file with document sharing and browser instruction lures severity high
- Attachment: Office file with suspicious function calls or downloaded file path severity high
- Attachment: OLE external relationship containing file scheme link to executable filetype severity high
- Attachment: OLE external relationship containing file scheme link to IP address severity high
- Attachment: Password-protected PDF with fake document indicators severity medium
- Attachment: PDF Attachment with links to workers.dev severity medium
- Attachment: PDF bid/proposal lure with credential theft indicators severity medium
- Attachment: PDF contains W9 or invoice YARA signatures severity medium
- Attachment: PDF file with link to fake Bitcoin exchange severity low
- Attachment: PDF file with low reputation link to ZIP file (unsolicited) severity medium
- Attachment: PDF file with low reputation links to suspicious filetypes (unsolicited) severity medium
- Attachment: PDF file with recipient domain and ATT eCheckRun pattern severity medium
- Attachment: PDF generated with wkhtmltopdf tool and default title severity low
- Attachment: PDF Object Hash - Encrypted PDFs with fake payment notification severity medium
- Attachment: PDF Object Hash associated with a fake invoice and a W-9 severity high
- Attachment: PDF Object Hash associated with fake Canada Revenue Agency documents severity medium
- Attachment: PDF Object Hash with Blue File Icon severity medium
- Attachment: PDF proposal with credential theft indicators severity high
- Attachment: PDF with a suspicious string and single URL severity high
- Attachment: PDF with base64 JavaScript and eval functions severity medium
- Attachment: PDF with blurry lure image severity medium
- Attachment: PDF with credential theft language and invalid reply-to domain severity medium
- Attachment: PDF with credential theft language and link to a free subdomain (unsolicited) severity medium
- Attachment: PDF with CVE-2026-34621 lures severity high
- Attachment: PDF with eCheckRun lures severity medium
- Attachment: PDF with fake invoice using suspicious font sizing severity medium
- Attachment: PDF with JSFck obfuscation severity high
- Attachment: PDF with link to DMG file download severity medium
- Attachment: PDF with link to zip containing a wsf file severity high
- Attachment: PDF with localhost IP in EXIF title metadata severity medium
- Attachment: PDF with Microsoft Purview message impersonation severity medium
- Attachment: PDF with multistage landing - ClickUp abuse severity high
- Attachment: PDF with password in filename matching body text severity medium
- Attachment: PDF with personal Microsoft OneNote URL severity medium
- Attachment: PDF with QR code containing recipient-specific credential theft content severity high
- Attachment: PDF with quote lure severity medium
- Attachment: PDF with recipient email in link severity high
- Attachment: PDF with ReportLab library and default metadata severity low
- Attachment: PDF With SAI Global ISO9001 Logo severity high
- Attachment: PDF with secure document acknowledgment prompt severity medium
- Attachment: PDF with self-service platform links with self sender or blank recipients severity medium
- Attachment: PDF with specific author metadata severity high
- Attachment: PDF with specific W-9 lure severity medium
- Attachment: PDF with split QR code severity medium
- Attachment: PDF with suspicious document view lure severity medium
- Attachment: PDF with suspicious HeadlessChrome metadata severity medium
- Attachment: PDF with suspicious internal object reference identifier severity medium
- Attachment: PDF with suspicious language and redirect to suspicious file type severity high
- Attachment: PDF with suspicious link and action-oriented language severity high
- Attachment: PDF with suspicious view document characteristics severity medium
- Attachment: PDF with W-9 form indicators severity high
- Attachment: Potential sandbox evasion in Office file severity high
- Attachment: PowerPoint with suspicious hyperlink severity high
- Attachment: PowerShell content severity high
- Attachment: QR code link with base64-encoded recipient address severity high
- Attachment: QR code with credential phishing indicators severity medium
- Attachment: QR code with encoded recipient targeting and redirect indicators severity high
- Attachment: QR code with recipient targeting and special characters severity high
- Attachment: QR code with suspicious URL patterns in EML file severity high
- Attachment: QR code with userinfo portion severity high
- Attachment: RDP connection file severity medium
- Attachment: RFC822 containing suspicious file sharing language with links from untrusted sender severity medium
- Attachment: RFP/RFQ impersonating government entities severity high
- Attachment: Romance scam with image lure and advance-fee or suspicious link indicators severity medium
- Attachment: RTF file with suspicious link severity medium
- Attachment: RTF with embedded content severity medium
- Attachment: RTF with link to free-hosted Cloudflare Pages severity high
- Attachment: Self-sender PDF with minimal content and view prompt severity high
- Attachment: SFX archive containing commands severity medium
- Attachment: Single-page PDF with S3-hosted HTML link severity medium
- Attachment: Small text file with link containing recipient email address severity medium
- Attachment: Soda PDF producer with encryption themes severity high
- Attachment: Suspicious employee policy update document lure severity medium
- Attachment: Suspicious PDF created with headless browser severity high
- Attachment: SVG file execution severity high
- Attachment: SVG file with HTML entity encoded href attributes severity medium
- Attachment: SVG file with hyperlinks and cursor styling severity medium
- Attachment: SVG files with evasion elements severity high
- Attachment: TAR file with RAR type severity high
- Attachment: Targeted DOCX with personalized recipient acknowledgement lure severity medium
- Attachment: Uncommon compressed file severity low
- Attachment: USDA bid invitation impersonation severity medium
- Attachment: Web files with suspicious comments severity high
- Attachment: WinRAR CVE-2025-8088 exploitation severity high
- Attachment: XLSX file with suspicious print titles metadata severity high
- Attachment: Zip exploiting CVE-2023-38831 (unsolicited) severity critical
- BEC with unusual reply-to or return-path mismatch severity high
- BEC/Fraud: Fake investment outreach from suspicious TLD severity medium
- BEC/Fraud: Generic scam attempt to undisclosed recipients severity low
- BEC/Fraud: Job scam fake thread or plaintext pivot to freemail severity medium
- BEC/Fraud: Penpal scam severity medium
- BEC/Fraud: Reply-chain manipulation with urgent keywords and self-reply severity medium
- BEC/Fraud: Romance scam severity medium
- BEC/Fraud: Scam lure with freemail pivot severity low
- BEC/Fraud: Student loan callback phishing severity medium
- BEC/Fraud: Unsolicited business acquisition offer severity medium
- BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns severity medium
- BEC: Employee impersonation with subject manipulation severity high
- BEC: Executive coaching vendor impersonation severity medium
- BEC: Financial fraud from newly registered sender domain severity medium
- BEC: Tax document request severity medium
- Benefits enrollment impersonation severity high
- beta.DLP: AWS Access Key severity high
- beta.DLP: Basic Auth Header severity high
- beta.DLP: Canadian Social Insurance Number (SIN) severity high
- beta.DLP: Crypto Wallet Address severity high
- beta.DLP: Date of Birth severity high
- beta.DLP: GitHub Token severity high
- beta.DLP: IBAN Code severity high
- beta.DLP: ICD-10 Code severity high
- beta.DLP: ICD-9 Code severity high
- beta.DLP: IP Address severity low
- beta.DLP: NHS Number severity high
- beta.DLP: OAuth Client Secret severity high
- beta.DLP: PCI US Credit Card Number (Any Network) severity high
- beta.DLP: Person Name severity medium
- beta.DLP: Phone Number severity low
- beta.DLP: Private Key severity high
- beta.DLP: SSL/TLS Certificate severity high
- beta.DLP: SWIFT/BIC Code severity high
- beta.DLP: UK Driver's License severity high
- beta.DLP: UK Electoral Roll severity high
- beta.DLP: UK National Insurance Number severity high
- beta.DLP: UK Passport severity high
- beta.DLP: UK UTR (Tax) severity high
- beta.DLP: US ABA Routing Number severity high
- beta.DLP: US Bank Account Number severity medium
- beta.DLP: US Driver's License severity high
- beta.DLP: US Individual Taxpayer Identification Number (ITIN) severity high
- beta.DLP: US Passport Number severity high
- beta.DLP: US Physical Address severity medium
- beta.DLP: US Social Security Number (SSN) severity high
- Body HTML: Comment with 24-character hex token severity low
- Body HTML: Recipient SLD in HTML class severity medium
- Body: CSS clamp() font obfuscation with IP-based links severity medium
- Body: CSS Hidden text via clip-path severity medium
- Body: CSS zero-value calc() obfuscation severity medium
- Body: Embedded email headers indicative of thread hijacking/abuse severity medium
- Body: Fake secure email portal with HTML obfuscation severity high
- Body: HTML whitespace stuffing with short initial message severity medium
- Body: Invisible Unicode obfuscation student loan callback phishing severity medium
- Body: PayApp transaction reference pattern severity medium
- Body: Suspicious date format severity medium
- Body: Suspicious table template fingerprint severity medium
- Body: Yellow highlighted text markers severity low
- Brand impersonation: AARP severity medium
- Brand impersonation: Adobe (QR code) severity high
- Brand impersonation: Adobe Acrobat Sign PDF phishing file format template severity high
- Brand impersonation: Adobe Sign with suspicious indicators severity high
- Brand impersonation: Adobe with suspicious language and link severity high
- Brand impersonation: ADP severity medium
- Brand impersonation: AliExpress severity medium
- Brand impersonation: Amazon severity low
- Brand impersonation: Amazon Web Services (AWS) severity medium
- Brand impersonation: Amazon with suspicious attachment severity medium
- Brand impersonation: American Express (AMEX) severity low
- Brand impersonation: Anthropic/Claude with newly registered domain severity medium
- Brand impersonation: Apple severity high
- Brand impersonation: Aquent severity medium
- Brand impersonation: Aramco severity medium
- Brand impersonation: AuthentiSign severity medium
- Brand impersonation: Automobile assistance associations severity high
- Brand impersonation: Bank of America severity high
- Brand impersonation: Barracuda Networks severity medium
- Brand impersonation: Bids & Tenders severity high
- Brand impersonation: Binance severity medium
- Brand impersonation: Blockchain.com severity medium
- Brand impersonation: Booking.com severity medium
- Brand impersonation: Box file sharing service severity medium
- Brand impersonation: Canada Revenue Agency severity medium
- Brand impersonation: Capital One severity high
- Brand impersonation: Charles Schwab severity medium
- Brand impersonation: Chase Bank severity high
- Brand impersonation: Chase bank with credential phishing indicators severity medium
- Brand impersonation: Cloud services with credential theft intent severity medium
- Brand impersonation: Coinbase severity high
- Brand impersonation: Coinbase with suspicious links severity medium
- Brand impersonation: Dashlane severity medium
- Brand impersonation: DHL severity low
- Brand impersonation: DigitalOcean severity high
- Brand impersonation: Discord notification severity medium
- Brand Impersonation: Disney severity medium
- Brand impersonation: DocSend severity high
- Brand impersonation: DocuSign severity high
- Brand impersonation: DocuSign (QR code) severity high
- Brand impersonation: DocuSign branded attachment lure with no DocuSign links severity high
- Brand impersonation: DocuSign PDF attachment with suspicious link severity high
- Brand impersonation: DocuSign with embedded QR code severity high
- Brand impersonation: DoorDash severity medium
- Brand impersonation: Dotloop severity medium
- Brand impersonation: Dropbox severity medium
- Brand impersonation: Enbridge severity medium
- Brand impersonation: Evite severity medium
- Brand impersonation: Exodus severity low
- Brand impersonation: Fake DocuSign HTML table not linking to DocuSign domains severity medium
- Brand impersonation: Fake Fax severity medium
- Brand impersonation: Fake procurement/RFQ PDF from energy and industrial companies severity high
- Brand impersonation: Fastway severity medium
- Brand impersonation: FedEx severity low
- Brand impersonation: Figma with malicious document access overlay severity high
- Brand impersonation: File sharing notification with template artifacts severity low
- Brand impersonation: FINRA severity medium
- Brand Impersonation: Gemini Trust Company severity medium
- Brand impersonation: Github severity high
- Brand impersonation: GitHub with callback scam indicators severity medium
- Brand impersonation: GoDaddy severity medium
- Brand Impersonation: Google (QR Code) severity high
- Brand impersonation: Google Careers severity high
- Brand impersonation: Google Drive fake file share severity medium
- Brand impersonation: Google fake sign-in warning severity high
- Brand impersonation: Google Meet with malicious link severity medium
- Brand impersonation: Google using Microsoft Forms severity high
- Brand impersonation: Google Workspace alert notification severity medium
- Brand impersonation: Government / Tax Authority document lure severity medium
- Brand impersonation: Greenvelope severity medium
- Brand impersonation: Gusto severity medium
- Brand impersonation: Hulu severity medium
- Brand impersonation: Interac severity medium
- Brand impersonation: Internal Revenue Service severity high
- Brand impersonation: KnowBe4 severity medium
- Brand impersonation: LastPass severity high
- Brand impersonation: Ledger severity low
- Brand impersonation: LinkedIn severity medium
- Brand impersonation: Mailchimp severity medium
- Brand impersonation: Mailgun severity medium
- Brand impersonation: Marriott with gift language severity medium
- Brand impersonation: McAfee severity medium
- Brand impersonation: Meta and subsidiaries severity medium
- Brand impersonation: MetaMask severity high
- Brand impersonation: Microsoft severity high
- Brand impersonation: Microsoft (QR code) severity high
- Brand impersonation: Microsoft fake sign-in alert severity medium
- Brand impersonation: Microsoft logo in HTML with fake quarantine release notification severity high
- Brand impersonation: Microsoft logo or suspicious language with open redirect severity high
- Brand impersonation: Microsoft Planner with suspicious link severity medium
- Brand impersonation: Microsoft quarantine release notification in body severity high
- Brand impersonation: Microsoft quarantine release notification in image attachment severity high
- Brand impersonation: Microsoft Teams severity high
- Brand impersonation: Microsoft Teams invitation severity high
- Brand impersonation: Microsoft with embedded logo and credential theft language severity high
- Brand impersonation: Microsoft with low reputation links severity medium
- Brand impersonation: Morgan Stanley severity medium
- Brand impersonation: Navan severity medium
- Brand impersonation: Netflix severity low
- Brand impersonation: Norton severity low
- Brand impersonation: Office 365 mail service severity medium
- Brand impersonation: Okta severity medium
- Brand Impersonation: OpenAI with ChatGPT Ads lure severity high
- Brand impersonation: OpenAI with payment issues severity high
- Brand impersonation: Outlook severity high
- Brand impersonation: Paperless Post severity high
- Brand Impersonation: PayPal severity medium
- Brand impersonation: PNC severity medium
- Brand Impersonation: Procore severity medium
- Brand impersonation: Proofpoint secure messaging without legitimate indicators severity high
- Brand impersonation: Punchbowl severity medium
- Brand impersonation: Purdue ePlanroom with suspicious links severity medium
- Brand impersonation: Quickbooks severity medium
- Brand impersonation: QuickBooks dispute notification severity high
- Brand impersonation: QuickBooks notification from Intuit themed company name severity medium
- Brand impersonation: Ripple severity low
- Brand impersonation: Robert Half severity medium
- Brand impersonation: Robinhood severity medium
- Brand impersonation: SendGrid severity medium
- Brand Impersonation: ShareFile severity medium
- Brand impersonation: Sharepoint severity high
- Brand impersonation: Sharepoint fake file share severity medium
- Brand impersonation: SharePoint PDF attachment with credential theft language severity medium
- Brand Impersonation: Shein severity medium
- Brand impersonation: Silicon Valley Bank severity medium
- Brand impersonation: SiriusXM severity medium
- Brand impersonation: Social Security Administration severity medium
- Brand impersonation: SoFi severity medium
- Brand impersonation: Spotify severity low
- Brand impersonation: Square severity medium
- Brand impersonation: Squarespace severity medium
- Brand impersonation: State Farm severity medium
- Brand impersonation: Stellar Development Foundation (SDF) severity low
- Brand Impersonation: Stripe severity high
- Brand impersonation: Stripe notification severity medium
- Brand impersonation: Sublime Security severity high
- Brand impersonation: Survey request with credential theft indicators severity medium
- Brand impersonation: TikTok severity medium
- Brand impersonation: Toronto-Dominion Bank severity medium
- Brand impersonation: Trust Wallet severity high
- Brand impersonation: TurboTax severity low
- Brand impersonation: Twitter severity medium
- Brand impersonation: UK government Home Office severity high
- Brand impersonation: ukr[.]net severity medium
- Brand impersonation: United Healthcare severity medium
- Brand impersonation: UPS severity low
- Brand impersonation: USPS severity high
- Brand impersonation: Vanguard severity medium
- Brand impersonation: Vanta severity low
- Brand impersonation: Venmo severity medium
- Brand impersonation: Wells Fargo severity high
- Brand impersonation: WeTransfer severity high
- Brand impersonation: Wise severity high
- Brand impersonation: Wix severity medium
- Brand impersonation: Xodo Sign severity medium
- Brand impersonation: Zoom severity medium
- Brand impersonation: Zoom (strict) severity medium
- Brand impersonation: Zoom via HTML styling severity medium
- Brand impersonation: Zoom via lookalike domain severity high
- Brand impersonation: Zoom with deceptive link display severity medium
- Brand spoof: Dropbox severity medium
- Business Email Compromise (BEC) attempt from unsolicited sender severity medium
- Business Email Compromise (BEC) attempt from untrusted sender severity medium
- Business Email Compromise (BEC) attempt from untrusted sender (French/Français) severity medium
- Business Email Compromise (BEC) attempt with masked recipients and reply-to mismatch (unsolicited) severity medium
- Business Email Compromise (BEC) with request for mobile number severity medium
- Business Email Compromise: Request for mobile number via reply thread hijacking severity medium
- Callback phishing in body or attachment (untrusted sender) severity medium
- Callback phishing solicitation in message body severity medium
- Callback phishing via Adobe Sign comment severity high
- Callback phishing via Apple ID display name abuse severity high
- Callback phishing via calendar invite severity medium
- Callback phishing via DocuSign comment severity high
- Callback phishing via e-signature service severity high
- Callback phishing via extensionless rfc822 attachment severity high
- Callback phishing via Google Group abuse severity high
- Callback phishing via Google Meet severity medium
- Callback phishing via Intuit service abuse severity medium
- Callback phishing via Microsoft comment severity medium
- Callback Phishing via Signable E-Signature Request severity high
- Callback phishing via SignFree e-signature request severity high
- Callback phishing via Xodo Sign comment severity high
- Callback phishing via Yammer comment severity medium
- Callback phishing via Zelle Service Abuse severity medium
- Callback phishing via Zoho service abuse severity medium
- Callback Phishing via Zoom comment severity medium
- Callback phishing: AOL senders with suspicious HTML template or PDF attachment severity high
- Callback phishing: Branded invoice from sender/reply-to domain less than 30 days old severity medium
- Callback phishing: Social Security Administration fraud severity medium
- Callback phishing: SumUp infrastructure abuse severity high
- Callback phishing: Zero-width character obfuscation from freemail sender severity medium
- Callback scam: Impersonation via TimeTrade infrastructure severity medium
- Canva design with suspicious embedded link severity high
- Canva infrastructure abuse severity medium
- Catbox.moe link from untrusted source severity medium
- ClickFunnels link infrastructure abuse severity high
- Cloud storage impersonation with credential theft indicators severity medium
- Commonly abused sender TLD with engaging language severity medium
- Compensation review with QR code in attached EML severity high
- Constant Contact link infrastructure abuse severity high
- COVID-19 themed fraud with sender and reply-to mismatch or compensation award severity medium
- Credential phishing content and link (untrusted sender) severity high
- Credential phishing language and suspicious indicators (unknown sender) severity medium
- Credential phishing link (unknown sender) severity high
- Credential Phishing via Dropbox comment abuse severity medium
- Credential phishing: 'Secure message' and engaging language severity medium
- Credential phishing: AWS Lambda URL with recipient targeting severity medium
- Credential phishing: Blue button styled link with file-sharing template artifacts severity low
- Credential phishing: DocuSign embedded image lure with no DocuSign domains in links severity high
- Credential phishing: Email delivery failure impersonation severity high
- Credential phishing: Engaging language and other indicators (untrusted sender) severity medium
- Credential phishing: Engaging language with IPFS link severity high
- Credential phishing: Fake card notification with tracking lure severity medium
- Credential phishing: Fake password expiration from new and unsolicited sender severity medium
- Credential phishing: Fake storage alerts (unsolicited) severity medium
- Credential phishing: Financial lure via ActiveCampaign infrastructure severity medium
- Credential phishing: Generic document share with unicode and proceedural greeting template severity low
- Credential phishing: Generic document sharing severity medium
- Credential phishing: Hyper-linked image leading to free file host severity medium
- Credential phishing: Image as content, short or no body contents severity medium
- Credential phishing: Onedrive impersonation severity high
- Credential phishing: Personalized document signing request severity medium
- Credential phishing: Re-Authentication lure severity high
- Credential phishing: Suspicious e-sign agreement document notification severity medium
- Credential Phishing: Suspicious language, link, recipients and other indicators severity medium
- Credential phishing: Suspicious subject with urgent financial request and link severity medium
- Credential phishing: Tax form impersonation with payment request severity medium
- Credential Phishing: W-2 lure with inline SVG Windows logo severity high
- Credential theft with 'safe content' deception and social engineering topics severity medium
- Credential theft: Gophish abuse with hidden tracking image severity high
- Credential theft: JavaScript date manipulation in HTML body severity medium
- CVE-2023-5631 - Roundcube Webmail XSS via crafted SVG severity critical
- Cyrillic vowel substitution in subject or display name from unknown sender severity medium
- Cyrillic vowel substitutions with suspicious subject from unknown sender severity medium
- Deceptive Dropbox mention severity medium
- Display name and subject impersonation using recipient SLD (new sender) severity medium
- Display Name Emoji with Financial Symbols severity low
- Display name impersonation using recipient SLD severity medium
- Disposable sender email (unsolicited) severity low
- DLP - Clear-Text Credentials Outbound severity critical
- DLP - Outbound to Personal Email Domains severity medium
- DLP - PCI: American Express Credit Card Number severity high
- DLP - PCI: Discover Credit Card Number severity high
- DLP - PCI: Mastercard Credit Card Number severity high
- DLP - PCI: US Credit Card Number (Any Network) severity high
- DLP - PCI: Visa Credit Card Number severity high
- DLP: Argentina DNI Number severity high
- DLP: Australia Bank Account Number severity medium
- DLP: Australia Credit Card Number severity high
- DLP: Australia Driver's License Number severity medium
- DLP: Australia Medical Account Number severity high
- DLP: Australia Passport Number severity high
- DLP: Australia SWIFT Code severity medium
- DLP: Australia Tax File Number severity medium
- DLP: Austria Identity Card severity high
- DLP: Austria Social Security Number severity high
- DLP: Austria Tax Identification Number severity medium
- DLP: AWS Credentials severity high
- DLP: Azure Authentication Token severity high
- DLP: Basic Authentication Header severity medium
- DLP: Belgium National Number severity high
- DLP: Brazil CPF Number severity high
- DLP: Brazil RG Number severity high
- DLP: Bulgaria Uniform Civil Number severity high
- DLP: Canada Bank Account Number severity medium
- DLP: Canada Credit Card Number severity high
- DLP: Canada Driver's License Number severity medium
- DLP: Canada Health Service Number severity high
- DLP: Canada Passport Number severity high
- DLP: Canada Personal Health Identification Number (PHIN) severity high
- DLP: Canada Social Insurance Number (SIN) severity high
- DLP: Chile Identity Card Number severity high
- DLP: China Resident ID Number severity high
- DLP: Colombia Citizenship Card Number severity high
- DLP: Croatia Personal Identification (OIB) severity high
- DLP: Cyprus Identity Card severity high
- DLP: Czech Personal Identity Number severity high
- DLP: Denmark Personal Identification Number severity high
- DLP: Estonia Personal Identification Code severity high
- DLP: EU Debit Card Number severity high
- DLP: Finland National ID severity high
- DLP: France Bank Account Number severity medium
- DLP: France Credit Card Number severity high
- DLP: France Debit Card Number severity high
- DLP: France Driver's License Number severity medium
- DLP: France National ID Card (CNI) severity high
- DLP: France Passport Number severity high
- DLP: France Social Security Number (INSEE) severity high
- DLP: France Tax Identification Number (SPI) severity medium
- DLP: GCP API Key severity high
- DLP: Germany Bank Account Number (IBAN) severity medium
- DLP: Germany Driver's License Number severity medium
- DLP: Germany Identity Card Number (Personalausweisnummer) severity high
- DLP: Germany Passport Number severity high
- DLP: Germany Tax Identification Number severity medium
- DLP: GitHub Token severity high
- DLP: Greece National ID Card severity high
- DLP: Greece Social Security Number (AMKA) severity high
- DLP: Greece Tax Identification Number severity medium
- DLP: Hungary Personal Identification Number severity high
- DLP: Hungary Social Security Number (TAJ) severity high
- DLP: Hungary Tax Identification Number severity medium
- DLP: IMEI Number severity medium
- DLP: IMSI Number severity medium
- DLP: India Aadhaar Number severity high
- DLP: India Bank Account Number severity medium
- DLP: India PAN Number severity high
- DLP: India Passport Number severity high
- DLP: IP Address severity low
- DLP: Ireland Personal Public Service (PPS) Number severity high
- DLP: Israel Bank Account Number severity medium
- DLP: Israel Credit Card Number severity high
- DLP: Israel National ID severity high
- DLP: Israel SWIFT Code severity medium
- DLP: Italy Fiscal Code severity high
- DLP: Japan Bank Account Number severity medium
- DLP: Japan Credit Card Number severity high
- DLP: Japan Driver's License Number severity medium
- DLP: Japan MyNumber ID severity high
- DLP: Japan Passport Number severity high
- DLP: Japan Social Insurance Number severity high
- DLP: JSON Web Token (JWT) severity medium
- DLP: Latvia Personal Code severity high
- DLP: Lithuania Personal Code severity high
- DLP: Luxembourg National ID (Natural Persons) severity high
- DLP: Luxembourg National ID (Non-Natural Persons) severity medium
- DLP: MAC Address severity low
- DLP: Malta Identity Card Number severity high
- DLP: Malta Tax ID Number severity medium
- DLP: Mexico CURP Number severity high
- DLP: Mexico Passport Number severity high
- DLP: Netherlands Citizen's Service (BSN) Number severity high
- DLP: Netherlands Tax Identification Number severity medium
- DLP: OAuth Client Secret severity high
- DLP: Poland Identity Card severity high
- DLP: Poland Tax Identification Number severity medium
- DLP: Portugal Citizen Card Number severity high
- DLP: Portugal Tax Identification Number severity medium
- DLP: Private Key severity high
- DLP: Romania Personal Numerical Code severity high
- DLP: Saudi Arabia IBAN severity medium
- DLP: Saudi Arabia National ID severity high
- DLP: Saudi Arabia SWIFT Code severity medium
- DLP: Slack Token severity high
- DLP: Slovakia Personal Number severity high
- DLP: Slovenia Tax Identification Number severity medium
- DLP: Slovenia Unique Master Citizen Number severity high
- DLP: South Korea Resident Registration Number (RRN) severity high
- DLP: Spain Bank Account Number severity medium
- DLP: Spain DNI/NIE severity high
- DLP: Spain Passport Number severity high
- DLP: Spain Social Security Number severity high
- DLP: Spain Tax Identification Number severity medium
- DLP: SSL Certificate severity medium
- DLP: Sweden National ID severity high
- DLP: Sweden Tax Identification Number severity medium
- DLP: Taiwan ID Number severity high
- DLP: Turkey ID Number severity high
- DLP: UK National Health Service Number severity high
- DLP: UK National Insurance Number (NINO) severity high
- DLP: UK Passport Number severity high
- DLP: UK SWIFT Code severity medium
- DLP: US Bank Account Number severity medium
- DLP: US Driver's License Number severity medium
- DLP: US ICD-10-CM Code severity medium
- DLP: US ICD-9-CM Code severity medium
- DLP: US Individual Taxpayer Identification Number (ITIN) severity high
- DLP: US Insurance Claim Number severity medium
- DLP: US Passport Number severity high
- DLP: US Social Security Number (SSN) severity high
- DLP: Vehicle Identification Number (VIN) severity medium
- DocuSign impersonation via CloudHQ links severity medium
- DocuSign impersonation via spoofed Intuit sender severity high
- Domain impersonation: Freemail reply-to local lookalike with financial request severity medium
- EML attachment with credential theft language (unknown sender) severity high
- Employee impersonation with urgent request (untrusted sender) severity medium
- Employee impersonation: Payroll fraud severity high
- Encrypted Microsoft Office files from untrusted sender severity medium
- Evasion: Hidden content divs from freemail sender severity medium
- Extortion / sextortion (untrusted sender) severity low
- Extortion / Sextortion - PDF attachment leveraging breach data from freemail sender severity high
- Extortion / sextortion in attachment from untrusted sender severity low
- Fake email quarantine notification severity high
- Fake message thread - Untrusted sender with a mismatched freemail reply-to address severity medium
- Fake message thread with a suspicious link and engaging language from an unknown sender severity medium
- Fake request for tax preparation severity high
- Fake scan-to-email message severity medium
- Fake shipping notification with link to free file hosting severity low
- Fake shipping notification with suspicious language severity medium
- Fake thread with suspicious indicators severity medium
- Fake voicemail notification (untrusted sender) severity medium
- Fake warning banner using confusable characters severity medium
- Fake Zoho Sign template abuse severity medium
- Fake Zoom meeting invite with suspicious link severity medium
- File sharing link from suspicious sender domain severity medium
- File sharing link with a suspicious subject severity medium
- Fraudulent e-commerce operators severity high
- Fraudulent order confirmation/shipping notification from Chinese sender domain severity medium
- Free email provider sender with mismatched provider reply-to severity medium
- Free subdomain link with credential theft indicators severity high
- Free subdomain link with login or captcha (untrusted sender) severity medium
- Fuzzy Attack Score: Advanced Graymail Detection severity medium
- Generic service abuse from newly registered domain severity high
- Google Accelerated Mobile Pages (AMP) abuse severity medium
- Google Drive abuse: Credential phishing link severity high
- Google Drive direct download link from unsolicited sender severity medium
- Google Notification alert link from non-Google sender severity medium
- Google presentation open redirect phishing severity medium
- Google services using g.co shortlinks severity medium
- Google share notification with suspicious comments severity high
- Hardbacon infrastructure abuse severity high
- Headers: Fake in-reply-to with wildcard sender and missing thread context severity high
- Headers: Invalid recipient domain with mismatched reply-to from new sender severity medium
- Headers: iOS/iPadOS mailer with invalid build number severity medium
- Headers: Outlook Express mailer severity medium
- Headers: risky-recover-production message ID severity low
- Headers: Self-sender using Microsoft CompAuth bypass with credential theft content severity high
- Headers: System account impersonation with empty sender address severity medium
- Headers: X-Source-Auth mismatch with mismatched reply-to domain severity high
- Headers: Zimbra mailer from a non-supported OS version severity medium
- Honorific greeting BEC attempt with sender and reply-to mismatch severity low
- HR impersonation via e-sign agreement comment severity high
- HTML content with print styling and credential theft language severity high
- HTML smuggling containing recipient email address severity medium
- HTML smuggling with atob in message body severity high
- HTML: Bidirectional (BIDI) HTML override with right to left obfuscation severity medium
- HTML: Template placeholders or recipient email in element class attributes severity high
- Image as content with a link to an open redirect severity high
- Impersonation using recipient domain (untrusted sender) severity medium
- Impersonation: Australian Federal Police with criminal case language severity high
- Impersonation: Chrome Web Store policy severity low
- Impersonation: Employee name in subject with suspicious sender severity medium
- Impersonation: Employee using fabricated identity in initial contact severity high
- Impersonation: Executive using numbered local part severity high
- Impersonation: Fake Gmail attachment severity high
- Impersonation: Fake product discount promotion severity medium
- Impersonation: Human Resources with link or attachment and engaging language severity medium
- Impersonation: Internal corporate services severity high
- Impersonation: IT Department mailbox storage alert severity medium
- Impersonation: Legal firm with copyright infringement notice severity medium
- Impersonation: Recipient organization in sender display name with credential theft image severity medium
- Impersonation: Salesforce fake campaign failure notification severity medium
- Impersonation: SAM/SBA federal registration severity high
- Impersonation: SharePoint reply header anomaly severity medium
- Impersonation: Suspected supplier impersonation with suspicious content severity high
- Inbound message from popular service via newly observed distribution list severity medium
- Inline image as message with attachment or link severity low
- Investor solicitation with organization targeting severity medium
- Invoicera infrastructure abuse severity medium
- Issuu document with suspicious embedded link severity high
- Job scam (unsolicited sender) severity low
- Job scam with specific salary pattern severity low
- Link abuse: Self-service creation platform link with suspicious recipient behavior severity high
- Link to a domain with punycode characters severity medium
- Link to auto-download of a suspicious file type (unsolicited) severity medium
- Link to auto-downloaded disk image in encrypted zip severity medium
- Link to auto-downloaded DMG in archive severity medium
- Link to auto-downloaded DMG in encrypted zip severity high
- Link to auto-downloaded file with Adobe branding severity high
- Link to auto-downloaded file with Google Drive branding severity high
- Link to Google Apps Script macro (unsolicited) severity medium
- Link to Google Apps Script macro via comment tagging severity medium
- Link: .onion From Unsolicited Sender severity low
- Link: .su domain link redirection from new sender domains severity high
- Link: /index.php enclosed in three asterisks severity medium
- Link: 9WOLF phishkit initial landing URI severity high
- Link: Abused Adobe Express severity high
- Link: Adobe share from unsolicited sender severity medium
- Link: Adobe share with suspicious indicators severity high
- Link: Apple App Store link to apps impersonating AI adveristing severity high
- Link: Apple App Store malicious ad manager themed apps from free email provider severity medium
- Link: Apple TestFlight from suspicious sender severity medium
- Link: Base64 encoded recipient address in URL fragment with hex subdomain severity high
- Link: Base64 encoded recipient address in URL fragment with subject hash severity low
- Link: BEC with newly registered domains and financial keywords severity medium
- Link: Blogspot hosting explicit romance content severity medium
- Link: Breely link masquerading as PDF severity high
- Link: chatbot.page platform abuse severity medium
- Link: Common hidden directory observed severity medium
- Link: Commonly Abused Web Service redirecting to ZIP file severity medium
- Link: Compromised WordPress site redirecting to suspicious root domain severity high
- Link: Concatenated display text concealing duplicate URLs with PDF reference severity medium
- Link: Credential harvesting with excess padding evasion severity low
- Link: Credential phishing link with undisclosed recipients severity medium
- Link: Credential phishing traversing Russian infrastructure severity high
- Link: Credential phishing via WordPress severity high
- Link: Credential theft with Cloudflare tunnel and recipient targeting severity high
- Link: Credential theft with invisible Unicode character in page title from unsolicited sender severity high
- Link: Cryptocurrency fraud with suspicious links severity high
- Link: CVE-2024-21413 Microsoft Outlook Remote Code Execution Vulnerability severity critical
- Link: Direct download of executable file severity low
- Link: Direct link to Dropbox Paper file severity low
- Link: Direct link to gamma.app document with mode parameter severity medium
- Link: Direct link to keap.app contact-us page severity medium
- Link: Direct link to limewire hosted file severity high
- Link: Direct link to riddle.com hosted showcase severity medium
- Link: Direct link to Zoom Docs from non-Zoom sender severity medium
- Link: Direct MSI download from low reputation domain severity low
- Link: Direct POWR.io Form Builder with suspicious patterns severity medium
- Link: Display text matches subject line severity medium
- Link: Display text with excessive right-to-left mark characters severity low
- Link: Document sharing invitation template severity high
- Link: Document-themed link to newly registered domain severity medium
- Link: Excessive URL rewrite encoders severity high
- Link: Executable file download with suspicious message content severity high
- Link: Fake forwarded message with suspicious URL in plain text severity medium
- Link: Fake secure message notification template severity medium
- Link: Figma design deck with credential theft language severity medium
- Link: File sharing impersonation with suspicious language and sending patterns severity medium
- Link: File sharing pretext with suspicious body and link severity medium
- Link: Financial account issue with suspicious indicators severity medium
- Link: Flagged bit.ly link severity medium
- Link: Flare-branded credential harvesting via Cloudflare tunnels severity high
- Link: Fraudulent state business filing notice severity medium
- Link: Free file host link with 'Important Viewing Note' lure severity medium
- Link: Free file host links from suspicious support sender with credential theft language severity medium
- Link: Free file hosting with undisclosed recipients severity medium
- Link: Free subdomain host with undisclosed recipients severity medium
- Link: Generic financial document with proceedural timeline template severity medium
- Link: Google Calendar invite linking to an open redirect from an untrusted freemail sender severity high
- Link: Google Cloud Storage hosted credential harvesting page severity high
- Link: Google Cloud Storage impersonating with googledrive in URL path severity high
- Link: Google Cloud Storage link with index.php in URL severity high
- Link: Google Cloud Storage link with redirect.html in URL severity high
- Link: Google Cloud Storage redirect to external domain severity medium
- Link: Google Cloud Storage with short-path link delivery severity medium
- Link: Google Cloud Storage with suspicious URL pattern severity high
- Link: Google Drawings link from new sender severity medium
- Link: Google Firebase dynamic link that redirects to new domain (<7 days old) severity low
- Link: Google Forms link with credential theft language severity medium
- Link: Google Translate (unsolicited) severity low
- Link: GoPhish query param values severity low
- Link: Hotel booking spoofed display URL severity medium
- Link: HR impersonation with suspicious domain indicators and credential theft severity high
- Link: HTML file with suspicious binary fragment ending pattern severity high
- Link: Intuit link abuse with file share context severity medium
- Link: Invalid reply-to with recipient details in subject, body, and encoded link severity medium
- Link: Invoice or receipt from freemail sender with customer service number severity low
- Link: IPFS severity medium
- Link: IPv4-mapped IPv6 address obfuscation severity medium
- Link: JavaScript obfuscation with Telegram bot integration severity high
- Link: Jensi file preview link from unsolicited sender severity medium
- Link: Job recruitment lure from unsolicited sender with suspicious hosting severity medium
- Link: Landing page with search-ms protocol redirect severity high
- Link: Mamba 2FA phishing kit severity high
- Link: Microsoft device code authentication with suspicious indicators severity high
- Link: Microsoft Dynamics 365 form phishing severity high
- Link: Microsoft impersonation using hosted png with suspicious link severity medium
- Link: Microsoft protected message with matching sender and recipient addresses severity medium
- Link: Mismatched free file host links with document lure severity medium
- Link: Mixed case HTTPS protocol severity medium
- Link: Multiple HTTP protocols in single URL severity medium
- Link: Multistage landing - Abused Adobe Acrobat hosted PDF severity medium
- Link: Multistage landing - Abused Adobe frame.io severity high
- Link: Multistage Landing - Abused Buildin.ai severity medium
- Link: Multistage landing - Abused Docusign severity high
- Link: Multistage landing - Abused Google Drive severity high
- Link: Multistage landing - ClickUp abuse severity high
- Link: Multistage landing - FreshDesk knowledge base abuse severity high
- Link: Multistage landing - JotForm abuse severity high
- Link: Multistage landing - Ludus presentation severity medium
- Link: Multistage landing - Microsoft Forms abuse severity high
- Link: Multistage landing - Published Google Doc severity high
- Link: Multistage landing - Scribd document severity medium
- Link: Multistage landing - Trello board abuse severity high
- Link: MyActiveCampaign Link Abuse severity medium
- Link: Non-standard port 8443 in display URL severity medium
- Link: Numeric IP obfuscation in URL severity medium
- Link: Obfuscation via userinfo with excessive URL padding severity medium
- Link: Obfuscation via userinfo with suspicious indicators severity low
- Link: Observed malicious URL path /redirect/redirect/ severity high
- Link: Observed URL pattern with specific domain registrar severity high
- Link: PDF and financial display text to free file host severity high
- Link: PDF display text with fake copyright claim template severity medium
- Link: PDF file disguised as HTML page severity medium
- Link: PDF filename impersonation with credential theft language severity medium
- Link: Personal SharePoint with invalid recipients and credential theft language severity medium
- Link: Personalized URL with recipient address on commonly abused web service severity medium
- Link: QR code in EML attachment with credential phishing indicators severity high
- Link: QR code with phishing disposition in img or pdf severity high
- Link: QR Code with suspicious language (untrusted sender) severity medium
- Link: QuickBooks image lure with suspicious link severity medium
- Link: Recipient domain in URL path severity high
- Link: Recipient email address in 'eta' parameter severity high
- Link: Referrer anonymization service from untrusted sender severity medium
- Link: Remittance payment request with timeline template severity medium
- Link: RFI document reference pattern in display text severity medium
- Link: Romance/Sexual Language With Suspicious Link severity low
- Link: ScreenConnect installer with suspicious relay domain severity high
- Link: ScreenConnect remote access tool delivery with unattended guest access severity high
- Link: Scribd fullscreen link from suspicious sender severity medium
- Link: Secure SharePoint file share from new or unusual sender severity low
- Link: Self-sender credential theft with configuration placeholder severity high
- Link: Self-sender with IP geolocation check and suspicious link behavior severity medium
- Link: Self-sender with sender org in subject and credential theft indicator severity high
- Link: Self-sent message with quarterly document review request severity critical
- Link: Self-sent PDF lure with subject correlation severity medium
- Link: SharePoint filename matches org name severity medium
- Link: SharePoint files shared from GoDaddy federated tenants severity low
- Link: SharePoint OneNote or PDF link with self sender behavior severity medium
- Link: Shortened URL with fragment matching subject severity medium
- Link: Single character path with credential theft body and self sender behavior or invalid recipient severity medium
- Link: Spam website with evasion indicators severity low
- Link: Squarespace infrastructure abuse severity medium
- Link: Suspicious Family fragment parameter with encoded recipient data severity high
- Link: Suspicious file retrieval with recipient targeting severity high
- Link: Suspicious go.php redirect with document lure severity medium
- Link: Suspicious HTML structure with subject mirrored in body and single link severity medium
- Link: Suspicious Loom HTML file path severity medium
- Link: Suspicious recipient with timeout redirect severity medium
- Link: Suspicious SharePoint document name severity low
- Link: Suspicious Sharepoint folder share severity high
- Link: Suspicious single-domain link with suspicious path and financial lure indicators severity medium
- Link: Suspicious URL path with binary character sequence severity medium
- Link: Suspicious URL with recipient targeting and special characters severity high
- Link: Suspicious wp-admin path from mismatched sender domain severity medium
- Link: SVG with embedded recipient data severity high
- Link: Tax document lure Portuguese/Spanish with suspicious domains severity medium
- Link: Tycoon2FA phishing kit (non-exhaustive) severity high
- Link: Uncommon SharePoint document type with sender's display name severity medium
- Link: Unformatted template with literal placeholder in mailto link severity medium
- Link: Unicode character obfuscation in display name with base64-encoded URL fragment severity medium
- Link: Unsolicited email contains link leading to Tycoon URL structure severity high
- Link: Unsolicited email contains link to page containing Tycoon URI structure severity high
- Link: URL fragment with hexadecimal pattern obfuscation severity high
- Link: URL fragmented by hidden spans severity high
- Link: URL path containing /moni/index severity high
- Link: URL redirecting to blob URL severity medium
- Link: URL scheme obfuscation via split HTML anchors severity high
- Link: URL shortener chaining to workers.dev redirect severity medium
- Link: URL shortener with copy-paste instructions and credential theft language severity low
- Link: URL using underscore-dot substitution in display text severity medium
- Link: Webflow link from unsolicited sender severity medium
- Link: WordPress admin targeting with recipient identifier in URL parts severity high
- Link: WordPress login page with Blogspot Binance scam severity medium
- Link: Zoho form link from unsolicited sender severity medium
- Lookalike sender domain (untrusted sender) severity high
- Low reputation link to auto-downloaded HTML file with smuggling indicators severity high
- macOS malware: Compiled AppleScript with document double-extension severity high
- Malware: Pikabot delivery via URL auto-download severity high
- MalwareBazaar: Malicious attachment hash (trusted reporters) severity high
- MalwareBazaar: Malicious attachment hash in archive (trusted reporters) severity high
- Mass campaign: Cross Site Scripting (XSS) attempt severity medium
- Mass campaign: recipient address in subject, body, and link (untrusted sender) severity medium
- Message content: Request for author engagement severity low
- Message traversed multiple onmicrosoft.com tenants severity medium
- Microsoft device code phishing severity medium
- Microsoft infrastructure abuse with suspicious patterns severity high
- Mismatched links: Free file share with urgent language severity medium
- New link domain (<=10d) from untrusted sender severity medium
- New sender domain (<=10d) from untrusted sender severity medium
- Newly registered sender or reply-to domain with newly registered linked domain severity medium
- Non-RFC compliant calendar files from unsolicited sender severity medium
- Notion suspicious file share severity medium
- Observed IOC: Mail transiting bulletproof host - SmartApe severity medium
- Observed IOC: Mail transiting OFAC-sanctioned bulletproof host Aeza Group severity high
- Observed IOC: Malicious sender domains severity high
- Observed IOC: Malicious sender email addresses severity high
- Observed IOC: Malicious sender root domains severity high
- Open redirect (go2.aspx) leading to Microsoft credential phishing severity medium
- Open redirect: adnxs.com severity medium
- Open redirect: agena-smile.com severity medium
- Open redirect: amaterasu-for-website-5.com severity medium
- Open redirect: api.spently.com severity medium
- Open redirect: Artisteer severity medium
- Open redirect: artkaderne severity medium
- Open Redirect: asemailmgmteu.com severity medium
- Open redirect: astroarts.co.jp severity medium
- Open redirect: Atdmt severity medium
- Open redirect: Avast severity medium
- Open redirect: bananaguide.com severity medium
- Open redirect: bangkoksync.com severity medium
- Open redirect: bestdeals.today severity medium
- Open redirect: Bitrix24 URL Path severity medium
- Open redirect: BMW USA severity medium
- Open redirect: bubblelife.com severity medium
- Open redirect: buildingengines.com severity medium
- Open redirect: business.google.com website_shared URL Param severity medium
- Open redirect: Cartoon Network severity medium
- Open redirect: chkc.com.hk severity medium
- Open redirect: City of Calgary severity medium
- Open redirect: Club-OS severity medium
- Open redirect: convertcart.com severity medium
- Open redirect: Dell severity medium
- Open redirect: designsori.com severity medium
- Open redirect: Diesel.az severity medium
- Open redirect: documentmailbox.com severity medium
- Open redirect: Doubleclick.net severity medium
- Open redirect: eaoko.org severity medium
- Open redirect: easycamp.com severity medium
- Open redirect: embluemail.com severity medium
- Open redirect: emlakarsa severity medium
- Open redirect: emp.eduyield.com severity medium
- Open redirect: eodcnetworkdirect.com severity medium
- Open redirect: events.csiro.au severity medium
- Open redirect: ExacTag severity medium
- Open redirect: fenc.com severity medium
- Open redirect: g7.fr severity medium
- Open redirect: giving.lluh.org severity medium
- Open redirect: Google Ad Services severity medium
- Open Redirect: Google domain with /url path and suspicious indicators severity medium
- Open redirect: Google Web Light severity medium
- Open redirect: Hakumonkai.org severity high
- Open redirect: HHS severity medium
- Open redirect: ijf.org severity medium
- Open redirect: Indeed severity medium
- Open redirect: IndiaTimes severity medium
- Open redirect: isadatalab.com severity medium
- Open redirect: JustPaste.it severity medium
- Open redirect: k-mil.net severity medium
- Open redirect: Klaviyo severity medium
- Open redirect: labcluster.com severity medium
- Open redirect: LearningApps severity medium
- Open redirect: Linkedin severity medium
- Open redirect: LinkedIn Redirect severity medium
- Open redirect: listing.ca severity medium
- Open redirect: magic4media.com severity medium
- Open redirect: magiccity.ne.jp severity medium
- Open redirect: magneticmarketing.com severity medium
- Open redirect: mail.spiceworks.com severity medium
- Open redirect: Mailtrack Korea severity medium
- Open redirect: marketing.edinburghairport.com severity medium
- Open redirect: McGill University severity low
- Open redirect: Medium severity medium
- Open redirect: Meta --> YouTube Redirection Chain severity medium
- Open redirect: mindmixer.com severity medium
- Open redirect: MSN severity medium
- Open redirect: museepicassoparis.fr severity medium
- Open redirect: Nested Doubleclick.net severity high
- Open redirect: Newegg severity medium
- Open redirect: next2.io severity medium
- Open redirect: nowlifestyle.com severity medium
- Open redirect: obunsha.co.jp severity medium
- Open redirect: Panera Bread severity medium
- Open redirect: people.anuneo.com severity medium
- Open redirect: phoenixartstudio.net severity medium
- Open redirect: PIRL San Diego severity medium
- Open redirect: plasticsurgery.or.kr severity medium
- Open redirect: pmifunds.com severity medium
- Open redirect: predictiveresponse.net severity medium
- Open redirect: PremierBet severity medium
- Open redirect: qrxtech.com severity medium
- Open redirect: queue.swytchbike.com severity medium
- Open redirect: radiopublic.com severity medium
- Open redirect: Recipient address embedded in redirect URL pointing to newly registered domain severity medium
- Open redirect: retailrocket.net severity medium
- Open redirect: ringaraja.net severity medium
- Open redirect: Samsung severity medium
- Open redirect: sciencebuddies.org severity medium
- Open redirect: secondstreetapp.com severity medium
- Open redirect: Shibboleth SSO Logout Return Parameter severity high
- Open redirect: shoppermeet.net severity medium
- Open redirect: shoppingwebapi.didatravel.com severity medium
- Open redirect: Signature Travel Network severity medium
- Open redirect: Slack severity low
- Open redirect: slubnaglowie.pl severity medium
- Open redirect: smartadserver.com severity medium
- Open redirect: smore.com severity medium
- Open redirect: Snapchat severity medium
- Open redirect: social.bigpress.net severity medium
- Open redirect: ssg-financial.com severity medium
- Open redirect: stats.lib.pdx.edu severity medium
- Open redirect: storematch.jp severity medium
- Open redirect: Ticketmaster severity low
- Open redirect: TikTok severity medium
- Open redirect: tkqlhce.com severity medium
- Open redirect: tuttocauzioni.it severity medium
- Open redirect: typedrawers.com severity medium
- Open redirect: U.S. Antarctic Program Data Center (USAP-DC) severity medium
- Open redirect: unitedwaynwvt.org severity medium
- Open redirect: ust.hk severity medium
- Open redirect: vconfex.com severity medium
- Open redirect: VK severity medium
- Open redirect: weblinkconnect.com severity medium
- Open redirect: whitefox.pl severity medium
- Open redirect: Xfinity CMP Redirection to Google AMP severity medium
- Open redirect: xfinity.com severity medium
- Open redirect: YouTube severity medium
- Open redirect: YouTube --> Google Redirection Chain severity medium
- Outlook hyperlink bypass: left-to-right mark (LRM) in base HTML tag severity medium
- PayPal invoice abuse severity medium
- PDF attachment with Google (AE) redirecting to a php or zip file severity high
- PhaaS: Impact Solutions (Impact Vector Suite) severity medium
- PHP Mailer with common phishing attachments severity medium
- Potential prompt injection attack in body HTML severity high
- Punycode sender domain severity high
- QR code to auto-download of a suspicious file type (unsolicited) severity high
- QR Code with suspicious indicators severity high
- Reconnaissance: All recipients cc/bcc'd or undisclosed severity low
- Reconnaissance: Email address harvesting attempt severity medium
- Reconnaissance: Empty message from uncommon sender severity low
- Reconnaissance: Empty subject with mismatched reply-to from new sender severity medium
- Reconnaissance: Fake real estate inquiry with empty body severity medium
- Reconnaissance: Hotel booking reply-to redirect severity medium
- Reconnaissance: Large unknown recipient list severity low
- Reconnaissance: Short generic greeting message severity medium
- Recruitee Infrastructure Abuse severity high
- Request for Quote or Purchase (RFQ|RFP) with HTML smuggling attachment severity high
- Request for Quote or Purchase (RFQ|RFP) with suspicious sender or recipient pattern severity medium
- Russia return-path TLD (untrusted sender) severity low
- Salesforce infrastructure abuse severity medium
- Scam soliciting employer review/rating severity low
- Self-impersonation: Sender matches recipient with bolded name and suspicious link severity medium
- Self-sender with copy/paste instructions and suspicious domains (French/Français) severity medium
- Self-sent fake PDF attachment with misleading link severity low
- Sender name contains Active Directory distinguished name severity medium
- Sender: IP address in local part severity medium
- Sendgrid onmicrosoft.com domain phishing severity medium
- Sendgrid voicemail phish severity high
- Service abuse: Adobe Creative Cloud share from an unsolicited sender address severity low
- Service abuse: Adobe legitimate domain with document approval language severity medium
- Service abuse: Adobe message from newly registered domain severity medium
- Service abuse: Adobe share containing newly observed email address domain severity high
- Service abuse: Adobe Sign notification from an unsolicited reply-to address severity medium
- Service abuse: Amazon invitation with suspected callback phishing severity medium
- Service abuse: Apple TestFlight with suspicious developer reference severity high
- Service abuse: AppSheet infrastructure with suspicious indicators severity medium
- Service abuse: AWS SNS callback scam impersonation severity medium
- Service abuse: Behance document sharing with suspicious language severity medium
- Service Abuse: Box file sharing with credential phishing intent severity medium
- Service abuse: Calendly callback scam detection severity medium
- Service abuse: Callback phishing via Microsoft Teams invite severity high
- Service abuse: Cisco secure email service with financial request severity high
- Service abuse: Citrix ShareFile impersonation via Outlook plugin severity medium
- Service abuse: Cognito Forms with short body from unknown sender severity medium
- Service abuse: Coursera callback scam severity high
- Service abuse: Demio notifications with suspicious content patterns severity medium
- Service abuse: DocSend share from an unsolicited reply-to address severity high
- Service abuse: DocSend share from newly registered domain severity high
- Service abuse: DocuSign notification with suspicious sender or document name severity medium
- Service abuse: DocuSign share from an unsolicited reply-to address severity medium
- Service abuse: Domains By Proxy sender severity medium
- Service abuse: Dropbox Paper with copy-paste instructions severity medium
- Service abuse: Dropbox share from an unsolicited reply-to address severity medium
- Service abuse: Dropbox share from new domain severity medium
- Service abuse: Dropbox share with suspicious sender or document name severity medium
- Service abuse: Elastic alerts extortion severity medium
- Service abuse: Evernote link severity low
- Service Abuse: ExactTarget with suspicious sender indicators severity high
- Service abuse: Facebook business with action required subject severity medium
- Service abuse: Facebook mail notification callback scam severity medium
- Service abuse: Fake loan/funding verification lure via Mailgun severity medium
- Service abuse: File sharing impersonation with external SharePoint links severity medium
- Service abuse: FileMail callback scam severity medium
- Service abuse: FlipHTML5 with attachment deception and credential theft language severity medium
- Service abuse: Formester with suspicious link behavior severity medium
- Service abuse: Free provider with SendGrid routing severity medium
- Service abuse: GetAccept callback scam content severity medium
- Service abuse: GitHub notification with excessive mentions and suspicious links severity high
- Service Abuse: GoDaddy infrastructure severity medium
- Service abuse: Google account notification with links to free file host severity high
- Service abuse: Google application integration redirecting to suspicious hosts severity medium
- Service abuse: Google Calendar notification with callback scam language severity medium
- Service abuse: Google classroom solicitation severity medium
- Service abuse: Google Drive share from an unsolicited reply-to address severity medium
- Service abuse: Google Drive share from new reply-to domain severity medium
- Service abuse: Google Firebase sender address with suspicious content severity low
- Service abuse: Google Groups callback scam severity medium
- Service abuse: Google OAuth with suspicious redirect destination severity medium
- Service abuse: Google Tag Manager debug cookie clearing with open redirect potential severity high
- Service abuse: HelloSign from an unsolicited sender address severity low
- Service Abuse: HelloSign share with suspicious sender or document name severity medium
- Service abuse: HungerRush domain with SendGrid tracking targeting ProtonMail severity high
- Service abuse: IBM IAM account notification with callback scam indicators severity medium
- Service abuse: Linode Objects HTML file hosting severity medium
- Service abuse: Meetup.com redirect with brand impersonation severity medium
- Service abuse: Microsoft Forms Pro with suspicious links or QR codes severity medium
- Service abuse: Microsoft Power Apps callback scam severity medium
- Service abuse: Microsoft Power Automate callback scam impersonation severity medium
- Service abuse: Microsoft Power BI callback scam severity medium
- Service abuse: Microsoft with suspicious indicators in subject severity medium
- Service abuse: Mimecast URL with excessive path length severity high
- Service abuse: Monday.com callback scam severity medium
- Service abuse: Monday.com infrastructure with phishing intent severity high
- Service abuse: MongoDB Atlas callback scam severity medium
- Service Abuse: Nifty.com with impersonation severity medium
- Service abuse: Notion free-tier account impersonating VIP severity medium
- Service abuse: Nylas tracking subdomain with suspicious content severity medium
- Service abuse: Oracle Cloud Workflow callback scam severity medium
- Service abuse: Outlook Groups with Google Sites link and evasion tag severity medium
- Service abuse: Payoneer callback scam severity medium
- Service abuse: PayPal manager account creation with callback scam indicators severity medium
- Service abuse: Postman reply-to mismatch with credential theft intent severity medium
- Service abuse: QuickBooks notification from new domain severity medium
- Service abuse: QuickBooks notification with suspicious comments severity medium
- Service abuse: Recruiting with suspicious language patterns from legitimate platforms severity medium
- Service abuse: Roomsy with unrelated body content severity medium
- Service abuse: Sendgrid credential theft with personalized request targeting single recipient severity medium
- Service abuse: SendGrid impersonation via Sendgrid from new sender severity high
- Service abuse: SendGrid-formatted link with actor-controlled fragment severity high
- Service abuse: SendThisFile with credential theft and financial language severity medium
- Service abuse: Settime.io sender with callback scam intent severity medium
- Service abuse: Soundestlink redirect with suspicious indicators severity medium
- Service abuse: Soundestlink.com Microsoft impersonation severity medium
- Service abuse: Square marketing with suspicious QR code severity high
- Service abuse: Substack credential theft with confusable characters and branded button redirects severity medium
- Service abuse: SurveyMonkey survey from newly registered domain severity high
- Service abuse: SurveyMonkey with suspicious outbound links severity medium
- Service abuse: Suspicious Datadog alert severity high
- Service abuse: Suspicious Zoom Docs link severity low
- Service abuse: Task management message sent via SendGrid severity medium
- Service abuse: Trello board invitation with VIP impersonation severity medium
- Service abuse: Vimeo with external plain-text links in message severity high
- Service abuse: WeTransfer callback scam severity medium
- Service abuse: Wix redirect through bulk mailer domains severity low
- Service abuse: Wufoo credential theft severity medium
- Service abuse: Zohodesk reply-to mismatch with job scam indicators severity medium
- Service abuse: Zoom Clips with unregistered reply-to domain severity low
- Service Abuse: Zoom with freemail reply-to and recipient address in greeting severity medium
- Service abuse: Zoom with newly registered reply-to domain severity medium
- Sharepoint file share with suspicious recipients pattern severity medium
- Sharepoint link likely unrelated to sender severity medium
- Sharepoint online with external recipients and external display name severity medium
- SharePoint OTP for filename matching org name severity medium
- Spam/fraud: Predatory journal/research paper request severity medium
- Spam: Attendee list solicitation severity low
- Spam: BlackBaud infrastructure abuse severity medium
- Spam: Campaign with excessive display-text and keywords found severity low
- Spam: Campaign with excessive space/char obfuscation and free file hosted link severity low
- Spam: Cold outreach from Cloudflare-hosted newly registered domain severity low
- Spam: Commonly observed formatting of unauthorized free giveaways severity low
- Spam: Cryptocurrency airdrop/giveaway severity low
- Spam: Default Microsoft Exchange Online sender domain (onmicrosoft.com) severity low
- Spam: Fake dating profile notification severity low
- Spam: Fake photo share severity low
- Spam: Firebase password reset from suspicious sender severity low
- Spam: Ghostwriting services scam with manipulative language severity medium
- Spam: Item giveaway spam template severity low
- Spam: Large financial amount mention from newly registered sender domain severity medium
- Spam: Link to blob.core.windows.net from new domain (<30d) severity medium
- Spam: Mastercard promotional content with image-based body severity low
- Spam: New job cold outreach from unsolicited sender severity low
- Spam: New link domain (<=10d) and emojis severity medium
- Spam: Personalized subject and greetings via Salesforce Marketing Cloud severity low
- Spam: Sendersrv.com with financial communications and unsubscribe language severity medium
- Spam: Sexually explicit content with emoji in subject from freemail provider severity low
- Spam: Sexually explicit Google Drive share severity low
- Spam: Sexually explicit Google group invitation severity low
- Spam: Sexually explicit Looker Studio report severity low
- Spam: Single recipient duplicated in cc severity medium
- Spam: SMTP & Proxy Communications in Email Body severity medium
- Spam: Suspicious toll-free phone number severity low
- Spam: Unsolicited malformed PDF severity low
- Spam: Unsolicited WordPress account creation or password reset request severity low
- Spam: URL shortener with short body content and emojis severity low
- Spam: Website errors solicitation severity low
- SPF temp error severity medium
- Spoofable internal domain with suspicious signals severity medium
- Stripe invoice abuse severity medium
- Subject and sender display name contains matching long alphanumeric string severity low
- Subject: Suspicious bracketed reference severity high
- Suspected cross-site scripting (XSS) found in subject severity medium
- Suspected lookalike domain with suspicious language severity medium
- Suspected WordPress abuse with cross-site scripting (XSS) indicators severity high
- Suspicious attachment with unscannable Cloudflare link severity medium
- Suspicious attachment: Duplicate decoy PDF files severity medium
- Suspicious display name: Gmail sender with engaging language severity low
- Suspicious DocuSign share from new domain severity high
- Suspicious invoice reference with missing or image-only attachments severity high
- Suspicious link to Looker Studio (lookerstudio.google.com) from a new and unsolicited sender severity medium
- Suspicious Links to Cloudflare R2 and Edge Services severity medium
- Suspicious mailer received from Gmail servers severity low
- Suspicious message with unscannable Cloudflare link severity medium
- Suspicious message with unscannable Vercel link severity medium
- Suspicious newly registered reply-to domain with engaging financial or urgent language severity medium
- Suspicious Office 365 app authorization (OAuth) link severity high
- Suspicious recipient pattern and language with low reputation link to login severity medium
- Suspicious recipients pattern with NLU credential theft indicators severity medium
- Suspicious recipients pattern with no Compauth pass and suspicious content severity medium
- Suspicious request for financial information severity high
- Suspicious sender display name with long procedurally generated text blob severity medium
- Suspicious SharePoint file sharing severity medium
- Suspicious subject with long procedurally generated text blob severity medium
- Suspicious VBA macros from untrusted sender severity high
- Targeting: Specific AOL address severity medium
- Tax Form: W-8BEN solicitation severity medium
- Truth Social infrastructure abuse via link redirect severity medium
- Twitter infrastructure abuse via link shortener severity medium
- Unicode QR code severity medium
- URI protocol handler: search-ms severity high
- URL with Unicode U+2044 (⁄) or U+2215 (∕) characters severity low
- URLhaus: Malicious domain in message body or pdf attachment (trusted reporters) severity medium
- Vendor compromise: GovDelivery message with suspicious link severity high
- Vendor impersonation: Thread hijacking with typosquat domain severity high
- Venmo payment request abuse severity medium
- VIP / Executive impersonation (strict match, untrusted) severity high
- VIP / Executive impersonation in subject (untrusted) severity medium
- VIP Impersonation via Google Group relay with suspicious indicators severity high
- VIP impersonation with BEC language (near match, untrusted sender) severity medium
- VIP impersonation with charitable donation fraud severity high
- VIP impersonation with invoicing request severity high
- VIP impersonation with urgent request (strict match, untrusted sender) severity high
- VIP impersonation with w2 request with reply-to mismatch severity high
- VIP impersonation: Fabricated thread history with fake VIP recipients severity high
- VIP impersonation: Fake forwarded indicator with VIP recipient impersonation severity high
- VIP impersonation: Fake thread with display name match, email mismatch severity medium
- VIP impersonation: Fake thread with VIPs missing email metadata severity high
- VIP impersonation: Invoice fraud with mobile device sign-off severity high
- VIP impersonation: Payment handoff with VIP display name authored fake threads severity high
- VIP Impersonation: VIP handoff with fake forwarded invoice thread severity high
- VIP impersonation: VIP name within a delimited subject with fake previous threads severity high
- VIP impersonation: VIP payment redirect handoff via fake threads severity high
- VIP impersonation: VIP recipient of previous thread with HTML generator severity high
- VIP local_part impersonation from unsolicited sender severity high
- X (Twitter) impersonation with credential phishing motives severity medium
- Xero infrastructure abuse severity medium
- Xero invoice abuse severity medium
- Zoom Events newsletter abuse severity medium