Detection rule frameworks
Secondary groupings alongside the primary Enterprise ATT&CK browse: MITRE ATT&CK Mobile and ICS, MITRE ATLAS, the Sublime email-threat taxonomy, and other detection categories.
MITRE ATT&CK
Initial Access
Drive-By Compromise T1456 1 rule
- Kusto Dataverse - TI map URL to DataverseActivity available
Supply Chain Compromise T1474 2 rules
- Kusto Dataverse - TI map URL to DataverseActivity available
- Kusto Quokka - Malicious Results Detected available
Phishing T1660 1 rule
- Kusto Lookout - Critical Smishing and Phishing Alerts (v2) available
Execution
Command and Scripting Interpreter T1623 1 rule
- Kusto Quokka - Malicious Results Detected available
Persistence
Foreground Persistence T1541 1 rule
- Kusto Quokka - Malicious Results Detected available
Event Triggered Execution T1624 1 rule
- Kusto Quokka - Malicious Results Detected available
Hijack Execution Flow T1625 1 rule
- Kusto Quokka - Malicious Results Detected available
Privilege Escalation
Exploitation for Privilege Escalation T1404 1 rule
- Kusto Dataverse - Suspicious security role modifications available
Abuse Elevation Control Mechanism T1626 2 rules
- Kusto Dataverse - Suspicious security role modifications available
- Kusto Lookout - Critical Audit and Policy Changes (v2) available
Process Injection T1631 1 rule
- Kusto Quokka - Malicious Results Detected available
Defense Evasion
Obfuscated Files or Information T1406 1 rule
- Kusto Quokka - Malicious Results Detected available
Input Injection T1516 1 rule
- Kusto Quokka - Malicious Results Detected available
Foreground Persistence T1541 1 rule
- Kusto Quokka - Malicious Results Detected available
Hooking T1617 1 rule
- Kusto Quokka - Malicious Results Detected available
Execution Guardrails T1627 1 rule
- Kusto Quokka - Malicious Results Detected available
Hide Artifacts T1628 1 rule
- Kusto Quokka - Malicious Results Detected available
Impair Defenses T1629 7 rules
- Kusto Dataverse - Guest user exfiltration following Power Platform defense impairment available
- Kusto Dataverse - Removal of blocked file extensions available
- Kusto Dataverse - Unusual sign-in following disabled IP address-based cookie binding protection available
- Kusto Lookout - Critical Audit and Policy Changes (v2) available
- Kusto Lookout - Device Compliance and Security Status Changes (v2) available
- Kusto Lookout - High Severity Mobile Threats Detected (v2) available
- Kusto Quokka - Malicious Results Detected available
Indicator Removal on Host T1630 2 rules
- Kusto Lookout - High Severity Mobile Threats Detected (v2) available
- Kusto Quokka - Malicious Results Detected available
Process Injection T1631 1 rule
- Kusto Quokka - Malicious Results Detected available
Virtualization/Sandbox Evasion T1633 1 rule
- Kusto Quokka - Malicious Results Detected available
Masquerading T1655 1 rule
- Kusto Lookout - Device Compliance and Security Status Changes (v2) available
Credential Access
Clipboard Data T1414 1 rule
- Kusto Quokka - Malicious Results Detected available
Input Capture T1417 2 rules
- Kusto Lookout - Critical Smishing and Phishing Alerts (v2) available
- Kusto Quokka - Malicious Results Detected available
Access Notifications T1517 1 rule
- Kusto Quokka - Malicious Results Detected available
Credentials from Password Store T1634 1 rule
- Kusto Quokka - Malicious Results Detected available
Steal Application Access Token T1635 2 rules
- Kusto Dataverse - New Dataverse application user activity type available
- Kusto Quokka - Malicious Results Detected available
Discovery
Software Discovery T1418 3 rules
- Kusto Lookout - Device Compliance and Security Status Changes (v2) available
- Kusto Lookout - High Severity Mobile Threats Detected (v2) available
- Kusto Quokka - Malicious Results Detected available
System Network Configuration Discovery T1422 1 rule
- Kusto Quokka - Malicious Results Detected available
Network Service Scanning T1423 1 rule
- Kusto Lookout - Critical Smishing and Phishing Alerts (v2) available
Process Discovery T1424 2 rules
- Kusto Lookout - High Severity Mobile Threats Detected (v2) available
- Kusto Quokka - Malicious Results Detected available
Location Tracking T1430 1 rule
- Kusto Quokka - Malicious Results Detected available
Lateral Movement
Exploitation of Remote Services T1428 1 rule
- Kusto Dataverse - TI map IP to DataverseActivity available
Collection
Stored Application Data T1409 1 rule
- Kusto Quokka - Malicious Results Detected available
Clipboard Data T1414 1 rule
- Kusto Quokka - Malicious Results Detected available
Input Capture T1417 2 rules
- Kusto Lookout - Critical Smishing and Phishing Alerts (v2) available
- Kusto Quokka - Malicious Results Detected available
Audio Capture T1429 1 rule
- Kusto Quokka - Malicious Results Detected available
Location Tracking T1430 1 rule
- Kusto Quokka - Malicious Results Detected available
Video Capture T1512 1 rule
- Kusto Quokka - Malicious Results Detected available
Screen Capture T1513 1 rule
- Kusto Quokka - Malicious Results Detected available
Access Notifications T1517 1 rule
- Kusto Quokka - Malicious Results Detected available
Archive Collected Data T1532 1 rule
- Kusto Quokka - Malicious Results Detected available
Call Control T1616 1 rule
- Kusto Quokka - Malicious Results Detected available
Protected User Data T1636 1 rule
- Kusto Quokka - Malicious Results Detected available
Adversary-in-the-Middle T1638 1 rule
- Kusto Quokka - Malicious Results Detected available
Command and Control
Web Service T1481 1 rule
- Kusto Quokka - Malicious Results Detected available
Non-Standard Port T1509 1 rule
- Kusto Quokka - Malicious Results Detected available
Ingress Tool Transfer T1544 1 rule
- Kusto Quokka - Malicious Results Detected available
Call Control T1616 1 rule
- Kusto Quokka - Malicious Results Detected available
Exfiltration
Impact
Data Encrypted for Impact T1471 1 rule
- Kusto Quokka - Malicious Results Detected available
Input Injection T1516 1 rule
- Kusto Quokka - Malicious Results Detected available
SMS Control T1582 1 rule
- Kusto Quokka - Malicious Results Detected available
Call Control T1616 1 rule
- Kusto Quokka - Malicious Results Detected available
Account Access Removal T1640 1 rule
- Kusto Quokka - Malicious Results Detected available
Data Manipulation T1641 2 rules
- Kusto Dataverse - Mass record updates available
- Kusto Quokka - Malicious Results Detected available
Endpoint Denial of Service T1642 1 rule
- Kusto Quokka - Malicious Results Detected available
Generate Traffic from Victim T1643 1 rule
- Kusto Quokka - Malicious Results Detected available
MITRE ATT&CK
Initial Access
Exploit Public-Facing Application T0819 3 rules
- Kusto Dataverse - New user agent type that was not used before available
- Kusto Dataverse - TI map URL to DataverseActivity available
- Kusto Radiflow - Exploit Detected available
External Remote Services T0822 1 rule
- Kusto Radiflow - Unauthorized Internet Access available
Rogue Master T0848 1 rule
- Kusto Radiflow - New Activity Detected available
Supply Chain Compromise T0862 1 rule
- Kusto Dataverse - TI map URL to DataverseActivity available
Spearphishing Attachment T0865 5 rules
- Kusto Dataverse - TI map URL to DataverseActivity available
- Kusto Mimecast Secure Email Gateway - Attachment Protect available
- Kusto Mimecast Secure Email Gateway - Attachment Protect
- Kusto Mimecast Targeted Threat Protection - Attachment Protect available
- Kusto Mimecast Targeted Threat Protection - URL Protect available
Internet Accessible Device T0883 1 rule
- Kusto Radiflow - Unauthorized Internet Access available
Remote Services T0886 4 rules
- Kusto Dataverse - TI map IP to DataverseActivity available
- Kusto Internet Access (Microsoft Defender for IoT) available
- Kusto Radiflow - Policy Violation Detected available
- Kusto Unauthorized remote access to the network (Microsoft Defender for IoT) available
Execution
Native API T0834 1 rule
- Kusto Dataverse - Anomalous application user activity available
Scripting T0853 7 rules
- Kusto App Gateway WAF - XSS Detection available
- Kusto Application Gateway WAF - XSS Detection
- Kusto Egress Defend - Dangerous Attachment Detected available
- Kusto Egress Defend - Dangerous Link Click available
- Kusto Front Door Premium WAF - XSS Detection available
- Kusto KnowBe4 Defend - Dangerous Attachment Detected available
- Kusto KnowBe4 Defend - Dangerous Link Click available
Change Operating Mode T0858 4 rules
- Kusto PLC Stop Command (Microsoft Defender for IoT) available
- Kusto PLC unsecure key state (Microsoft Defender for IoT) available
- Kusto Radiflow - Policy Violation Detected available
- Kusto Radiflow - Unauthorized Command in Operational Device available
User Execution T0863 4 rules
- Kusto Dataverse - Executable uploaded to SharePoint document management site available
- Kusto Dataverse - TI map URL to DataverseActivity available
- Kusto Egress Defend - Dangerous Attachment Detected available
- Kusto KnowBe4 Defend - Dangerous Attachment Detected available
Execution through API T0871 5 rules
- Kusto Dataverse - Anomalous application user activity available
- Kusto Dataverse - New Dataverse application user activity type available
- Kusto External Fabric Module XFM1 is unhealthy
- Kusto Power Platform - Connector added to a sensitive environment available
- Kusto Pure Controller Failed
Persistence
Module Firmware T0839 1 rule
- Kusto Unauthorized PLC changes (Microsoft Defender for IoT) available
System Firmware T0857 2 rules
- Kusto Firmware Updates (Microsoft Defender for IoT) available
- Kusto Radiflow - Unauthorized Command in Operational Device available
Valid Accounts T0859 7 rules
- Kusto Dataverse - Anomalous application user activity available
- Kusto Dataverse - New non-interactive identity granted access available
- Kusto Dataverse - TI map IP to DataverseActivity available
- Kusto F&O - Bank account change following network alias reassignment available
- Kusto F&O - Non-interactive account mapped to self or sensitive privileged user available
- Kusto SAP BTP - User added to Cloud Identity Service privileged Administrators list available
- Kusto SAP BTP - User added to sensitive privileged role collection available
Project File Infection T0873 3 rules
- Kusto Dataverse - Executable uploaded to SharePoint document management site available
- Kusto Dataverse - TI map URL to DataverseActivity available
- Kusto SAP BTP - Malware detected in BAS dev space available
Modify Program T0889 1 rule
- Kusto Radiflow - Policy Violation Detected available
Privilege Escalation
Exploitation for Privilege Escalation T0890 4 rules
- Kusto App Gateway WAF - SQLi Detection available
- Kusto Application Gateway WAF - SQLi Detection
- Kusto Front Door Premium WAF - SQLi Detection available
- Kusto Radiflow - Exploit Detected available
Evasion
Rootkit T0851 1 rule
- Kusto Radiflow - Suspicious Malicious Activity Detected available
Change Operating Mode T0858 4 rules
- Kusto PLC Stop Command (Microsoft Defender for IoT) available
- Kusto PLC unsecure key state (Microsoft Defender for IoT) available
- Kusto Radiflow - Policy Violation Detected available
- Kusto Radiflow - Unauthorized Command in Operational Device available
Discovery
Network Connection Enumeration T0840 1 rule
- Kusto Radiflow - Network Scanning Detected available
Network Sniffing T0842 4 rules
- Kusto High bandwidth in the network (Microsoft Defender for IoT) available
- Kusto Multiple scans in the network (Microsoft Defender for IoT) available
- Kusto Unauthorized device in the network (Microsoft Defender for IoT) available
- Kusto Unauthorized DHCP configuration in the network (Microsoft Defender for IoT) available
Remote System Discovery T0846 1 rule
- Kusto Radiflow - Network Scanning Detected available
Remote System Information Discovery T0888 1 rule
- Kusto Radiflow - Network Scanning Detected available
Lateral Movement
Program Download T0843 2 rules
- Kusto Radiflow - Policy Violation Detected available
- Kusto Radiflow - Unauthorized Command in Operational Device available
Valid Accounts T0859 7 rules
- Kusto Dataverse - Anomalous application user activity available
- Kusto Dataverse - New non-interactive identity granted access available
- Kusto Dataverse - TI map IP to DataverseActivity available
- Kusto F&O - Bank account change following network alias reassignment available
- Kusto F&O - Non-interactive account mapped to self or sensitive privileged user available
- Kusto SAP BTP - User added to Cloud Identity Service privileged Administrators list available
- Kusto SAP BTP - User added to sensitive privileged role collection available
Remote Services T0886 4 rules
- Kusto Dataverse - TI map IP to DataverseActivity available
- Kusto Internet Access (Microsoft Defender for IoT) available
- Kusto Radiflow - Policy Violation Detected available
- Kusto Unauthorized remote access to the network (Microsoft Defender for IoT) available
Collection
Program Upload T0845 1 rule
- Kusto Radiflow - Policy Violation Detected available
Command and Control
Connection Proxy T0884 1 rule
- Sigma Network proxy configuration changed experimental
Commonly Used Port T0885 1 rule
Inhibit Response Function
Denial of Service T0814 1 rule
- Kusto Denial of Service (Microsoft Defender for IoT) available
Device Restart/Shutdown T0816 1 rule
- Kusto Radiflow - Unauthorized Command in Operational Device available
Rootkit T0851 1 rule
- Kusto Radiflow - Suspicious Malicious Activity Detected available
System Firmware T0857 2 rules
- Kusto Firmware Updates (Microsoft Defender for IoT) available
- Kusto Radiflow - Unauthorized Command in Operational Device available
Service Stop T0881 1 rule
- Kusto No traffic on Sensor Detected (Microsoft Defender for IoT) available
Impair Process Control
Brute Force I/O T0806 1 rule
- Kusto Excessive Login Attempts (Microsoft Defender for IoT) available
Modify Parameter T0836 1 rule
- Kusto Radiflow - Unauthorized Command in Operational Device available
Module Firmware T0839 1 rule
- Kusto Unauthorized PLC changes (Microsoft Defender for IoT) available
Unauthorized Command Message T0855 3 rules
- Kusto Illegal Function Codes for ICS traffic (Microsoft Defender for IoT) available
- Kusto Radiflow - Policy Violation Detected available
- Kusto Radiflow - Unauthorized Command in Operational Device available
Impact
Denial of Control T0813 3 rules
- Kusto Power Automate - Departing employee flow activity available
- Kusto SAP BTP - Mass user deletion in a sub account available
- Kusto SAP BTP - Mass user deletion in Cloud Identity Service available
Loss of Availability T0826 4 rules
- Kusto Power Apps - Multiple apps deleted available
- Kusto Power Automate - Departing employee flow activity available
- Kusto SAP BTP - Mass user deletion in a sub account available
- Kusto SAP BTP - Mass user deletion in Cloud Identity Service available
Loss of Control T0827 2 rules
- Kusto SAP BTP - Mass user deletion in a sub account available
- Kusto SAP BTP - Mass user deletion in Cloud Identity Service available
Loss of Productivity and Revenue T0828 2 rules
- Kusto F&O - Reverted bank account number modifications available
- Kusto Power Automate - Unusual bulk deletion of flow resources available
Manipulation of Control T0831 1 rule
- Kusto F&O - Reverted bank account number modifications available
Damage to Property T0879 1 rule
- Kusto Power Automate - Departing employee flow activity available
Theft of Operational Information T0882 2 rules
- Kusto Radiflow - Unauthorized Internet Access available
- Kusto Suspicious malware found in the network (Microsoft Defender for IoT) available
Initial Access
AI Supply Chain Compromise: Model AML.T0010.003 1 rule
- Elastic Ollama DNS Query to Untrusted Domain production
Evade AI Model AML.T0015 2 rules
- Elastic AWS Bedrock Detected Multiple Attempts to use Denied Models by a Single User production
- Elastic AWS Bedrock Detected Multiple Validation Exception Errors by a Single User production
AI Model Access
AI Model Inference API Access AML.T0040 1 rule
- Elastic Ollama API Accessed from External Network production
Full AI Model Access AML.T0044 2 rules
- Elastic Ollama API Accessed from External Network production
- Elastic Potential Azure OpenAI Model Theft production
Execution
LLM Prompt Injection AML.T0051 8 rules
- Elastic AWS Bedrock Guardrails Detected Multiple Policy Violations Within a Single Blocked Request production
- Elastic AWS Bedrock Guardrails Detected Multiple Violations by a Single User Over a Session production
- Elastic AWS Bedrock Invocations without Guardrails Detected by a Single User Over a Session production
- Splunk MCP Prompt Injection production
- Elastic Unusual High Confidence Content Filter Blocks Detected production
- Elastic Unusual High Denied Sensitive Information Policy Blocks Detected production
- Elastic Unusual High Denied Topic Blocks Detected production
- Elastic Unusual High Word Policy Blocks Detected production
AI Agent Tool Invocation AML.T0053 2 rules
- Elastic GenAI or MCP Server Child Process Execution production
- Elastic GenAI Process Compiling or Generating Executables production
Privilege Escalation
AI Agent Tool Invocation AML.T0053 2 rules
- Elastic GenAI or MCP Server Child Process Execution production
- Elastic GenAI Process Compiling or Generating Executables production
LLM Jailbreak AML.T0054 7 rules
- Elastic AWS Bedrock Guardrails Detected Multiple Policy Violations Within a Single Blocked Request production
- Elastic AWS Bedrock Guardrails Detected Multiple Violations by a Single User Over a Session production
- Elastic AWS Bedrock Invocations without Guardrails Detected by a Single User Over a Session production
- Elastic Unusual High Confidence Content Filter Blocks Detected production
- Elastic Unusual High Denied Sensitive Information Policy Blocks Detected production
- Elastic Unusual High Denied Topic Blocks Detected production
- Elastic Unusual High Word Policy Blocks Detected production
Defense Evasion
Evade AI Model AML.T0015 2 rules
- Elastic AWS Bedrock Detected Multiple Attempts to use Denied Models by a Single User production
- Elastic AWS Bedrock Detected Multiple Validation Exception Errors by a Single User production
LLM Jailbreak AML.T0054 7 rules
- Elastic AWS Bedrock Guardrails Detected Multiple Policy Violations Within a Single Blocked Request production
- Elastic AWS Bedrock Guardrails Detected Multiple Violations by a Single User Over a Session production
- Elastic AWS Bedrock Invocations without Guardrails Detected by a Single User Over a Session production
- Elastic Unusual High Confidence Content Filter Blocks Detected production
- Elastic Unusual High Denied Sensitive Information Policy Blocks Detected production
- Elastic Unusual High Denied Topic Blocks Detected production
- Elastic Unusual High Word Policy Blocks Detected production
Credential Access
Unsecured Credentials AML.T0055 1 rule
- Elastic GenAI Process Accessing Sensitive Files production
Collection
Data from AI Services AML.T0085 1 rule
- Elastic GenAI Process Accessing Sensitive Files production
Data from AI Services: AI Agent Tools AML.T0085.001 1 rule
- Elastic GenAI Process Accessing Sensitive Files production
Exfiltration
Exfiltration via AI Inference API AML.T0024 1 rule
- Elastic AWS Bedrock High-Frequency Single-Model Inference API Probing production
Exfiltration via AI Inference API: Infer Training Data Membership AML.T0024.000 1 rule
- Elastic AWS Bedrock High-Frequency Single-Model Inference API Probing production
Exfiltration via AI Agent Tool Invocation AML.T0086 3 rules
- Elastic GenAI Process Connection to Suspicious Top Level Domain production
- Elastic GenAI Process Connection to Unusual Domain production
- Elastic GenAI Process Performing Encoding/Chunking Prior to Network Activity production
Impact
Evade AI Model AML.T0015 2 rules
- Elastic AWS Bedrock Detected Multiple Attempts to use Denied Models by a Single User production
- Elastic AWS Bedrock Detected Multiple Validation Exception Errors by a Single User production
Denial of AI Service AML.T0029 1 rule
- Elastic Potential Denial of Azure OpenAI ML Service production
Cost Harvesting AML.T0034 2 rules
- Elastic AWS Bedrock Detected Multiple Attempts to use Denied Models by a Single User production
- Elastic AWS Bedrock Detected Multiple Validation Exception Errors by a Single User production
Credential Phishing
Credential Phishing 1 rule
- Sublime MQL Link: Tycoon2FA phishing kit (non-exhaustive)
Encryption 14 rules
- Sublime MQL Attachment: Encrypted PDF With Credential Harvesting Indicators
- Sublime MQL Attachment: Encrypted PDF with credential theft body
- Sublime MQL Attachment: Encrypted PDF with credential theft language in EML
- Sublime MQL Attachment: HTML smuggling with excessive line break obfuscation
- Sublime MQL Attachment: HTML smuggling with RC4 decryption
- Sublime MQL Attachment: HTML smuggling with ROT13
- Sublime MQL Attachment: Identity Confirmation With Document Unlock Code
- Sublime MQL Attachment: Password-protected PDF with fake document indicators
- Sublime MQL Attachment: PDF with password in filename matching body text
- Sublime MQL Attachment: PDF with recipient email in link
- Sublime MQL Encrypted Microsoft Office files from untrusted sender
- Sublime MQL Link: Base64 encoded recipient address in URL fragment with subject hash
- Sublime MQL Link: Excessive URL rewrite encoders
- Sublime MQL Link: Suspicious Family fragment parameter with encoded recipient data
Evasion 350 rules
- Sublime MQL Abuse: Cloudflare Workers Hosted EvilTokens Domain Structure
- Sublime MQL Attachment: Any HTML file within archive (unsolicited)
- Sublime MQL Attachment: Archive containing HTML file with file scheme link
- Sublime MQL Attachment: Calendar file with invisible Unicode characters
- Sublime MQL Attachment: DOCX with hyperlink targeting recipient address
- Sublime MQL Attachment: DOCX with malicious document template artifacts
- Sublime MQL Attachment: Double base64-encoded zip file in HTML smuggling attachment
- Sublime MQL Attachment: EML containing a base64 encoded script
- Sublime MQL Attachment: EML file contains HTML attachment with login portal indicators
- Sublime MQL Attachment: EML file with HTML attachment (unsolicited)
- Sublime MQL Attachment: EML file with IPFS links
- Sublime MQL Attachment: EML with embedded Javascript in SVG file
- Sublime MQL Attachment: EML with link to credential phishing page
- Sublime MQL Attachment: EML with QR code redirecting to Cloudflare challenges
- Sublime MQL Attachment: EML with SharePoint files shared from GoDaddy federated tenants
- Sublime MQL Attachment: EML with Sharepoint link likely unrelated to sender
- Sublime MQL Attachment: EML with suspicious indicators
- Sublime MQL Attachment: Encrypted PDF With Credential Harvesting Indicators
- Sublime MQL Attachment: Encrypted PDF with credential theft body
- Sublime MQL Attachment: Encrypted PDF with credential theft language in EML
- Sublime MQL Attachment: Excel file with suspicious template identifier
- Sublime MQL Attachment: Excel Web Query File (IQY)
- Sublime MQL Attachment: Fake attachment image lure
- Sublime MQL Attachment: Finance themed PDF with observed phishing template
- Sublime MQL Attachment: HTML attachment with Javascript location
- Sublime MQL Attachment: HTML file contains exclusively Javascript
- Sublime MQL Attachment: HTML file with excessive 'const' declarations and abnormally long timeouts
- Sublime MQL Attachment: HTML file with excessive padding and suspicious patterns
- Sublime MQL Attachment: HTML smuggling 'body onload' linking to suspicious destination
- Sublime MQL Attachment: HTML smuggling 'body onload' with high entropy and suspicious text
- Sublime MQL Attachment: HTML smuggling with atob and high entropy via calendar invite
- Sublime MQL Attachment: HTML smuggling with base64 encoded ZIP file
- Sublime MQL Attachment: HTML smuggling with concatenation obfuscation
- Sublime MQL Attachment: HTML smuggling with decimal encoding
- Sublime MQL Attachment: HTML smuggling with embedded base64-encoded ISO
- Sublime MQL Attachment: HTML smuggling with eval and atob
- Sublime MQL Attachment: HTML smuggling with eval and atob via calendar invite
- Sublime MQL Attachment: HTML smuggling with excessive line break obfuscation
- Sublime MQL Attachment: HTML smuggling with excessive string concatenation and suspicious patterns
- Sublime MQL Attachment: HTML smuggling with fromCharCode and other signals
- Sublime MQL Attachment: HTML smuggling with hex strings
- Sublime MQL Attachment: HTML smuggling with raw array buffer
- Sublime MQL Attachment: HTML smuggling with RC4 decryption
- Sublime MQL Attachment: HTML smuggling with ROT13
- Sublime MQL Attachment: HTML smuggling with setTimeout
- Sublime MQL Attachment: HTML smuggling with unescape
- Sublime MQL Attachment: HTML with emoji-to-character map
- Sublime MQL Attachment: HTML with hidden body
- Sublime MQL Attachment: HTML with JavaScript functions for HTTP requests
- Sublime MQL Attachment: ICS calendar file with base64 encoded recipient address in URL parameters
- Sublime MQL Attachment: ICS calendar file with QR code containing recipient email address
- Sublime MQL Attachment: ICS calendar file with suspicious product identifier
- Sublime MQL Attachment: ICS calendar with embedded file from internal sender with SPF failure
- Sublime MQL Attachment: ICS file with AWS Lambda URL
- Sublime MQL Attachment: ICS file with non-Gregorian calendar scale
- Sublime MQL Attachment: ICS with embedded Javascript in SVG file
- Sublime MQL Attachment: ICS with employee policy review lure
- Sublime MQL Attachment: JPEG with gd-jpeg creator and suspicious file name
- Sublime MQL Attachment: Legal themed message or PDF with suspicious indicators
- Sublime MQL Attachment: Link file with UNC path
- Sublime MQL Attachment: Link to Doubleclick.net open redirect
- Sublime MQL Attachment: Macro files containing MHT content
- Sublime MQL Attachment: Malformed OLE file
- Sublime MQL Attachment: Microsoft OAuth credential harvesting via EML with embedded malicious links
- Sublime MQL Attachment: Office file contains OLE relationship to credential phishing page
- Sublime MQL Attachment: Office file with credential phishing URLs
- Sublime MQL Attachment: Office file with document sharing and browser instruction lures
- Sublime MQL Attachment: Password-protected PDF with fake document indicators
- Sublime MQL Attachment: PDF Attachment with links to workers.dev
- Sublime MQL Attachment: PDF generated with wkhtmltopdf tool and default title
- Sublime MQL Attachment: PDF Object Hash associated with fake Canada Revenue Agency documents
- Sublime MQL Attachment: PDF proposal with credential theft indicators
- Sublime MQL Attachment: PDF with a suspicious string and single URL
- Sublime MQL Attachment: PDF with localhost IP in EXIF title metadata
- Sublime MQL Attachment: PDF with multistage landing - ClickUp abuse
- Sublime MQL Attachment: PDF with password in filename matching body text
- Sublime MQL Attachment: PDF with ReportLab library and default metadata
- Sublime MQL Attachment: PDF with secure document acknowledgment prompt
- Sublime MQL Attachment: PDF with self-service platform links with self sender or blank recipients
- Sublime MQL Attachment: PDF with split QR code
- Sublime MQL Attachment: PDF with suspicious HeadlessChrome metadata
- Sublime MQL Attachment: PDF with suspicious language and redirect to suspicious file type
- Sublime MQL Attachment: PDF with suspicious link and action-oriented language
- Sublime MQL Attachment: PDF with suspicious view document characteristics
- Sublime MQL Attachment: QR code link with base64-encoded recipient address
- Sublime MQL Attachment: QR code with encoded recipient targeting and redirect indicators
- Sublime MQL Attachment: QR code with recipient targeting and special characters
- Sublime MQL Attachment: QR code with suspicious URL patterns in EML file
- Sublime MQL Attachment: QR code with userinfo portion
- Sublime MQL Attachment: RFC822 containing suspicious file sharing language with links from untrusted sender
- Sublime MQL Attachment: RTF file with suspicious link
- Sublime MQL Attachment: Self-sender PDF with minimal content and view prompt
- Sublime MQL Attachment: Single-page PDF with S3-hosted HTML link
- Sublime MQL Attachment: Small text file with link containing recipient email address
- Sublime MQL Attachment: Suspicious employee policy update document lure
- Sublime MQL Attachment: Suspicious PDF created with headless browser
- Sublime MQL Attachment: SVG file with HTML entity encoded href attributes
- Sublime MQL Attachment: SVG file with hyperlinks and cursor styling
- Sublime MQL Attachment: SVG files with evasion elements
- Sublime MQL Attachment: Web files with suspicious comments
- Sublime MQL Attachment: XLSX file with suspicious print titles metadata
- Sublime MQL Benefits enrollment impersonation
- Sublime MQL Body HTML: Recipient SLD in HTML class
- Sublime MQL Body: CSS clamp() font obfuscation with IP-based links
- Sublime MQL Body: CSS Hidden text via clip-path
- Sublime MQL Body: CSS zero-value calc() obfuscation
- Sublime MQL Body: Embedded email headers indicative of thread hijacking/abuse
- Sublime MQL Body: Fake secure email portal with HTML obfuscation
- Sublime MQL Body: HTML whitespace stuffing with short initial message
- Sublime MQL Body: Invisible Unicode obfuscation student loan callback phishing
- Sublime MQL Body: Suspicious date format
- Sublime MQL Body: Suspicious table template fingerprint
- Sublime MQL Body: Yellow highlighted text markers
- Sublime MQL Brand impersonation: Coinbase with suspicious links
- Sublime MQL Brand impersonation: DocuSign with embedded QR code
- Sublime MQL Brand impersonation: File sharing notification with template artifacts
- Sublime MQL Brand impersonation: Microsoft logo in HTML with fake quarantine release notification
- Sublime MQL Brand impersonation: Microsoft Planner with suspicious link
- Sublime MQL Brand impersonation: QuickBooks notification from Intuit themed company name
- Sublime MQL Brand Impersonation: ShareFile
- Sublime MQL Brand impersonation: SharePoint PDF attachment with credential theft language
- Sublime MQL Brand impersonation: Stripe notification
- Sublime MQL Brand impersonation: Zoom
- Sublime MQL Canva design with suspicious embedded link
- Sublime MQL Credential Phishing via Dropbox comment abuse
- Sublime MQL Credential phishing: Generic document share with unicode and proceedural greeting template
- Sublime MQL Credential phishing: Generic document sharing
- Sublime MQL Credential phishing: Hyper-linked image leading to free file host
- Sublime MQL Credential phishing: Image as content, short or no body contents
- Sublime MQL Credential Phishing: Suspicious language, link, recipients and other indicators
- Sublime MQL Credential Phishing: W-2 lure with inline SVG Windows logo
- Sublime MQL Credential theft with 'safe content' deception and social engineering topics
- Sublime MQL Credential theft: JavaScript date manipulation in HTML body
- Sublime MQL Cyrillic vowel substitution in subject or display name from unknown sender
- Sublime MQL Cyrillic vowel substitutions with suspicious subject from unknown sender
- Sublime MQL EML attachment with credential theft language (unknown sender)
- Sublime MQL Encrypted Microsoft Office files from untrusted sender
- Sublime MQL Evasion: Hidden content divs from freemail sender
- Sublime MQL Fake shipping notification with suspicious language
- Sublime MQL Fake thread with suspicious indicators
- Sublime MQL Fake warning banner using confusable characters
- Sublime MQL Fake Zoho Sign template abuse
- Sublime MQL Fake Zoom meeting invite with suspicious link
- Sublime MQL Generic service abuse from newly registered domain
- Sublime MQL Google Drive direct download link from unsolicited sender
- Sublime MQL Google presentation open redirect phishing
- Sublime MQL Google services using g.co shortlinks
- Sublime MQL Hardbacon infrastructure abuse
- Sublime MQL Headers: Fake in-reply-to with wildcard sender and missing thread context
- Sublime MQL Headers: Invalid recipient domain with mismatched reply-to from new sender
- Sublime MQL Headers: iOS/iPadOS mailer with invalid build number
- Sublime MQL Headers: Outlook Express mailer
- Sublime MQL Headers: Self-sender using Microsoft CompAuth bypass with credential theft content
- Sublime MQL HR impersonation via e-sign agreement comment
- Sublime MQL HTML content with print styling and credential theft language
- Sublime MQL HTML smuggling containing recipient email address
- Sublime MQL HTML: Bidirectional (BIDI) HTML override with right to left obfuscation
- Sublime MQL HTML: Template placeholders or recipient email in element class attributes
- Sublime MQL Image as content with a link to an open redirect
- Sublime MQL Impersonation: SharePoint reply header anomaly
- Sublime MQL Inline image as message with attachment or link
- Sublime MQL Issuu document with suspicious embedded link
- Sublime MQL Link to a domain with punycode characters
- Sublime MQL Link: .onion From Unsolicited Sender
- Sublime MQL Link: .su domain link redirection from new sender domains
- Sublime MQL Link: Abused Adobe Express
- Sublime MQL Link: Adobe share from unsolicited sender
- Sublime MQL Link: Adobe share with suspicious indicators
- Sublime MQL Link: Apple App Store malicious ad manager themed apps from free email provider
- Sublime MQL Link: Apple TestFlight from suspicious sender
- Sublime MQL Link: Base64 encoded recipient address in URL fragment with hex subdomain
- Sublime MQL Link: Base64 encoded recipient address in URL fragment with subject hash
- Sublime MQL Link: Common hidden directory observed
- Sublime MQL Link: Compromised WordPress site redirecting to suspicious root domain
- Sublime MQL Link: Concatenated display text concealing duplicate URLs with PDF reference
- Sublime MQL Link: Credential harvesting with excess padding evasion
- Sublime MQL Link: Credential phishing link with undisclosed recipients
- Sublime MQL Link: Credential theft with Cloudflare tunnel and recipient targeting
- Sublime MQL Link: Credential theft with invisible Unicode character in page title from unsolicited sender
- Sublime MQL Link: Direct link to gamma.app document with mode parameter
- Sublime MQL Link: Direct link to keap.app contact-us page
- Sublime MQL Link: Display text matches subject line
- Sublime MQL Link: Display text with excessive right-to-left mark characters
- Sublime MQL Link: Document-themed link to newly registered domain
- Sublime MQL Link: Excessive URL rewrite encoders
- Sublime MQL Link: Executable file download with suspicious message content
- Sublime MQL Link: Fake forwarded message with suspicious URL in plain text
- Sublime MQL Link: Fake secure message notification template
- Sublime MQL Link: Figma design deck with credential theft language
- Sublime MQL Link: File sharing pretext with suspicious body and link
- Sublime MQL Link: Flagged bit.ly link
- Sublime MQL Link: Free file hosting with undisclosed recipients
- Sublime MQL Link: Generic financial document with proceedural timeline template
- Sublime MQL Link: Google Cloud Storage hosted credential harvesting page
- Sublime MQL Link: Google Cloud Storage link with index.php in URL
- Sublime MQL Link: Google Cloud Storage link with redirect.html in URL
- Sublime MQL Link: Google Cloud Storage redirect to external domain
- Sublime MQL Link: Google Cloud Storage with short-path link delivery
- Sublime MQL Link: Google Cloud Storage with suspicious URL pattern
- Sublime MQL Link: Google Firebase dynamic link that redirects to new domain (<7 days old)
- Sublime MQL Link: GoPhish query param values
- Sublime MQL Link: Hotel booking spoofed display URL
- Sublime MQL Link: HTML file with suspicious binary fragment ending pattern
- Sublime MQL Link: Invalid reply-to with recipient details in subject, body, and encoded link
- Sublime MQL Link: IPv4-mapped IPv6 address obfuscation
- Sublime MQL Link: JavaScript obfuscation with Telegram bot integration
- Sublime MQL Link: Mamba 2FA phishing kit
- Sublime MQL Link: Microsoft device code authentication with suspicious indicators
- Sublime MQL Link: Microsoft Dynamics 365 form phishing
- Sublime MQL Link: Microsoft protected message with matching sender and recipient addresses
- Sublime MQL Link: Mixed case HTTPS protocol
- Sublime MQL Link: Multiple HTTP protocols in single URL
- Sublime MQL Link: Multistage landing - Abused Adobe frame.io
- Sublime MQL Link: Multistage landing - Abused Docusign
- Sublime MQL Link: Multistage landing - Abused Google Drive
- Sublime MQL Link: Multistage landing - ClickUp abuse
- Sublime MQL Link: Multistage landing - JotForm abuse
- Sublime MQL Link: Multistage landing - Ludus presentation
- Sublime MQL Link: Multistage landing - Scribd document
- Sublime MQL Link: Non-standard port 8443 in display URL
- Sublime MQL Link: Numeric IP obfuscation in URL
- Sublime MQL Link: Obfuscation via userinfo with excessive URL padding
- Sublime MQL Link: Obfuscation via userinfo with suspicious indicators
- Sublime MQL Link: Observed malicious URL path /redirect/redirect/
- Sublime MQL Link: PDF display text with fake copyright claim template
- Sublime MQL Link: PDF file disguised as HTML page
- Sublime MQL Link: PDF filename impersonation with credential theft language
- Sublime MQL Link: QR code in EML attachment with credential phishing indicators
- Sublime MQL Link: Recipient email address in 'eta' parameter
- Sublime MQL Link: Referrer anonymization service from untrusted sender
- Sublime MQL Link: Scribd fullscreen link from suspicious sender
- Sublime MQL Link: Secure SharePoint file share from new or unusual sender
- Sublime MQL Link: Self-sender credential theft with configuration placeholder
- Sublime MQL Link: Self-sender with IP geolocation check and suspicious link behavior
- Sublime MQL Link: Self-sender with sender org in subject and credential theft indicator
- Sublime MQL Link: Self-sent message with quarterly document review request
- Sublime MQL Link: Self-sent PDF lure with subject correlation
- Sublime MQL Link: SharePoint files shared from GoDaddy federated tenants
- Sublime MQL Link: SharePoint OneNote or PDF link with self sender behavior
- Sublime MQL Link: Shortened URL with fragment matching subject
- Sublime MQL Link: Single character path with credential theft body and self sender behavior or invalid recipient
- Sublime MQL Link: Suspicious Family fragment parameter with encoded recipient data
- Sublime MQL Link: Suspicious go.php redirect with document lure
- Sublime MQL Link: Suspicious recipient with timeout redirect
- Sublime MQL Link: Suspicious SharePoint document name
- Sublime MQL Link: Suspicious Sharepoint folder share
- Sublime MQL Link: Suspicious URL path with binary character sequence
- Sublime MQL Link: Suspicious URL with recipient targeting and special characters
- Sublime MQL Link: Suspicious wp-admin path from mismatched sender domain
- Sublime MQL Link: SVG with embedded recipient data
- Sublime MQL Link: Tycoon2FA phishing kit (non-exhaustive)
- Sublime MQL Link: Unformatted template with literal placeholder in mailto link
- Sublime MQL Link: Unicode character obfuscation in display name with base64-encoded URL fragment
- Sublime MQL Link: Unsolicited email contains link leading to Tycoon URL structure
- Sublime MQL Link: Unsolicited email contains link to page containing Tycoon URI structure
- Sublime MQL Link: URL fragment with hexadecimal pattern obfuscation
- Sublime MQL Link: URL fragmented by hidden spans
- Sublime MQL Link: URL path containing /moni/index
- Sublime MQL Link: URL redirecting to blob URL
- Sublime MQL Link: URL scheme obfuscation via split HTML anchors
- Sublime MQL Link: URL shortener chaining to workers.dev redirect
- Sublime MQL Link: URL shortener with copy-paste instructions and credential theft language
- Sublime MQL Link: URL using underscore-dot substitution in display text
- Sublime MQL Link: WordPress admin targeting with recipient identifier in URL parts
- Sublime MQL Low reputation link to auto-downloaded HTML file with smuggling indicators
- Sublime MQL Malformed URL prefix
- Sublime MQL Notion suspicious file share
- Sublime MQL Observed IOC: Mail transiting bulletproof host - SmartApe
- Sublime MQL Observed IOC: Mail transiting OFAC-sanctioned bulletproof host Aeza Group
- Sublime MQL Open redirect: Cartoon Network
- Sublime MQL Open redirect: giving.lluh.org
- Sublime MQL Open Redirect: Google domain with /url path and suspicious indicators
- Sublime MQL Open redirect: JustPaste.it
- Sublime MQL Open redirect: Klaviyo
- Sublime MQL Open redirect: Mailtrack Korea
- Sublime MQL Open redirect: marketing.edinburghairport.com
- Sublime MQL Open redirect: next2.io
- Sublime MQL Open redirect: people.anuneo.com
- Sublime MQL Open redirect: Shibboleth SSO Logout Return Parameter
- Sublime MQL Open redirect: slubnaglowie.pl
- Sublime MQL Open redirect: typedrawers.com
- Sublime MQL Open redirect: weblinkconnect.com
- Sublime MQL Open redirect: Xfinity CMP Redirection to Google AMP
- Sublime MQL Outlook hyperlink bypass: left-to-right mark (LRM) in base HTML tag
- Sublime MQL PhaaS: Impact Solutions (Impact Vector Suite)
- Sublime MQL Potential prompt injection attack in body HTML
- Sublime MQL Punycode sender domain
- Sublime MQL Reconnaissance: Empty subject with mismatched reply-to from new sender
- Sublime MQL Request for Quote or Purchase (RFQ|RFP) with HTML smuggling attachment
- Sublime MQL Salesforce infrastructure abuse
- Sublime MQL Self-impersonation: Sender matches recipient with bolded name and suspicious link
- Sublime MQL Self-sender with copy/paste instructions and suspicious domains (French/Français)
- Sublime MQL Self-sent fake PDF attachment with misleading link
- Sublime MQL Sender: IP address in local part
- Sublime MQL Sendgrid onmicrosoft.com domain phishing
- Sublime MQL Service abuse: Adobe Creative Cloud share from an unsolicited sender address
- Sublime MQL Service abuse: Adobe message from newly registered domain
- Sublime MQL Service abuse: AppSheet infrastructure with suspicious indicators
- Sublime MQL Service Abuse: Box file sharing with credential phishing intent
- Sublime MQL Service abuse: DocSend share from an unsolicited reply-to address
- Sublime MQL Service abuse: DocSend share from newly registered domain
- Sublime MQL Service abuse: DocuSign share from an unsolicited reply-to address
- Sublime MQL Service abuse: Domains By Proxy sender
- Sublime MQL Service abuse: Dropbox Paper with copy-paste instructions
- Sublime MQL Service abuse: Dropbox share from new domain
- Sublime MQL Service Abuse: ExactTarget with suspicious sender indicators
- Sublime MQL Service abuse: Fake loan/funding verification lure via Mailgun
- Sublime MQL Service abuse: FlipHTML5 with attachment deception and credential theft language
- Sublime MQL Service abuse: Free provider with SendGrid routing
- Sublime MQL Service abuse: Google application integration redirecting to suspicious hosts
- Sublime MQL Service abuse: Google OAuth with suspicious redirect destination
- Sublime MQL Service abuse: HelloSign from an unsolicited sender address
- Sublime MQL Service abuse: Linode Objects HTML file hosting
- Sublime MQL Service abuse: Meetup.com redirect with brand impersonation
- Sublime MQL Service abuse: Mimecast URL with excessive path length
- Sublime MQL Service abuse: Monday.com infrastructure with phishing intent
- Sublime MQL Service abuse: Nylas tracking subdomain with suspicious content
- Sublime MQL Service abuse: Outlook Groups with Google Sites link and evasion tag
- Sublime MQL Service abuse: QuickBooks notification from new domain
- Sublime MQL Service abuse: QuickBooks notification with suspicious comments
- Sublime MQL Service abuse: SendGrid-formatted link with actor-controlled fragment
- Sublime MQL Service abuse: Soundestlink redirect with suspicious indicators
- Sublime MQL Service abuse: Substack credential theft with confusable characters and branded button redirects
- Sublime MQL Service abuse: SurveyMonkey survey from newly registered domain
- Sublime MQL Service abuse: Suspicious Datadog alert
- Sublime MQL Service abuse: Suspicious Zoom Docs link
- Sublime MQL Service abuse: Task management message sent via SendGrid
- Sublime MQL Service abuse: Wix redirect through bulk mailer domains
- Sublime MQL Sharepoint file share with suspicious recipients pattern
- Sublime MQL Sharepoint online with external recipients and external display name
- Sublime MQL Spam: Firebase password reset from suspicious sender
- Sublime MQL Subject and sender display name contains matching long alphanumeric string
- Sublime MQL Subject: Suspicious bracketed reference
- Sublime MQL Suspected cross-site scripting (XSS) found in subject
- Sublime MQL Suspicious attachment with unscannable Cloudflare link
- Sublime MQL Suspicious attachment: Duplicate decoy PDF files
- Sublime MQL Suspicious DocuSign share from new domain
- Sublime MQL Suspicious link to Looker Studio (lookerstudio.google.com) from a new and unsolicited sender
- Sublime MQL Suspicious message with unscannable Vercel link
- Sublime MQL Suspicious recipients pattern with NLU credential theft indicators
- Sublime MQL Suspicious sender display name with long procedurally generated text blob
- Sublime MQL Suspicious subject with long procedurally generated text blob
- Sublime MQL Truth Social infrastructure abuse via link redirect
- Sublime MQL Twitter infrastructure abuse via link shortener
- Sublime MQL Unicode QR code
- Sublime MQL Unusually long local part from untrusted sender address
- Sublime MQL URL with Unicode U+2044 (⁄) or U+2215 (∕) characters
- Sublime MQL Vendor compromise: GovDelivery message with suspicious link
- Sublime MQL VIP Impersonation via Google Group relay with suspicious indicators
- Sublime MQL Xero infrastructure abuse
Exploit 5 rules
- Sublime MQL Attachment: Archive containing HTML file with file scheme link
- Sublime MQL Attachment: CVE-2025-24071 - Microsoft Windows File Explorer Spoofing Vulnerability
- Sublime MQL Attachment: DOCX with malicious document template artifacts
- Sublime MQL Open redirect: City of Calgary
- Sublime MQL Outlook hyperlink bypass: left-to-right mark (LRM) in base HTML tag
Free email provider 27 rules
- Sublime MQL Attachment: Canva PDF with susupicious author metadata
- Sublime MQL Brand impersonation: Hulu
- Sublime MQL Brand impersonation: KnowBe4
- Sublime MQL Brand impersonation: Norton
- Sublime MQL Brand impersonation: SiriusXM
- Sublime MQL Brand impersonation: Zoom via lookalike domain
- Sublime MQL ClickFunnels link infrastructure abuse
- Sublime MQL Constant Contact link infrastructure abuse
- Sublime MQL Credential phishing language and suspicious indicators (unknown sender)
- Sublime MQL Credential phishing: Engaging language and other indicators (untrusted sender)
- Sublime MQL Domain impersonation: Freemail reply-to local lookalike with financial request
- Sublime MQL Evasion: Hidden content divs from freemail sender
- Sublime MQL Free email provider sender with mismatched provider reply-to
- Sublime MQL Google services using g.co shortlinks
- Sublime MQL Impersonation: Chrome Web Store policy
- Sublime MQL Link abuse: Self-service creation platform link with suspicious recipient behavior
- Sublime MQL Link: Apple App Store malicious ad manager themed apps from free email provider
- Sublime MQL Link: Apple TestFlight from suspicious sender
- Sublime MQL Link: Multistage landing - Abused Google Drive
- Sublime MQL Link: PDF and financial display text to free file host
- Sublime MQL Reconnaissance: Email address harvesting attempt
- Sublime MQL Service abuse: Free provider with SendGrid routing
- Sublime MQL Service abuse: Google Drive share from an unsolicited reply-to address
- Sublime MQL Service abuse: Google Drive share from new reply-to domain
- Sublime MQL Spam: Default Microsoft Exchange Online sender domain (onmicrosoft.com)
- Sublime MQL Suspicious SharePoint file sharing
- Sublime MQL VIP Impersonation via Google Group relay with suspicious indicators
Free file host 93 rules
- Sublime MQL Attachment: EML file with IPFS links
- Sublime MQL Attachment: EML with link to credential phishing page
- Sublime MQL Attachment: Fake scan-to-email
- Sublime MQL Attachment: ICS file with AWS Lambda URL
- Sublime MQL Attachment: PDF bid/proposal lure with credential theft indicators
- Sublime MQL Attachment: PDF with multistage landing - ClickUp abuse
- Sublime MQL Attachment: PDF with self-service platform links with self sender or blank recipients
- Sublime MQL Attachment: Single-page PDF with S3-hosted HTML link
- Sublime MQL Brand impersonation: Fake Fax
- Sublime MQL Brand impersonation: Microsoft quarantine release notification in image attachment
- Sublime MQL Brand impersonation: Microsoft with low reputation links
- Sublime MQL Canva design with suspicious embedded link
- Sublime MQL Cloud storage impersonation with credential theft indicators
- Sublime MQL Credential phishing: Engaging language with IPFS link
- Sublime MQL Credential phishing: Hyper-linked image leading to free file host
- Sublime MQL Deceptive Dropbox mention
- Sublime MQL DocuSign impersonation via CloudHQ links
- Sublime MQL Fake scan-to-email message
- Sublime MQL File sharing link from suspicious sender domain
- Sublime MQL Google Drive abuse: Credential phishing link
- Sublime MQL Google Drive direct download link from unsolicited sender
- Sublime MQL Google share notification with suspicious comments
- Sublime MQL Invoicera infrastructure abuse
- Sublime MQL Issuu document with suspicious embedded link
- Sublime MQL Link: Abused Adobe Express
- Sublime MQL Link: Adobe share from unsolicited sender
- Sublime MQL Link: Adobe share with suspicious indicators
- Sublime MQL Link: Direct link to Dropbox Paper file
- Sublime MQL Link: Direct link to gamma.app document with mode parameter
- Sublime MQL Link: Direct link to keap.app contact-us page
- Sublime MQL Link: Direct link to riddle.com hosted showcase
- Sublime MQL Link: Document sharing invitation template
- Sublime MQL Link: Figma design deck with credential theft language
- Sublime MQL Link: Financial account issue with suspicious indicators
- Sublime MQL Link: Free file host link with 'Important Viewing Note' lure
- Sublime MQL Link: Free file host links from suspicious support sender with credential theft language
- Sublime MQL Link: Free file hosting with undisclosed recipients
- Sublime MQL Link: Google Cloud Storage hosted credential harvesting page
- Sublime MQL Link: Google Cloud Storage impersonating with googledrive in URL path
- Sublime MQL Link: Google Cloud Storage link with index.php in URL
- Sublime MQL Link: Google Cloud Storage link with redirect.html in URL
- Sublime MQL Link: Google Cloud Storage redirect to external domain
- Sublime MQL Link: Google Cloud Storage with short-path link delivery
- Sublime MQL Link: Google Cloud Storage with suspicious URL pattern
- Sublime MQL Link: IPFS
- Sublime MQL Link: Mismatched free file host links with document lure
- Sublime MQL Link: Multistage landing - Abused Adobe frame.io
- Sublime MQL Link: Multistage Landing - Abused Buildin.ai
- Sublime MQL Link: Multistage landing - Abused Docusign
- Sublime MQL Link: Multistage landing - Abused Google Drive
- Sublime MQL Link: Multistage landing - ClickUp abuse
- Sublime MQL Link: Multistage landing - Published Google Doc
- Sublime MQL Link: Multistage landing - Scribd document
- Sublime MQL Link: Multistage landing - Trello board abuse
- Sublime MQL Link: PDF and financial display text to free file host
- Sublime MQL Link: Personalized URL with recipient address on commonly abused web service
- Sublime MQL Link: Scribd fullscreen link from suspicious sender
- Sublime MQL Link: Secure SharePoint file share from new or unusual sender
- Sublime MQL Link: SharePoint OneNote or PDF link with self sender behavior
- Sublime MQL Link: Suspicious SharePoint document name
- Sublime MQL Link: Suspicious Sharepoint folder share
- Sublime MQL Link: Tax document lure Portuguese/Spanish with suspicious domains
- Sublime MQL Link: URL redirecting to blob URL
- Sublime MQL Low reputation link to auto-downloaded HTML file with smuggling indicators
- Sublime MQL Mismatched links: Free file share with urgent language
- Sublime MQL Notion suspicious file share
- Sublime MQL Open redirect: JustPaste.it
- Sublime MQL Service abuse: Adobe Creative Cloud share from an unsolicited sender address
- Sublime MQL Service abuse: Behance document sharing with suspicious language
- Sublime MQL Service abuse: Citrix ShareFile impersonation via Outlook plugin
- Sublime MQL Service abuse: DocSend share from an unsolicited reply-to address
- Sublime MQL Service abuse: DocSend share from newly registered domain
- Sublime MQL Service abuse: DocuSign share from an unsolicited reply-to address
- Sublime MQL Service abuse: Dropbox Paper with copy-paste instructions
- Sublime MQL Service abuse: FlipHTML5 with attachment deception and credential theft language
- Sublime MQL Service abuse: Formester with suspicious link behavior
- Sublime MQL Service abuse: GitHub notification with excessive mentions and suspicious links
- Sublime MQL Service abuse: Google account notification with links to free file host
- Sublime MQL Service abuse: Google application integration redirecting to suspicious hosts
- Sublime MQL Service abuse: Google Drive share from an unsolicited reply-to address
- Sublime MQL Service abuse: Google Drive share from new reply-to domain
- Sublime MQL Service abuse: Google OAuth with suspicious redirect destination
- Sublime MQL Service abuse: HelloSign from an unsolicited sender address
- Sublime MQL Service abuse: Linode Objects HTML file hosting
- Sublime MQL Service abuse: SendThisFile with credential theft and financial language
- Sublime MQL Service abuse: Square marketing with suspicious QR code
- Sublime MQL Service abuse: SurveyMonkey survey from newly registered domain
- Sublime MQL Service abuse: Suspicious Zoom Docs link
- Sublime MQL Spoofable internal domain with suspicious signals
- Sublime MQL Suspicious DocuSign share from new domain
- Sublime MQL Suspicious Links to Cloudflare R2 and Edge Services
- Sublime MQL Suspicious SharePoint file sharing
- Sublime MQL Zoom Events newsletter abuse
Free subdomain host 47 rules
- Sublime MQL Attachment: EML file with IPFS links
- Sublime MQL Attachment: EML with link to credential phishing page
- Sublime MQL Attachment: HTML smuggling Microsoft sign in
- Sublime MQL Attachment: HTML smuggling with raw array buffer
- Sublime MQL Attachment: PDF Attachment with links to workers.dev
- Sublime MQL Attachment: PDF bid/proposal lure with credential theft indicators
- Sublime MQL Attachment: PDF with credential theft language and link to a free subdomain (unsolicited)
- Sublime MQL Attachment: PDF with multistage landing - ClickUp abuse
- Sublime MQL Attachment: RTF with link to free-hosted Cloudflare Pages
- Sublime MQL Brand impersonation: Coinbase with suspicious links
- Sublime MQL Brand impersonation: Fake Fax
- Sublime MQL Brand impersonation: Government / Tax Authority document lure
- Sublime MQL ClickFunnels link infrastructure abuse
- Sublime MQL Credential phishing: AWS Lambda URL with recipient targeting
- Sublime MQL Credential phishing: Engaging language with IPFS link
- Sublime MQL Credential phishing: Onedrive impersonation
- Sublime MQL Deceptive Dropbox mention
- Sublime MQL Free subdomain link with credential theft indicators
- Sublime MQL Free subdomain link with login or captcha (untrusted sender)
- Sublime MQL Invoicera infrastructure abuse
- Sublime MQL Link: Abused Adobe Express
- Sublime MQL Link: Breely link masquerading as PDF
- Sublime MQL Link: Credential phishing via WordPress
- Sublime MQL Link: File sharing impersonation with suspicious language and sending patterns
- Sublime MQL Link: Financial account issue with suspicious indicators
- Sublime MQL Link: Flare-branded credential harvesting via Cloudflare tunnels
- Sublime MQL Link: Fraudulent state business filing notice
- Sublime MQL Link: Free file hosting with undisclosed recipients
- Sublime MQL Link: IPFS
- Sublime MQL Link: Multistage landing - Abused Docusign
- Sublime MQL Link: Multistage landing - ClickUp abuse
- Sublime MQL Link: Tax document lure Portuguese/Spanish with suspicious domains
- Sublime MQL Link: Tycoon2FA phishing kit (non-exhaustive)
- Sublime MQL Link: URL shortener chaining to workers.dev redirect
- Sublime MQL Link: WordPress login page with Blogspot Binance scam
- Sublime MQL Low reputation link to auto-downloaded HTML file with smuggling indicators
- Sublime MQL Self-sender with copy/paste instructions and suspicious domains (French/Français)
- Sublime MQL Self-sent fake PDF attachment with misleading link
- Sublime MQL Service abuse: GitHub notification with excessive mentions and suspicious links
- Sublime MQL Service abuse: Google application integration redirecting to suspicious hosts
- Sublime MQL Service abuse: Google Firebase sender address with suspicious content
- Sublime MQL Service abuse: Google OAuth with suspicious redirect destination
- Sublime MQL Service abuse: Outlook Groups with Google Sites link and evasion tag
- Sublime MQL Service abuse: Suspicious Datadog alert
- Sublime MQL Spoofable internal domain with suspicious signals
- Sublime MQL Vendor compromise: GovDelivery message with suspicious link
- Sublime MQL Zoom Events newsletter abuse
HTML injection 1 rule
HTML smuggling 44 rules
- Sublime MQL Attachment: Any HTML file within archive (unsolicited)
- Sublime MQL Attachment: Archive containing HTML file with file scheme link
- Sublime MQL Attachment: Double base64-encoded zip file in HTML smuggling attachment
- Sublime MQL Attachment: EML containing a base64 encoded script
- Sublime MQL Attachment: EML file contains HTML attachment with login portal indicators
- Sublime MQL Attachment: EML file with HTML attachment (unsolicited)
- Sublime MQL Attachment: EML with suspicious indicators
- Sublime MQL Attachment: HTML attachment with Javascript location
- Sublime MQL Attachment: HTML attachment with login portal indicators
- Sublime MQL Attachment: HTML file contains exclusively Javascript
- Sublime MQL Attachment: HTML file with excessive 'const' declarations and abnormally long timeouts
- Sublime MQL Attachment: HTML file with excessive padding and suspicious patterns
- Sublime MQL Attachment: HTML file with reference to recipient and suspicious patterns
- Sublime MQL Attachment: HTML smuggling 'body onload' linking to suspicious destination
- Sublime MQL Attachment: HTML smuggling 'body onload' with high entropy and suspicious text
- Sublime MQL Attachment: HTML smuggling Microsoft sign in
- Sublime MQL Attachment: HTML smuggling with atob and high entropy
- Sublime MQL Attachment: HTML smuggling with atob and high entropy via calendar invite
- Sublime MQL Attachment: HTML smuggling with auto-downloaded file
- Sublime MQL Attachment: HTML smuggling with base64 encoded JavaScript function
- Sublime MQL Attachment: HTML smuggling with base64 encoded ZIP file
- Sublime MQL Attachment: HTML smuggling with concatenation obfuscation
- Sublime MQL Attachment: HTML smuggling with decimal encoding
- Sublime MQL Attachment: HTML smuggling with embedded base64-encoded ISO
- Sublime MQL Attachment: HTML smuggling with eval and atob
- Sublime MQL Attachment: HTML smuggling with eval and atob via calendar invite
- Sublime MQL Attachment: HTML smuggling with excessive line break obfuscation
- Sublime MQL Attachment: HTML smuggling with excessive string concatenation and suspicious patterns
- Sublime MQL Attachment: HTML smuggling with fromCharCode and other signals
- Sublime MQL Attachment: HTML smuggling with hex strings
- Sublime MQL Attachment: HTML smuggling with raw array buffer
- Sublime MQL Attachment: HTML smuggling with RC4 decryption
- Sublime MQL Attachment: HTML smuggling with ROT13
- Sublime MQL Attachment: HTML smuggling with setTimeout
- Sublime MQL Attachment: HTML smuggling with unescape
- Sublime MQL Attachment: HTML with emoji-to-character map
- Sublime MQL Attachment: HTML with obfuscation and recipient's email in JavaScript strings
- Sublime MQL Attachment: SVG file with HTML entity encoded href attributes
- Sublime MQL Attachment: Web files with suspicious comments
- Sublime MQL Credential Phishing: W-2 lure with inline SVG Windows logo
- Sublime MQL HTML content with print styling and credential theft language
- Sublime MQL HTML smuggling containing recipient email address
- Sublime MQL HTML smuggling with atob in message body
- Sublime MQL Low reputation link to auto-downloaded HTML file with smuggling indicators
ICS Phishing 12 rules
- Sublime MQL Attachment: Calendar file with invisible Unicode characters
- Sublime MQL Attachment: Calendar invite with Google redirect and invoice request
- Sublime MQL Attachment: HTML smuggling with atob and high entropy via calendar invite
- Sublime MQL Attachment: HTML smuggling with eval and atob via calendar invite
- Sublime MQL Attachment: ICS calendar file with base64 encoded recipient address in URL parameters
- Sublime MQL Attachment: ICS calendar file with suspicious product identifier
- Sublime MQL Attachment: ICS calendar with embedded file from internal sender with SPF failure
- Sublime MQL Attachment: ICS file with AWS Lambda URL
- Sublime MQL Attachment: ICS file with meeting prefix
- Sublime MQL Attachment: ICS file with non-Gregorian calendar scale
- Sublime MQL Attachment: ICS with embedded Javascript in SVG file
- Sublime MQL Attachment: ICS with employee policy review lure
IPFS 4 rules
- Sublime MQL Attachment: EML file with IPFS links
- Sublime MQL Credential phishing: Engaging language with IPFS link
- Sublime MQL Link: IPFS
- Sublime MQL Vendor compromise: GovDelivery message with suspicious link
ISO 1 rule
Image as content 30 rules
- Sublime MQL Attachment: Adobe image lure in body or attachment with suspicious link
- Sublime MQL Attachment: Fake attachment image lure
- Sublime MQL Attachment: Fake scan-to-email
- Sublime MQL Attachment: Fake secure message and suspicious indicators
- Sublime MQL Attachment: Microsoft impersonation via PDF with link and suspicious language
- Sublime MQL Attachment: Microsoft SharePoint Impersonation via images in macro-enabled attachment
- Sublime MQL Attachment: PDF with secure document acknowledgment prompt
- Sublime MQL Attachment: QR code link with base64-encoded recipient address
- Sublime MQL Attachment: QR code with encoded recipient targeting and redirect indicators
- Sublime MQL Attachment: QR code with userinfo portion
- Sublime MQL Attachment: SVG file with hyperlinks and cursor styling
- Sublime MQL Attachment: SVG files with evasion elements
- Sublime MQL Brand impersonation: Coinbase with suspicious links
- Sublime MQL Brand impersonation: DocuSign with embedded QR code
- Sublime MQL Brand impersonation: Fake Fax
- Sublime MQL Brand impersonation: Figma with malicious document access overlay
- Sublime MQL Brand impersonation: Microsoft Planner with suspicious link
- Sublime MQL Brand impersonation: Microsoft with low reputation links
- Sublime MQL Brand impersonation: USPS
- Sublime MQL Cloud storage impersonation with credential theft indicators
- Sublime MQL Credential phishing: Hyper-linked image leading to free file host
- Sublime MQL Credential phishing: Image as content, short or no body contents
- Sublime MQL Image as content with a link to an open redirect
- Sublime MQL Impersonation: Recipient organization in sender display name with credential theft image
- Sublime MQL Impersonation: SAM/SBA federal registration
- Sublime MQL Inline image as message with attachment or link
- Sublime MQL Invoicera infrastructure abuse
- Sublime MQL Link: PDF display text with fake copyright claim template
- Sublime MQL PHP Mailer with common phishing attachments
- Sublime MQL Spam: Mastercard promotional content with image-based body
Impersonation: Brand 255 rules
- Sublime MQL Abuse: Cloudflare Workers Hosted EvilTokens Domain Structure
- Sublime MQL Abuse: Robinhood injected content
- Sublime MQL Attachment: Adobe image lure in body or attachment with suspicious link
- Sublime MQL Attachment: Adobe Sign lure PDF with embedded banner images
- Sublime MQL Attachment: Compensation-themed DOCX with QR code credential theft
- Sublime MQL Attachment: Decoy PDF author (Julie P.)
- Sublime MQL Attachment: DocuSign impersonation via PDF linking to new domain
- Sublime MQL Attachment: Dropbox image lure with no Dropbox domains in links
- Sublime MQL Attachment: EML with SharePoint files shared from GoDaddy federated tenants
- Sublime MQL Attachment: EML with Sharepoint link likely unrelated to sender
- Sublime MQL Attachment: Fake secure message and suspicious indicators
- Sublime MQL Attachment: HTML smuggling Microsoft sign in
- Sublime MQL Attachment: HTML with emoji-to-character map
- Sublime MQL Attachment: Microsoft 365 credential phishing
- Sublime MQL Attachment: Microsoft impersonation via PDF with link and suspicious language
- Sublime MQL Attachment: Microsoft OAuth credential harvesting via EML with embedded malicious links
- Sublime MQL Attachment: Microsoft SharePoint Impersonation via images in macro-enabled attachment
- Sublime MQL Attachment: PDF with Microsoft Purview message impersonation
- Sublime MQL Attachment: PDF With SAI Global ISO9001 Logo
- Sublime MQL Attachment: PDF with secure document acknowledgment prompt
- Sublime MQL Brand impersonation: AARP
- Sublime MQL Brand impersonation: Adobe (QR code)
- Sublime MQL Brand impersonation: Adobe Acrobat Sign PDF phishing file format template
- Sublime MQL Brand impersonation: Adobe Sign with suspicious indicators
- Sublime MQL Brand impersonation: Adobe with suspicious language and link
- Sublime MQL Brand impersonation: ADP
- Sublime MQL Brand impersonation: AliExpress
- Sublime MQL Brand impersonation: Amazon
- Sublime MQL Brand impersonation: Amazon Web Services (AWS)
- Sublime MQL Brand impersonation: Amazon with suspicious attachment
- Sublime MQL Brand impersonation: American Express (AMEX)
- Sublime MQL Brand impersonation: Apple
- Sublime MQL Brand impersonation: Aquent
- Sublime MQL Brand impersonation: AuthentiSign
- Sublime MQL Brand impersonation: Automobile assistance associations
- Sublime MQL Brand impersonation: Bank of America
- Sublime MQL Brand impersonation: Barracuda Networks
- Sublime MQL Brand impersonation: Bids & Tenders
- Sublime MQL Brand impersonation: Binance
- Sublime MQL Brand impersonation: Blockchain.com
- Sublime MQL Brand impersonation: Booking.com
- Sublime MQL Brand impersonation: Box file sharing service
- Sublime MQL Brand impersonation: Canada Revenue Agency
- Sublime MQL Brand impersonation: Capital One
- Sublime MQL Brand impersonation: Charles Schwab
- Sublime MQL Brand impersonation: Chase Bank
- Sublime MQL Brand impersonation: Chase bank with credential phishing indicators
- Sublime MQL Brand impersonation: Coinbase
- Sublime MQL Brand impersonation: Coinbase with suspicious links
- Sublime MQL Brand impersonation: Dashlane
- Sublime MQL Brand impersonation: DHL
- Sublime MQL Brand impersonation: DigitalOcean
- Sublime MQL Brand impersonation: Discord notification
- Sublime MQL Brand Impersonation: Disney
- Sublime MQL Brand impersonation: DocSend
- Sublime MQL Brand impersonation: DocuSign
- Sublime MQL Brand impersonation: DocuSign (QR code)
- Sublime MQL Brand impersonation: DocuSign branded attachment lure with no DocuSign links
- Sublime MQL Brand impersonation: DocuSign PDF attachment with suspicious link
- Sublime MQL Brand impersonation: DocuSign with embedded QR code
- Sublime MQL Brand impersonation: DoorDash
- Sublime MQL Brand impersonation: Dotloop
- Sublime MQL Brand impersonation: Dropbox
- Sublime MQL Brand impersonation: Enbridge
- Sublime MQL Brand impersonation: Evite
- Sublime MQL Brand impersonation: Exodus
- Sublime MQL Brand impersonation: Fake DocuSign HTML table not linking to DocuSign domains
- Sublime MQL Brand impersonation: Fake Fax
- Sublime MQL Brand impersonation: Fastway
- Sublime MQL Brand impersonation: FedEx
- Sublime MQL Brand impersonation: Figma with malicious document access overlay
- Sublime MQL Brand impersonation: File sharing notification with template artifacts
- Sublime MQL Brand impersonation: FINRA
- Sublime MQL Brand Impersonation: Gemini Trust Company
- Sublime MQL Brand impersonation: Github
- Sublime MQL Brand impersonation: GoDaddy
- Sublime MQL Brand Impersonation: Google (QR Code)
- Sublime MQL Brand impersonation: Google Careers
- Sublime MQL Brand impersonation: Google Drive fake file share
- Sublime MQL Brand impersonation: Google fake sign-in warning
- Sublime MQL Brand impersonation: Google Meet with malicious link
- Sublime MQL Brand impersonation: Google using Microsoft Forms
- Sublime MQL Brand impersonation: Google Workspace alert notification
- Sublime MQL Brand impersonation: Government / Tax Authority document lure
- Sublime MQL Brand impersonation: Greenvelope
- Sublime MQL Brand impersonation: Gusto
- Sublime MQL Brand impersonation: Hulu
- Sublime MQL Brand impersonation: Internal Revenue Service
- Sublime MQL Brand impersonation: KnowBe4
- Sublime MQL Brand impersonation: LastPass
- Sublime MQL Brand impersonation: Ledger
- Sublime MQL Brand impersonation: LinkedIn
- Sublime MQL Brand impersonation: Mailchimp
- Sublime MQL Brand impersonation: Mailgun
- Sublime MQL Brand impersonation: Marriott with gift language
- Sublime MQL Brand impersonation: McAfee
- Sublime MQL Brand impersonation: Meta and subsidiaries
- Sublime MQL Brand impersonation: MetaMask
- Sublime MQL Brand impersonation: Microsoft
- Sublime MQL Brand impersonation: Microsoft (QR code)
- Sublime MQL Brand impersonation: Microsoft fake sign-in alert
- Sublime MQL Brand impersonation: Microsoft logo in HTML with fake quarantine release notification
- Sublime MQL Brand impersonation: Microsoft Planner with suspicious link
- Sublime MQL Brand impersonation: Microsoft quarantine release notification in body
- Sublime MQL Brand impersonation: Microsoft quarantine release notification in image attachment
- Sublime MQL Brand impersonation: Microsoft Teams
- Sublime MQL Brand impersonation: Microsoft Teams invitation
- Sublime MQL Brand impersonation: Microsoft with embedded logo and credential theft language
- Sublime MQL Brand impersonation: Microsoft with low reputation links
- Sublime MQL Brand impersonation: Morgan Stanley
- Sublime MQL Brand impersonation: Navan
- Sublime MQL Brand impersonation: Netflix
- Sublime MQL Brand impersonation: Norton
- Sublime MQL Brand impersonation: Office 365 mail service
- Sublime MQL Brand impersonation: Okta
- Sublime MQL Brand Impersonation: OpenAI with ChatGPT Ads lure
- Sublime MQL Brand impersonation: OpenAI with payment issues
- Sublime MQL Brand impersonation: Outlook
- Sublime MQL Brand impersonation: Paperless Post
- Sublime MQL Brand Impersonation: PayPal
- Sublime MQL Brand impersonation: PNC
- Sublime MQL Brand Impersonation: Procore
- Sublime MQL Brand impersonation: Proofpoint secure messaging without legitimate indicators
- Sublime MQL Brand impersonation: Punchbowl
- Sublime MQL Brand impersonation: Purdue ePlanroom with suspicious links
- Sublime MQL Brand impersonation: Quickbooks
- Sublime MQL Brand impersonation: Ripple
- Sublime MQL Brand impersonation: Robert Half
- Sublime MQL Brand impersonation: Robinhood
- Sublime MQL Brand impersonation: SendGrid
- Sublime MQL Brand Impersonation: ShareFile
- Sublime MQL Brand impersonation: Sharepoint
- Sublime MQL Brand impersonation: Sharepoint fake file share
- Sublime MQL Brand impersonation: SharePoint PDF attachment with credential theft language
- Sublime MQL Brand Impersonation: Shein
- Sublime MQL Brand impersonation: Silicon Valley Bank
- Sublime MQL Brand impersonation: SiriusXM
- Sublime MQL Brand impersonation: Social Security Administration
- Sublime MQL Brand impersonation: SoFi
- Sublime MQL Brand impersonation: Spotify
- Sublime MQL Brand impersonation: Square
- Sublime MQL Brand impersonation: Squarespace
- Sublime MQL Brand impersonation: State Farm
- Sublime MQL Brand impersonation: Stellar Development Foundation (SDF)
- Sublime MQL Brand Impersonation: Stripe
- Sublime MQL Brand impersonation: Stripe notification
- Sublime MQL Brand impersonation: Sublime Security
- Sublime MQL Brand impersonation: Survey request with credential theft indicators
- Sublime MQL Brand impersonation: TikTok
- Sublime MQL Brand impersonation: Toronto-Dominion Bank
- Sublime MQL Brand impersonation: Trust Wallet
- Sublime MQL Brand impersonation: TurboTax
- Sublime MQL Brand impersonation: Twitter
- Sublime MQL Brand impersonation: UK government Home Office
- Sublime MQL Brand impersonation: ukr[.]net
- Sublime MQL Brand impersonation: United Healthcare
- Sublime MQL Brand impersonation: UPS
- Sublime MQL Brand impersonation: USPS
- Sublime MQL Brand impersonation: Vanguard
- Sublime MQL Brand impersonation: Vanta
- Sublime MQL Brand impersonation: Venmo
- Sublime MQL Brand impersonation: Wells Fargo
- Sublime MQL Brand impersonation: WeTransfer
- Sublime MQL Brand impersonation: Wise
- Sublime MQL Brand impersonation: Wix
- Sublime MQL Brand impersonation: Xodo Sign
- Sublime MQL Brand impersonation: Zoom
- Sublime MQL Brand impersonation: Zoom (strict)
- Sublime MQL Brand impersonation: Zoom via HTML styling
- Sublime MQL Brand impersonation: Zoom via lookalike domain
- Sublime MQL Brand impersonation: Zoom with deceptive link display
- Sublime MQL Brand spoof: Dropbox
- Sublime MQL Cloud storage impersonation with credential theft indicators
- Sublime MQL Credential phishing: Blue button styled link with file-sharing template artifacts
- Sublime MQL Credential phishing: DocuSign embedded image lure with no DocuSign domains in links
- Sublime MQL Credential phishing: Email delivery failure impersonation
- Sublime MQL Credential phishing: Onedrive impersonation
- Sublime MQL Credential phishing: Personalized document signing request
- Sublime MQL Credential phishing: Re-Authentication lure
- Sublime MQL Credential phishing: Suspicious subject with urgent financial request and link
- Sublime MQL Credential phishing: Tax form impersonation with payment request
- Sublime MQL Cyrillic vowel substitutions with suspicious subject from unknown sender
- Sublime MQL Deceptive Dropbox mention
- Sublime MQL DocuSign impersonation via CloudHQ links
- Sublime MQL DocuSign impersonation via spoofed Intuit sender
- Sublime MQL Fake Zoom meeting invite with suspicious link
- Sublime MQL Google Accelerated Mobile Pages (AMP) abuse
- Sublime MQL Google Drive abuse: Credential phishing link
- Sublime MQL Hardbacon infrastructure abuse
- Sublime MQL HR impersonation via e-sign agreement comment
- Sublime MQL Impersonation: Chrome Web Store policy
- Sublime MQL Impersonation: Fake Gmail attachment
- Sublime MQL Impersonation: Recipient organization in sender display name with credential theft image
- Sublime MQL Impersonation: Salesforce fake campaign failure notification
- Sublime MQL Impersonation: SAM/SBA federal registration
- Sublime MQL Impersonation: SharePoint reply header anomaly
- Sublime MQL Link: Apple App Store link to apps impersonating AI adveristing
- Sublime MQL Link: Direct link to Zoom Docs from non-Zoom sender
- Sublime MQL Link: File sharing impersonation with suspicious language and sending patterns
- Sublime MQL Link: Fraudulent state business filing notice
- Sublime MQL Link: Free file host link with 'Important Viewing Note' lure
- Sublime MQL Link: Google Cloud Storage hosted credential harvesting page
- Sublime MQL Link: Google Cloud Storage impersonating with googledrive in URL path
- Sublime MQL Link: Google Cloud Storage redirect to external domain
- Sublime MQL Link: Google Cloud Storage with short-path link delivery
- Sublime MQL Link: Intuit link abuse with file share context
- Sublime MQL Link: Microsoft device code authentication with suspicious indicators
- Sublime MQL Link: Microsoft impersonation using hosted png with suspicious link
- Sublime MQL Link: Multistage landing - Abused Adobe Acrobat hosted PDF
- Sublime MQL Link: Multistage landing - FreshDesk knowledge base abuse
- Sublime MQL Link: Multistage landing - Ludus presentation
- Sublime MQL Link: Multistage landing - Microsoft Forms abuse
- Sublime MQL Link: Multistage landing - Scribd document
- Sublime MQL Link: Obfuscation via userinfo with excessive URL padding
- Sublime MQL Link: QR Code with suspicious language (untrusted sender)
- Sublime MQL Link: QuickBooks image lure with suspicious link
- Sublime MQL Link: Squarespace infrastructure abuse
- Sublime MQL Link: Suspicious HTML structure with subject mirrored in body and single link
- Sublime MQL Link: Suspicious Loom HTML file path
- Sublime MQL Link: WordPress login page with Blogspot Binance scam
- Sublime MQL Low reputation link to auto-downloaded HTML file with smuggling indicators
- Sublime MQL Microsoft device code phishing
- Sublime MQL Open redirect (go2.aspx) leading to Microsoft credential phishing
- Sublime MQL Open redirect: Diesel.az
- Sublime MQL Open redirect: Klaviyo
- Sublime MQL Open redirect: queue.swytchbike.com
- Sublime MQL Recruitee Infrastructure Abuse
- Sublime MQL Scam soliciting employer review/rating
- Sublime MQL Service abuse: DocSend share from newly registered domain
- Sublime MQL Service abuse: Facebook business with action required subject
- Sublime MQL Service abuse: Fake loan/funding verification lure via Mailgun
- Sublime MQL Service abuse: File sharing impersonation with external SharePoint links
- Sublime MQL Service abuse: Google account notification with links to free file host
- Sublime MQL Service abuse: Meetup.com redirect with brand impersonation
- Sublime MQL Service abuse: Microsoft Forms Pro with suspicious links or QR codes
- Sublime MQL Service abuse: Microsoft with suspicious indicators in subject
- Sublime MQL Service abuse: PayPal manager account creation with callback scam indicators
- Sublime MQL Service abuse: Roomsy with unrelated body content
- Sublime MQL Service abuse: SendGrid impersonation via Sendgrid from new sender
- Sublime MQL Service abuse: Soundestlink.com Microsoft impersonation
- Sublime MQL Service abuse: SurveyMonkey with suspicious outbound links
- Sublime MQL Service abuse: Task management message sent via SendGrid
- Sublime MQL Service abuse: Vimeo with external plain-text links in message
- Sublime MQL SharePoint OTP for filename matching org name
- Sublime MQL Spam: Default Microsoft Exchange Online sender domain (onmicrosoft.com)
- Sublime MQL Spam: Mastercard promotional content with image-based body
- Sublime MQL Subject: Suspicious bracketed reference
- Sublime MQL Suspected WordPress abuse with cross-site scripting (XSS) indicators
- Sublime MQL Suspicious DocuSign share from new domain
- Sublime MQL Truth Social infrastructure abuse via link redirect
- Sublime MQL Twitter infrastructure abuse via link shortener
- Sublime MQL Vendor compromise: GovDelivery message with suspicious link
- Sublime MQL X (Twitter) impersonation with credential phishing motives
- Sublime MQL Xero invoice abuse
- Sublime MQL Zoom Events newsletter abuse
Impersonation: Domain 2 rules
- Sublime MQL Observed IOC: Malicious sender domains
- Sublime MQL Observed IOC: Malicious sender root domains
Impersonation: Email address 1 rule
- Sublime MQL Observed IOC: Malicious sender email addresses
Impersonation: Employee 13 rules
- Sublime MQL Benefits enrollment impersonation
- Sublime MQL Credential phishing: Generic document sharing
- Sublime MQL Headers: System account impersonation with empty sender address
- Sublime MQL Impersonation: Human Resources with link or attachment and engaging language
- Sublime MQL Impersonation: Internal corporate services
- Sublime MQL Impersonation: IT Department mailbox storage alert
- Sublime MQL Link: HR impersonation with suspicious domain indicators and credential theft
- Sublime MQL Link: SharePoint filename matches org name
- Sublime MQL Service Abuse: Box file sharing with credential phishing intent
- Sublime MQL Sharepoint link likely unrelated to sender
- Sublime MQL Suspicious attachment with unscannable Cloudflare link
- Sublime MQL VIP Impersonation via Google Group relay with suspicious indicators
- Sublime MQL Xero invoice abuse
Impersonation: VIP 5 rules
- Sublime MQL Google share notification with suspicious comments
- Sublime MQL Service Abuse: Box file sharing with credential phishing intent
- Sublime MQL Service abuse: Notion free-tier account impersonating VIP
- Sublime MQL Service abuse: Trello board invitation with VIP impersonation
- Sublime MQL Suspicious attachment with unscannable Cloudflare link
LNK 1 rule
- Sublime MQL Attachment: Link file with UNC path
Lookalike domain 55 rules
- Sublime MQL Brand impersonation: American Express (AMEX)
- Sublime MQL Brand impersonation: AuthentiSign
- Sublime MQL Brand impersonation: Bank of America
- Sublime MQL Brand impersonation: Barracuda Networks
- Sublime MQL Brand impersonation: Binance
- Sublime MQL Brand impersonation: Blockchain.com
- Sublime MQL Brand impersonation: Capital One
- Sublime MQL Brand impersonation: Charles Schwab
- Sublime MQL Brand impersonation: Chase Bank
- Sublime MQL Brand impersonation: Coinbase
- Sublime MQL Brand impersonation: DHL
- Sublime MQL Brand impersonation: DigitalOcean
- Sublime MQL Brand impersonation: DocSend
- Sublime MQL Brand impersonation: DocuSign
- Sublime MQL Brand impersonation: Fastway
- Sublime MQL Brand impersonation: FedEx
- Sublime MQL Brand impersonation: FINRA
- Sublime MQL Brand impersonation: Github
- Sublime MQL Brand impersonation: Google using Microsoft Forms
- Sublime MQL Brand impersonation: Google Workspace alert notification
- Sublime MQL Brand impersonation: Government / Tax Authority document lure
- Sublime MQL Brand impersonation: Gusto
- Sublime MQL Brand impersonation: Hulu
- Sublime MQL Brand impersonation: KnowBe4
- Sublime MQL Brand impersonation: Ledger
- Sublime MQL Brand impersonation: LinkedIn
- Sublime MQL Brand impersonation: Meta and subsidiaries
- Sublime MQL Brand impersonation: Netflix
- Sublime MQL Brand impersonation: Office 365 mail service
- Sublime MQL Brand impersonation: Okta
- Sublime MQL Brand impersonation: Outlook
- Sublime MQL Brand Impersonation: PayPal
- Sublime MQL Brand impersonation: PNC
- Sublime MQL Brand Impersonation: ShareFile
- Sublime MQL Brand impersonation: Silicon Valley Bank
- Sublime MQL Brand impersonation: Spotify
- Sublime MQL Brand Impersonation: Stripe
- Sublime MQL Brand impersonation: Sublime Security
- Sublime MQL Brand impersonation: TurboTax
- Sublime MQL Brand impersonation: Twitter
- Sublime MQL Brand impersonation: UK government Home Office
- Sublime MQL Brand impersonation: UPS
- Sublime MQL Brand impersonation: Vanta
- Sublime MQL Brand impersonation: Venmo
- Sublime MQL Brand impersonation: Wells Fargo
- Sublime MQL Brand impersonation: Wix
- Sublime MQL Impersonation: Chrome Web Store policy
- Sublime MQL Link to a domain with punycode characters
- Sublime MQL Link: HR impersonation with suspicious domain indicators and credential theft
- Sublime MQL Link: Recipient domain in URL path
- Sublime MQL Lookalike sender domain (untrusted sender)
- Sublime MQL Punycode sender domain
- Sublime MQL Service abuse: Adobe message from newly registered domain
- Sublime MQL Service abuse: Soundestlink.com Microsoft impersonation
- Sublime MQL Sharepoint link likely unrelated to sender
Macros 7 rules
- Sublime MQL Attachment: CVE-2025-24071 - Microsoft Windows File Explorer Spoofing Vulnerability
- Sublime MQL Attachment: Excel file with document sharing lure created by Go Excelize
- Sublime MQL Attachment: Excel file with suspicious template identifier
- Sublime MQL Attachment: Macro files containing MHT content
- Sublime MQL Attachment: Microsoft SharePoint Impersonation via images in macro-enabled attachment
- Sublime MQL Attachment: QR code link with base64-encoded recipient address
- Sublime MQL Attachment: XLSX file with suspicious print titles metadata
OneNote 4 rules
Open redirect 151 rules
- Sublime MQL Attachment: Calendar invite with Google redirect and invoice request
- Sublime MQL Attachment: Link to Doubleclick.net open redirect
- Sublime MQL Attachment: QR code with encoded recipient targeting and redirect indicators
- Sublime MQL Constant Contact link infrastructure abuse
- Sublime MQL Fake Zoho Sign template abuse
- Sublime MQL Google Accelerated Mobile Pages (AMP) abuse
- Sublime MQL Google presentation open redirect phishing
- Sublime MQL Image as content with a link to an open redirect
- Sublime MQL Link to Google Apps Script macro (unsolicited)
- Sublime MQL Link: .su domain link redirection from new sender domains
- Sublime MQL Link: Compromised WordPress site redirecting to suspicious root domain
- Sublime MQL Link: Google Cloud Storage link with index.php in URL
- Sublime MQL Link: Google Cloud Storage link with redirect.html in URL
- Sublime MQL Link: Google Cloud Storage redirect to external domain
- Sublime MQL Link: Google Translate (unsolicited)
- Sublime MQL Link: Multistage landing - ClickUp abuse
- Sublime MQL Link: Multistage landing - FreshDesk knowledge base abuse
- Sublime MQL Link: Observed malicious URL path /redirect/redirect/
- Sublime MQL Link: QR code in EML attachment with credential phishing indicators
- Sublime MQL Link: Referrer anonymization service from untrusted sender
- Sublime MQL Link: URL path containing /moni/index
- Sublime MQL Link: URL redirecting to blob URL
- Sublime MQL Link: URL shortener chaining to workers.dev redirect
- Sublime MQL Low reputation link to auto-downloaded HTML file with smuggling indicators
- Sublime MQL Open redirect (go2.aspx) leading to Microsoft credential phishing
- Sublime MQL Open redirect: adnxs.com
- Sublime MQL Open redirect: agena-smile.com
- Sublime MQL Open redirect: amaterasu-for-website-5.com
- Sublime MQL Open redirect: api.spently.com
- Sublime MQL Open redirect: Artisteer
- Sublime MQL Open redirect: artkaderne
- Sublime MQL Open Redirect: asemailmgmteu.com
- Sublime MQL Open redirect: astroarts.co.jp
- Sublime MQL Open redirect: Atdmt
- Sublime MQL Open redirect: Avast
- Sublime MQL Open redirect: bananaguide.com
- Sublime MQL Open redirect: bangkoksync.com
- Sublime MQL Open redirect: bestdeals.today
- Sublime MQL Open redirect: Bitrix24 URL Path
- Sublime MQL Open redirect: BMW USA
- Sublime MQL Open redirect: bubblelife.com
- Sublime MQL Open redirect: buildingengines.com
- Sublime MQL Open redirect: business.google.com website_shared URL Param
- Sublime MQL Open redirect: Cartoon Network
- Sublime MQL Open redirect: chkc.com.hk
- Sublime MQL Open redirect: City of Calgary
- Sublime MQL Open redirect: Club-OS
- Sublime MQL Open redirect: convertcart.com
- Sublime MQL Open redirect: Dell
- Sublime MQL Open redirect: designsori.com
- Sublime MQL Open redirect: Diesel.az
- Sublime MQL Open redirect: documentmailbox.com
- Sublime MQL Open redirect: Doubleclick.net
- Sublime MQL Open redirect: eaoko.org
- Sublime MQL Open redirect: easycamp.com
- Sublime MQL Open redirect: embluemail.com
- Sublime MQL Open redirect: emlakarsa
- Sublime MQL Open redirect: emp.eduyield.com
- Sublime MQL Open redirect: eodcnetworkdirect.com
- Sublime MQL Open redirect: events.csiro.au
- Sublime MQL Open redirect: ExacTag
- Sublime MQL Open redirect: fenc.com
- Sublime MQL Open redirect: g7.fr
- Sublime MQL Open redirect: giving.lluh.org
- Sublime MQL Open redirect: Google Ad Services
- Sublime MQL Open Redirect: Google domain with /url path and suspicious indicators
- Sublime MQL Open redirect: Google Web Light
- Sublime MQL Open redirect: Hakumonkai.org
- Sublime MQL Open redirect: HHS
- Sublime MQL Open redirect: ijf.org
- Sublime MQL Open redirect: Indeed
- Sublime MQL Open redirect: IndiaTimes
- Sublime MQL Open redirect: isadatalab.com
- Sublime MQL Open redirect: JustPaste.it
- Sublime MQL Open redirect: k-mil.net
- Sublime MQL Open redirect: Klaviyo
- Sublime MQL Open redirect: labcluster.com
- Sublime MQL Open redirect: LearningApps
- Sublime MQL Open redirect: Linkedin
- Sublime MQL Open redirect: LinkedIn Redirect
- Sublime MQL Open redirect: listing.ca
- Sublime MQL Open redirect: magic4media.com
- Sublime MQL Open redirect: magiccity.ne.jp
- Sublime MQL Open redirect: magneticmarketing.com
- Sublime MQL Open redirect: mail.spiceworks.com
- Sublime MQL Open redirect: Mailtrack Korea
- Sublime MQL Open redirect: marketing.edinburghairport.com
- Sublime MQL Open redirect: McGill University
- Sublime MQL Open redirect: Medium
- Sublime MQL Open redirect: Meta --> YouTube Redirection Chain
- Sublime MQL Open redirect: mindmixer.com
- Sublime MQL Open redirect: MSN
- Sublime MQL Open redirect: museepicassoparis.fr
- Sublime MQL Open redirect: Nested Doubleclick.net
- Sublime MQL Open redirect: Newegg
- Sublime MQL Open redirect: next2.io
- Sublime MQL Open redirect: nowlifestyle.com
- Sublime MQL Open redirect: obunsha.co.jp
- Sublime MQL Open redirect: Panera Bread
- Sublime MQL Open redirect: people.anuneo.com
- Sublime MQL Open redirect: phoenixartstudio.net
- Sublime MQL Open redirect: PIRL San Diego
- Sublime MQL Open redirect: plasticsurgery.or.kr
- Sublime MQL Open redirect: pmifunds.com
- Sublime MQL Open redirect: predictiveresponse.net
- Sublime MQL Open redirect: PremierBet
- Sublime MQL Open redirect: qrxtech.com
- Sublime MQL Open redirect: queue.swytchbike.com
- Sublime MQL Open redirect: radiopublic.com
- Sublime MQL Open redirect: Recipient address embedded in redirect URL pointing to newly registered domain
- Sublime MQL Open redirect: retailrocket.net
- Sublime MQL Open redirect: ringaraja.net
- Sublime MQL Open redirect: Samsung
- Sublime MQL Open redirect: sciencebuddies.org
- Sublime MQL Open redirect: secondstreetapp.com
- Sublime MQL Open redirect: Shibboleth SSO Logout Return Parameter
- Sublime MQL Open redirect: shoppermeet.net
- Sublime MQL Open redirect: shoppingwebapi.didatravel.com
- Sublime MQL Open redirect: Signature Travel Network
- Sublime MQL Open redirect: Slack
- Sublime MQL Open redirect: slubnaglowie.pl
- Sublime MQL Open redirect: smartadserver.com
- Sublime MQL Open redirect: smore.com
- Sublime MQL Open redirect: Snapchat
- Sublime MQL Open redirect: social.bigpress.net
- Sublime MQL Open redirect: ssg-financial.com
- Sublime MQL Open redirect: stats.lib.pdx.edu
- Sublime MQL Open redirect: storematch.jp
- Sublime MQL Open redirect: Ticketmaster
- Sublime MQL Open redirect: TikTok
- Sublime MQL Open redirect: tkqlhce.com
- Sublime MQL Open redirect: tuttocauzioni.it
- Sublime MQL Open redirect: typedrawers.com
- Sublime MQL Open redirect: U.S. Antarctic Program Data Center (USAP-DC)
- Sublime MQL Open redirect: unitedwaynwvt.org
- Sublime MQL Open redirect: ust.hk
- Sublime MQL Open redirect: vconfex.com
- Sublime MQL Open redirect: VK
- Sublime MQL Open redirect: weblinkconnect.com
- Sublime MQL Open redirect: whitefox.pl
- Sublime MQL Open redirect: Xfinity CMP Redirection to Google AMP
- Sublime MQL Open redirect: xfinity.com
- Sublime MQL Open redirect: YouTube
- Sublime MQL Open redirect: YouTube --> Google Redirection Chain
- Sublime MQL Service abuse: Formester with suspicious link behavior
- Sublime MQL Service abuse: Google application integration redirecting to suspicious hosts
- Sublime MQL Service abuse: Google OAuth with suspicious redirect destination
- Sublime MQL Service abuse: Google Tag Manager debug cookie clearing with open redirect potential
- Sublime MQL Service abuse: Meetup.com redirect with brand impersonation
- Sublime MQL Service abuse: Mimecast URL with excessive path length
- Sublime MQL Service abuse: Wix redirect through bulk mailer domains
Out of band pivot 8 rules
- Sublime MQL Benefits enrollment impersonation
- Sublime MQL Credential Phishing via Dropbox comment abuse
- Sublime MQL HR impersonation via e-sign agreement comment
- Sublime MQL Impersonation: IT Department mailbox storage alert
- Sublime MQL Link: chatbot.page platform abuse
- Sublime MQL Link: Direct link to Dropbox Paper file
- Sublime MQL Service abuse: Adobe share containing newly observed email address domain
- Sublime MQL Service abuse: Postman reply-to mismatch with credential theft intent
PDF 71 rules
- Sublime MQL Attachment: Adobe Sign lure PDF with embedded banner images
- Sublime MQL Attachment: Canva PDF with susupicious author metadata
- Sublime MQL Attachment: Compensation review lure with QR code
- Sublime MQL Attachment: Decoy PDF author (Julie P.)
- Sublime MQL Attachment: DocuSign impersonation via PDF linking to new domain
- Sublime MQL Attachment: Encrypted PDF With Credential Harvesting Indicators
- Sublime MQL Attachment: Encrypted PDF with credential theft body
- Sublime MQL Attachment: Encrypted PDF with credential theft language in EML
- Sublime MQL Attachment: Fake PDF Invoices Yara
- Sublime MQL Attachment: Fake scan-to-email
- Sublime MQL Attachment: Fake voicemail via PDF
- Sublime MQL Attachment: Finance themed PDF with observed phishing template
- Sublime MQL Attachment: Identity Confirmation With Document Unlock Code
- Sublime MQL Attachment: Legal themed message or PDF with suspicious indicators
- Sublime MQL Attachment: Microsoft impersonation via PDF with link and suspicious language
- Sublime MQL Attachment: Microsoft OAuth credential harvesting via EML with embedded malicious links
- Sublime MQL Attachment: Password-protected PDF with fake document indicators
- Sublime MQL Attachment: PDF Attachment with links to workers.dev
- Sublime MQL Attachment: PDF bid/proposal lure with credential theft indicators
- Sublime MQL Attachment: PDF contains W9 or invoice YARA signatures
- Sublime MQL Attachment: PDF generated with wkhtmltopdf tool and default title
- Sublime MQL Attachment: PDF Object Hash associated with fake Canada Revenue Agency documents
- Sublime MQL Attachment: PDF proposal with credential theft indicators
- Sublime MQL Attachment: PDF with a suspicious string and single URL
- Sublime MQL Attachment: PDF with blurry lure image
- Sublime MQL Attachment: PDF with credential theft language and invalid reply-to domain
- Sublime MQL Attachment: PDF with credential theft language and link to a free subdomain (unsolicited)
- Sublime MQL Attachment: PDF with eCheckRun lures
- Sublime MQL Attachment: PDF with localhost IP in EXIF title metadata
- Sublime MQL Attachment: PDF with Microsoft Purview message impersonation
- Sublime MQL Attachment: PDF with multistage landing - ClickUp abuse
- Sublime MQL Attachment: PDF with password in filename matching body text
- Sublime MQL Attachment: PDF with personal Microsoft OneNote URL
- Sublime MQL Attachment: PDF with QR code containing recipient-specific credential theft content
- Sublime MQL Attachment: PDF with quote lure
- Sublime MQL Attachment: PDF with recipient email in link
- Sublime MQL Attachment: PDF with ReportLab library and default metadata
- Sublime MQL Attachment: PDF With SAI Global ISO9001 Logo
- Sublime MQL Attachment: PDF with secure document acknowledgment prompt
- Sublime MQL Attachment: PDF with self-service platform links with self sender or blank recipients
- Sublime MQL Attachment: PDF with specific author metadata
- Sublime MQL Attachment: PDF with split QR code
- Sublime MQL Attachment: PDF with suspicious HeadlessChrome metadata
- Sublime MQL Attachment: PDF with suspicious language and redirect to suspicious file type
- Sublime MQL Attachment: PDF with suspicious link and action-oriented language
- Sublime MQL Attachment: PDF with suspicious view document characteristics
- Sublime MQL Attachment: QR code link with base64-encoded recipient address
- Sublime MQL Attachment: QR code with userinfo portion
- Sublime MQL Attachment: Self-sender PDF with minimal content and view prompt
- Sublime MQL Attachment: Single-page PDF with S3-hosted HTML link
- Sublime MQL Attachment: Soda PDF producer with encryption themes
- Sublime MQL Attachment: Suspicious employee policy update document lure
- Sublime MQL Attachment: Suspicious PDF created with headless browser
- Sublime MQL Brand impersonation: Adobe (QR code)
- Sublime MQL Brand impersonation: Adobe Acrobat Sign PDF phishing file format template
- Sublime MQL Brand impersonation: DocuSign (QR code)
- Sublime MQL Brand impersonation: DocuSign PDF attachment with suspicious link
- Sublime MQL Brand Impersonation: Google (QR Code)
- Sublime MQL Brand impersonation: Microsoft (QR code)
- Sublime MQL Brand impersonation: SharePoint PDF attachment with credential theft language
- Sublime MQL Credential phishing: Tax form impersonation with payment request
- Sublime MQL Link: PDF display text with fake copyright claim template
- Sublime MQL Link: PDF file disguised as HTML page
- Sublime MQL Link: PDF filename impersonation with credential theft language
- Sublime MQL Link: SharePoint OneNote or PDF link with self sender behavior
- Sublime MQL Link: Uncommon SharePoint document type with sender's display name
- Sublime MQL Sharepoint link likely unrelated to sender
- Sublime MQL Suspicious attachment with unscannable Cloudflare link
- Sublime MQL Suspicious attachment: Duplicate decoy PDF files
- Sublime MQL Suspicious SharePoint file sharing
- Sublime MQL URLhaus: Malicious domain in message body or pdf attachment (trusted reporters)
Punycode 2 rules
- Sublime MQL Link to a domain with punycode characters
- Sublime MQL Punycode sender domain
QR code 30 rules
- Sublime MQL Attachment: Compensation review lure with QR code
- Sublime MQL Attachment: Compensation-themed DOCX with QR code credential theft
- Sublime MQL Attachment: EML with QR code redirecting to Cloudflare challenges
- Sublime MQL Attachment: Fake voicemail via PDF
- Sublime MQL Attachment: HTML smuggling - QR Code with suspicious links
- Sublime MQL Attachment: ICS calendar file with QR code containing recipient email address
- Sublime MQL Attachment: PDF with QR code containing recipient-specific credential theft content
- Sublime MQL Attachment: PDF with recipient email in link
- Sublime MQL Attachment: PDF with split QR code
- Sublime MQL Attachment: QR code link with base64-encoded recipient address
- Sublime MQL Attachment: QR code with credential phishing indicators
- Sublime MQL Attachment: QR code with encoded recipient targeting and redirect indicators
- Sublime MQL Attachment: QR code with recipient targeting and special characters
- Sublime MQL Attachment: QR code with suspicious URL patterns in EML file
- Sublime MQL Attachment: QR code with userinfo portion
- Sublime MQL Attachment: SVG files with evasion elements
- Sublime MQL Brand impersonation: Adobe (QR code)
- Sublime MQL Brand impersonation: DocuSign (QR code)
- Sublime MQL Brand impersonation: DocuSign with embedded QR code
- Sublime MQL Brand Impersonation: Google (QR Code)
- Sublime MQL Brand impersonation: Microsoft (QR code)
- Sublime MQL Compensation review with QR code in attached EML
- Sublime MQL Link: QR code in EML attachment with credential phishing indicators
- Sublime MQL Link: QR code with phishing disposition in img or pdf
- Sublime MQL Link: QR Code with suspicious language (untrusted sender)
- Sublime MQL Open redirect: typedrawers.com
- Sublime MQL QR Code with suspicious indicators
- Sublime MQL Service abuse: Microsoft Forms Pro with suspicious links or QR codes
- Sublime MQL Service abuse: Monday.com infrastructure with phishing intent
- Sublime MQL Service abuse: Square marketing with suspicious QR code
Scripting 41 rules
- Sublime MQL Attachment: CVE-2025-24071 - Microsoft Windows File Explorer Spoofing Vulnerability
- Sublime MQL Attachment: Double base64-encoded zip file in HTML smuggling attachment
- Sublime MQL Attachment: EML containing a base64 encoded script
- Sublime MQL Attachment: EML with embedded Javascript in SVG file
- Sublime MQL Attachment: HTML attachment with Javascript location
- Sublime MQL Attachment: HTML attachment with login portal indicators
- Sublime MQL Attachment: HTML file contains exclusively Javascript
- Sublime MQL Attachment: HTML file with excessive 'const' declarations and abnormally long timeouts
- Sublime MQL Attachment: HTML file with reference to recipient and suspicious patterns
- Sublime MQL Attachment: HTML smuggling 'body onload' linking to suspicious destination
- Sublime MQL Attachment: HTML smuggling 'body onload' with high entropy and suspicious text
- Sublime MQL Attachment: HTML smuggling with atob and high entropy
- Sublime MQL Attachment: HTML smuggling with atob and high entropy via calendar invite
- Sublime MQL Attachment: HTML smuggling with auto-downloaded file
- Sublime MQL Attachment: HTML smuggling with base64 encoded JavaScript function
- Sublime MQL Attachment: HTML smuggling with base64 encoded ZIP file
- Sublime MQL Attachment: HTML smuggling with concatenation obfuscation
- Sublime MQL Attachment: HTML smuggling with decimal encoding
- Sublime MQL Attachment: HTML smuggling with eval and atob
- Sublime MQL Attachment: HTML smuggling with eval and atob via calendar invite
- Sublime MQL Attachment: HTML smuggling with excessive line break obfuscation
- Sublime MQL Attachment: HTML smuggling with excessive string concatenation and suspicious patterns
- Sublime MQL Attachment: HTML smuggling with fromCharCode and other signals
- Sublime MQL Attachment: HTML smuggling with RC4 decryption
- Sublime MQL Attachment: HTML smuggling with ROT13
- Sublime MQL Attachment: HTML smuggling with setTimeout
- Sublime MQL Attachment: HTML smuggling with unescape
- Sublime MQL Attachment: HTML with emoji-to-character map
- Sublime MQL Attachment: HTML with hidden body
- Sublime MQL Attachment: HTML with JavaScript functions for HTTP requests
- Sublime MQL Attachment: HTML with obfuscation and recipient's email in JavaScript strings
- Sublime MQL Attachment: ICS with embedded Javascript in SVG file
- Sublime MQL Attachment: Macro files containing MHT content
- Sublime MQL Attachment: Microsoft impersonation via PDF with link and suspicious language
- Sublime MQL Credential theft: JavaScript date manipulation in HTML body
- Sublime MQL HTML smuggling containing recipient email address
- Sublime MQL HTML: Bidirectional (BIDI) HTML override with right to left obfuscation
- Sublime MQL Link: JavaScript obfuscation with Telegram bot integration
- Sublime MQL Link: Suspicious recipient with timeout redirect
- Sublime MQL Suspected cross-site scripting (XSS) found in subject
- Sublime MQL Suspected WordPress abuse with cross-site scripting (XSS) indicators
Service abuse 1 rule
Social engineering 500 rules
- Sublime MQL Abuse: Cloudflare Workers Hosted EvilTokens Domain Structure
- Sublime MQL Abuse: Robinhood injected content
- Sublime MQL Attachment: Archive containing HTML file with file scheme link
- Sublime MQL Attachment: Calendar invite with Google redirect and invoice request
- Sublime MQL Attachment: Compensation review lure with QR code
- Sublime MQL Attachment: Compensation-themed DOCX with QR code credential theft
- Sublime MQL Attachment: DocuSign impersonation via PDF linking to new domain
- Sublime MQL Attachment: DOCX with hyperlink targeting recipient address
- Sublime MQL Attachment: Dropbox image lure with no Dropbox domains in links
- Sublime MQL Attachment: EML containing a base64 encoded script
- Sublime MQL Attachment: EML with link to credential phishing page
- Sublime MQL Attachment: EML with SharePoint files shared from GoDaddy federated tenants
- Sublime MQL Attachment: EML with Sharepoint link likely unrelated to sender
- Sublime MQL Attachment: EML with suspicious indicators
- Sublime MQL Attachment: Encrypted PDF with credential theft body
- Sublime MQL Attachment: Encrypted PDF with credential theft language in EML
- Sublime MQL Attachment: Excel file with document sharing lure created by Go Excelize
- Sublime MQL Attachment: Fake attachment image lure
- Sublime MQL Attachment: Fake PDF Invoices Yara
- Sublime MQL Attachment: Fake scan-to-email
- Sublime MQL Attachment: Fake secure message and suspicious indicators
- Sublime MQL Attachment: Fake voicemail via PDF
- Sublime MQL Attachment: HTML smuggling Microsoft sign in
- Sublime MQL Attachment: HTML smuggling with excessive string concatenation and suspicious patterns
- Sublime MQL Attachment: HTML with emoji-to-character map
- Sublime MQL Attachment: ICS calendar file with base64 encoded recipient address in URL parameters
- Sublime MQL Attachment: ICS calendar file with QR code containing recipient email address
- Sublime MQL Attachment: ICS calendar file with recipient address in UID field
- Sublime MQL Attachment: ICS calendar file with suspicious product identifier
- Sublime MQL Attachment: ICS calendar file with suspicious UID domain
- Sublime MQL Attachment: ICS file with links to newly registered domains
- Sublime MQL Attachment: ICS file with meeting prefix
- Sublime MQL Attachment: ICS with employee policy review lure
- Sublime MQL Attachment: Identity Confirmation With Document Unlock Code
- Sublime MQL Attachment: Legal themed message or PDF with suspicious indicators
- Sublime MQL Attachment: Link to Doubleclick.net open redirect
- Sublime MQL Attachment: Microsoft 365 credential phishing
- Sublime MQL Attachment: Microsoft impersonation via PDF with link and suspicious language
- Sublime MQL Attachment: Microsoft SharePoint Impersonation via images in macro-enabled attachment
- Sublime MQL Attachment: Office file contains OLE relationship to credential phishing page
- Sublime MQL Attachment: Office file with credential phishing URLs
- Sublime MQL Attachment: Office file with document sharing and browser instruction lures
- Sublime MQL Attachment: PDF bid/proposal lure with credential theft indicators
- Sublime MQL Attachment: PDF contains W9 or invoice YARA signatures
- Sublime MQL Attachment: PDF proposal with credential theft indicators
- Sublime MQL Attachment: PDF with a suspicious string and single URL
- Sublime MQL Attachment: PDF with credential theft language and invalid reply-to domain
- Sublime MQL Attachment: PDF with credential theft language and link to a free subdomain (unsolicited)
- Sublime MQL Attachment: PDF with Microsoft Purview message impersonation
- Sublime MQL Attachment: PDF with multistage landing - ClickUp abuse
- Sublime MQL Attachment: PDF with personal Microsoft OneNote URL
- Sublime MQL Attachment: PDF with QR code containing recipient-specific credential theft content
- Sublime MQL Attachment: PDF with quote lure
- Sublime MQL Attachment: PDF with recipient email in link
- Sublime MQL Attachment: PDF with secure document acknowledgment prompt
- Sublime MQL Attachment: PDF with suspicious link and action-oriented language
- Sublime MQL Attachment: PDF with suspicious view document characteristics
- Sublime MQL Attachment: QR code link with base64-encoded recipient address
- Sublime MQL Attachment: QR code with credential phishing indicators
- Sublime MQL Attachment: QR code with recipient targeting and special characters
- Sublime MQL Attachment: QR code with suspicious URL patterns in EML file
- Sublime MQL Attachment: RFC822 containing suspicious file sharing language with links from untrusted sender
- Sublime MQL Attachment: Self-sender PDF with minimal content and view prompt
- Sublime MQL Attachment: Small text file with link containing recipient email address
- Sublime MQL Attachment: Soda PDF producer with encryption themes
- Sublime MQL Attachment: Suspicious employee policy update document lure
- Sublime MQL Attachment: Targeted DOCX with personalized recipient acknowledgement lure
- Sublime MQL Benefits enrollment impersonation
- Sublime MQL Body HTML: Recipient SLD in HTML class
- Sublime MQL Body: CSS clamp() font obfuscation with IP-based links
- Sublime MQL Body: Embedded email headers indicative of thread hijacking/abuse
- Sublime MQL Body: Fake secure email portal with HTML obfuscation
- Sublime MQL Body: HTML whitespace stuffing with short initial message
- Sublime MQL Body: Invisible Unicode obfuscation student loan callback phishing
- Sublime MQL Body: Suspicious date format
- Sublime MQL Body: Suspicious table template fingerprint
- Sublime MQL Brand impersonation: AARP
- Sublime MQL Brand impersonation: Adobe Sign with suspicious indicators
- Sublime MQL Brand impersonation: Adobe with suspicious language and link
- Sublime MQL Brand impersonation: ADP
- Sublime MQL Brand impersonation: AliExpress
- Sublime MQL Brand impersonation: Amazon
- Sublime MQL Brand impersonation: Amazon Web Services (AWS)
- Sublime MQL Brand impersonation: Amazon with suspicious attachment
- Sublime MQL Brand impersonation: American Express (AMEX)
- Sublime MQL Brand impersonation: Apple
- Sublime MQL Brand impersonation: Aquent
- Sublime MQL Brand impersonation: AuthentiSign
- Sublime MQL Brand impersonation: Automobile assistance associations
- Sublime MQL Brand impersonation: Bank of America
- Sublime MQL Brand impersonation: Barracuda Networks
- Sublime MQL Brand impersonation: Bids & Tenders
- Sublime MQL Brand impersonation: Binance
- Sublime MQL Brand impersonation: Blockchain.com
- Sublime MQL Brand impersonation: Booking.com
- Sublime MQL Brand impersonation: Box file sharing service
- Sublime MQL Brand impersonation: Canada Revenue Agency
- Sublime MQL Brand impersonation: Capital One
- Sublime MQL Brand impersonation: Charles Schwab
- Sublime MQL Brand impersonation: Chase Bank
- Sublime MQL Brand impersonation: Chase bank with credential phishing indicators
- Sublime MQL Brand impersonation: Cloud services with credential theft intent
- Sublime MQL Brand impersonation: Coinbase
- Sublime MQL Brand impersonation: Dashlane
- Sublime MQL Brand impersonation: DHL
- Sublime MQL Brand impersonation: DigitalOcean
- Sublime MQL Brand impersonation: Discord notification
- Sublime MQL Brand Impersonation: Disney
- Sublime MQL Brand impersonation: DocSend
- Sublime MQL Brand impersonation: DocuSign
- Sublime MQL Brand impersonation: DocuSign (QR code)
- Sublime MQL Brand impersonation: DocuSign branded attachment lure with no DocuSign links
- Sublime MQL Brand impersonation: DocuSign PDF attachment with suspicious link
- Sublime MQL Brand impersonation: DoorDash
- Sublime MQL Brand impersonation: Dotloop
- Sublime MQL Brand impersonation: Dropbox
- Sublime MQL Brand impersonation: Enbridge
- Sublime MQL Brand impersonation: Evite
- Sublime MQL Brand impersonation: Exodus
- Sublime MQL Brand impersonation: Fake DocuSign HTML table not linking to DocuSign domains
- Sublime MQL Brand impersonation: Fake Fax
- Sublime MQL Brand impersonation: Fastway
- Sublime MQL Brand impersonation: FedEx
- Sublime MQL Brand impersonation: Figma with malicious document access overlay
- Sublime MQL Brand impersonation: File sharing notification with template artifacts
- Sublime MQL Brand impersonation: FINRA
- Sublime MQL Brand Impersonation: Gemini Trust Company
- Sublime MQL Brand impersonation: Github
- Sublime MQL Brand impersonation: GoDaddy
- Sublime MQL Brand impersonation: Google Careers
- Sublime MQL Brand impersonation: Google Drive fake file share
- Sublime MQL Brand impersonation: Google fake sign-in warning
- Sublime MQL Brand impersonation: Google Meet with malicious link
- Sublime MQL Brand impersonation: Google using Microsoft Forms
- Sublime MQL Brand impersonation: Google Workspace alert notification
- Sublime MQL Brand impersonation: Government / Tax Authority document lure
- Sublime MQL Brand impersonation: Greenvelope
- Sublime MQL Brand impersonation: Gusto
- Sublime MQL Brand impersonation: Hulu
- Sublime MQL Brand impersonation: Internal Revenue Service
- Sublime MQL Brand impersonation: KnowBe4
- Sublime MQL Brand impersonation: LastPass
- Sublime MQL Brand impersonation: Ledger
- Sublime MQL Brand impersonation: LinkedIn
- Sublime MQL Brand impersonation: Mailchimp
- Sublime MQL Brand impersonation: Marriott with gift language
- Sublime MQL Brand impersonation: McAfee
- Sublime MQL Brand impersonation: Meta and subsidiaries
- Sublime MQL Brand impersonation: MetaMask
- Sublime MQL Brand impersonation: Microsoft
- Sublime MQL Brand impersonation: Microsoft (QR code)
- Sublime MQL Brand impersonation: Microsoft fake sign-in alert
- Sublime MQL Brand impersonation: Microsoft logo in HTML with fake quarantine release notification
- Sublime MQL Brand impersonation: Microsoft Planner with suspicious link
- Sublime MQL Brand impersonation: Microsoft quarantine release notification in body
- Sublime MQL Brand impersonation: Microsoft quarantine release notification in image attachment
- Sublime MQL Brand impersonation: Microsoft Teams
- Sublime MQL Brand impersonation: Microsoft Teams invitation
- Sublime MQL Brand impersonation: Microsoft with embedded logo and credential theft language
- Sublime MQL Brand impersonation: Microsoft with low reputation links
- Sublime MQL Brand impersonation: Morgan Stanley
- Sublime MQL Brand impersonation: Navan
- Sublime MQL Brand impersonation: Netflix
- Sublime MQL Brand impersonation: Norton
- Sublime MQL Brand impersonation: Office 365 mail service
- Sublime MQL Brand impersonation: Okta
- Sublime MQL Brand Impersonation: OpenAI with ChatGPT Ads lure
- Sublime MQL Brand impersonation: OpenAI with payment issues
- Sublime MQL Brand impersonation: Outlook
- Sublime MQL Brand Impersonation: PayPal
- Sublime MQL Brand impersonation: PNC
- Sublime MQL Brand Impersonation: Procore
- Sublime MQL Brand impersonation: Proofpoint secure messaging without legitimate indicators
- Sublime MQL Brand impersonation: Punchbowl
- Sublime MQL Brand impersonation: Purdue ePlanroom with suspicious links
- Sublime MQL Brand impersonation: Quickbooks
- Sublime MQL Brand impersonation: QuickBooks notification from Intuit themed company name
- Sublime MQL Brand impersonation: Ripple
- Sublime MQL Brand impersonation: Robert Half
- Sublime MQL Brand impersonation: Robinhood
- Sublime MQL Brand impersonation: SendGrid
- Sublime MQL Brand impersonation: Sharepoint
- Sublime MQL Brand impersonation: Sharepoint fake file share
- Sublime MQL Brand impersonation: SharePoint PDF attachment with credential theft language
- Sublime MQL Brand Impersonation: Shein
- Sublime MQL Brand impersonation: Silicon Valley Bank
- Sublime MQL Brand impersonation: SiriusXM
- Sublime MQL Brand impersonation: Social Security Administration
- Sublime MQL Brand impersonation: SoFi
- Sublime MQL Brand impersonation: Spotify
- Sublime MQL Brand impersonation: Square
- Sublime MQL Brand impersonation: Squarespace
- Sublime MQL Brand impersonation: State Farm
- Sublime MQL Brand impersonation: Stellar Development Foundation (SDF)
- Sublime MQL Brand Impersonation: Stripe
- Sublime MQL Brand impersonation: Stripe notification
- Sublime MQL Brand impersonation: Sublime Security
- Sublime MQL Brand impersonation: Survey request with credential theft indicators
- Sublime MQL Brand impersonation: TikTok
- Sublime MQL Brand impersonation: Toronto-Dominion Bank
- Sublime MQL Brand impersonation: Trust Wallet
- Sublime MQL Brand impersonation: TurboTax
- Sublime MQL Brand impersonation: Twitter
- Sublime MQL Brand impersonation: UK government Home Office
- Sublime MQL Brand impersonation: ukr[.]net
- Sublime MQL Brand impersonation: United Healthcare
- Sublime MQL Brand impersonation: UPS
- Sublime MQL Brand impersonation: USPS
- Sublime MQL Brand impersonation: Vanta
- Sublime MQL Brand impersonation: Venmo
- Sublime MQL Brand impersonation: Wells Fargo
- Sublime MQL Brand impersonation: Wise
- Sublime MQL Brand impersonation: Wix
- Sublime MQL Brand impersonation: Xodo Sign
- Sublime MQL Brand impersonation: Zoom
- Sublime MQL Brand impersonation: Zoom (strict)
- Sublime MQL Brand impersonation: Zoom via HTML styling
- Sublime MQL Brand impersonation: Zoom via lookalike domain
- Sublime MQL Canva design with suspicious embedded link
- Sublime MQL ClickFunnels link infrastructure abuse
- Sublime MQL Cloud storage impersonation with credential theft indicators
- Sublime MQL Commonly abused sender TLD with engaging language
- Sublime MQL Compensation review with QR code in attached EML
- Sublime MQL Constant Contact link infrastructure abuse
- Sublime MQL Credential phishing content and link (untrusted sender)
- Sublime MQL Credential phishing language and suspicious indicators (unknown sender)
- Sublime MQL Credential phishing link (unknown sender)
- Sublime MQL Credential Phishing via Dropbox comment abuse
- Sublime MQL Credential phishing: 'Secure message' and engaging language
- Sublime MQL Credential phishing: AWS Lambda URL with recipient targeting
- Sublime MQL Credential phishing: Blue button styled link with file-sharing template artifacts
- Sublime MQL Credential phishing: DocuSign embedded image lure with no DocuSign domains in links
- Sublime MQL Credential phishing: Email delivery failure impersonation
- Sublime MQL Credential phishing: Engaging language and other indicators (untrusted sender)
- Sublime MQL Credential phishing: Fake card notification with tracking lure
- Sublime MQL Credential phishing: Fake password expiration from new and unsolicited sender
- Sublime MQL Credential phishing: Fake storage alerts (unsolicited)
- Sublime MQL Credential phishing: Financial lure via ActiveCampaign infrastructure
- Sublime MQL Credential phishing: Generic document share with unicode and proceedural greeting template
- Sublime MQL Credential phishing: Generic document sharing
- Sublime MQL Credential phishing: Hyper-linked image leading to free file host
- Sublime MQL Credential phishing: Onedrive impersonation
- Sublime MQL Credential phishing: Personalized document signing request
- Sublime MQL Credential phishing: Re-Authentication lure
- Sublime MQL Credential phishing: Suspicious e-sign agreement document notification
- Sublime MQL Credential phishing: Suspicious subject with urgent financial request and link
- Sublime MQL Credential phishing: Tax form impersonation with payment request
- Sublime MQL Credential Phishing: W-2 lure with inline SVG Windows logo
- Sublime MQL Credential theft with 'safe content' deception and social engineering topics
- Sublime MQL Credential theft: JavaScript date manipulation in HTML body
- Sublime MQL Cyrillic vowel substitution in subject or display name from unknown sender
- Sublime MQL Cyrillic vowel substitutions with suspicious subject from unknown sender
- Sublime MQL Deceptive Dropbox mention
- Sublime MQL Display name and subject impersonation using recipient SLD (new sender)
- Sublime MQL Display name impersonation using recipient SLD
- Sublime MQL Domain impersonation: Freemail reply-to local lookalike with financial request
- Sublime MQL EML attachment with credential theft language (unknown sender)
- Sublime MQL Fake email quarantine notification
- Sublime MQL Fake message thread with a suspicious link and engaging language from an unknown sender
- Sublime MQL Fake scan-to-email message
- Sublime MQL Fake thread with suspicious indicators
- Sublime MQL Fake voicemail notification (untrusted sender)
- Sublime MQL Fake warning banner using confusable characters
- Sublime MQL Fake Zoho Sign template abuse
- Sublime MQL Fake Zoom meeting invite with suspicious link
- Sublime MQL Free email provider sender with mismatched provider reply-to
- Sublime MQL Free subdomain link with login or captcha (untrusted sender)
- Sublime MQL Generic service abuse from newly registered domain
- Sublime MQL Google Drive direct download link from unsolicited sender
- Sublime MQL Google Notification alert link from non-Google sender
- Sublime MQL Google presentation open redirect phishing
- Sublime MQL Hardbacon infrastructure abuse
- Sublime MQL Headers: Fake in-reply-to with wildcard sender and missing thread context
- Sublime MQL Headers: Invalid recipient domain with mismatched reply-to from new sender
- Sublime MQL Headers: System account impersonation with empty sender address
- Sublime MQL HR impersonation via e-sign agreement comment
- Sublime MQL HTML content with print styling and credential theft language
- Sublime MQL HTML: Bidirectional (BIDI) HTML override with right to left obfuscation
- Sublime MQL HTML: Template placeholders or recipient email in element class attributes
- Sublime MQL Image as content with a link to an open redirect
- Sublime MQL Impersonation using recipient domain (untrusted sender)
- Sublime MQL Impersonation: Human Resources with link or attachment and engaging language
- Sublime MQL Impersonation: Internal corporate services
- Sublime MQL Impersonation: IT Department mailbox storage alert
- Sublime MQL Impersonation: Recipient organization in sender display name with credential theft image
- Sublime MQL Impersonation: Salesforce fake campaign failure notification
- Sublime MQL Impersonation: SAM/SBA federal registration
- Sublime MQL Impersonation: SharePoint reply header anomaly
- Sublime MQL Invoicera infrastructure abuse
- Sublime MQL Issuu document with suspicious embedded link
- Sublime MQL Link abuse: Self-service creation platform link with suspicious recipient behavior
- Sublime MQL Link to Google Apps Script macro (unsolicited)
- Sublime MQL Link to Google Apps Script macro via comment tagging
- Sublime MQL Link: .onion From Unsolicited Sender
- Sublime MQL Link: .su domain link redirection from new sender domains
- Sublime MQL Link: Apple App Store malicious ad manager themed apps from free email provider
- Sublime MQL Link: Base64 encoded recipient address in URL fragment with subject hash
- Sublime MQL Link: Breely link masquerading as PDF
- Sublime MQL Link: chatbot.page platform abuse
- Sublime MQL Link: Compromised WordPress site redirecting to suspicious root domain
- Sublime MQL Link: Concatenated display text concealing duplicate URLs with PDF reference
- Sublime MQL Link: Credential harvesting with excess padding evasion
- Sublime MQL Link: Credential phishing traversing Russian infrastructure
- Sublime MQL Link: Credential phishing via WordPress
- Sublime MQL Link: Credential theft with Cloudflare tunnel and recipient targeting
- Sublime MQL Link: Credential theft with invisible Unicode character in page title from unsolicited sender
- Sublime MQL Link: Direct link to Dropbox Paper file
- Sublime MQL Link: Direct link to Zoom Docs from non-Zoom sender
- Sublime MQL Link: Direct POWR.io Form Builder with suspicious patterns
- Sublime MQL Link: Display text matches subject line
- Sublime MQL Link: Document sharing invitation template
- Sublime MQL Link: Document-themed link to newly registered domain
- Sublime MQL Link: Executable file download with suspicious message content
- Sublime MQL Link: Fake forwarded message with suspicious URL in plain text
- Sublime MQL Link: Fake secure message notification template
- Sublime MQL Link: Figma design deck with credential theft language
- Sublime MQL Link: File sharing impersonation with suspicious language and sending patterns
- Sublime MQL Link: File sharing pretext with suspicious body and link
- Sublime MQL Link: Financial account issue with suspicious indicators
- Sublime MQL Link: Flare-branded credential harvesting via Cloudflare tunnels
- Sublime MQL Link: Fraudulent state business filing notice
- Sublime MQL Link: Free file host link with 'Important Viewing Note' lure
- Sublime MQL Link: Free file host links from suspicious support sender with credential theft language
- Sublime MQL Link: Generic financial document with proceedural timeline template
- Sublime MQL Link: Google Cloud Storage hosted credential harvesting page
- Sublime MQL Link: Google Cloud Storage redirect to external domain
- Sublime MQL Link: Google Cloud Storage with short-path link delivery
- Sublime MQL Link: Google Drawings link from new sender
- Sublime MQL Link: Google Forms link with credential theft language
- Sublime MQL Link: Hotel booking spoofed display URL
- Sublime MQL Link: HR impersonation with suspicious domain indicators and credential theft
- Sublime MQL Link: Intuit link abuse with file share context
- Sublime MQL Link: Invalid reply-to with recipient details in subject, body, and encoded link
- Sublime MQL Link: Job recruitment lure from unsolicited sender with suspicious hosting
- Sublime MQL Link: Mamba 2FA phishing kit
- Sublime MQL Link: Microsoft device code authentication with suspicious indicators
- Sublime MQL Link: Microsoft impersonation using hosted png with suspicious link
- Sublime MQL Link: Microsoft protected message with matching sender and recipient addresses
- Sublime MQL Link: Mismatched free file host links with document lure
- Sublime MQL Link: Multistage landing - Abused Adobe Acrobat hosted PDF
- Sublime MQL Link: Multistage Landing - Abused Buildin.ai
- Sublime MQL Link: Multistage landing - FreshDesk knowledge base abuse
- Sublime MQL Link: Multistage landing - JotForm abuse
- Sublime MQL Link: Multistage landing - Ludus presentation
- Sublime MQL Link: Multistage landing - Microsoft Forms abuse
- Sublime MQL Link: Multistage landing - Published Google Doc
- Sublime MQL Link: Multistage landing - Scribd document
- Sublime MQL Link: Multistage landing - Trello board abuse
- Sublime MQL Link: MyActiveCampaign Link Abuse
- Sublime MQL Link: Observed malicious URL path /redirect/redirect/
- Sublime MQL Link: PDF and financial display text to free file host
- Sublime MQL Link: PDF filename impersonation with credential theft language
- Sublime MQL Link: Personal SharePoint with invalid recipients and credential theft language
- Sublime MQL Link: Personalized URL with recipient address on commonly abused web service
- Sublime MQL Link: QR code with phishing disposition in img or pdf
- Sublime MQL Link: QR Code with suspicious language (untrusted sender)
- Sublime MQL Link: QuickBooks image lure with suspicious link
- Sublime MQL Link: Recipient email address in 'eta' parameter
- Sublime MQL Link: Remittance payment request with timeline template
- Sublime MQL Link: Scribd fullscreen link from suspicious sender
- Sublime MQL Link: Self-sender credential theft with configuration placeholder
- Sublime MQL Link: Self-sender with IP geolocation check and suspicious link behavior
- Sublime MQL Link: Self-sender with sender org in subject and credential theft indicator
- Sublime MQL Link: Self-sent message with quarterly document review request
- Sublime MQL Link: Self-sent PDF lure with subject correlation
- Sublime MQL Link: SharePoint filename matches org name
- Sublime MQL Link: Shortened URL with fragment matching subject
- Sublime MQL Link: Single character path with credential theft body and self sender behavior or invalid recipient
- Sublime MQL Link: Squarespace infrastructure abuse
- Sublime MQL Link: Suspicious Family fragment parameter with encoded recipient data
- Sublime MQL Link: Suspicious file retrieval with recipient targeting
- Sublime MQL Link: Suspicious go.php redirect with document lure
- Sublime MQL Link: Suspicious HTML structure with subject mirrored in body and single link
- Sublime MQL Link: Suspicious Loom HTML file path
- Sublime MQL Link: Suspicious recipient with timeout redirect
- Sublime MQL Link: Suspicious URL with recipient targeting and special characters
- Sublime MQL Link: Suspicious wp-admin path from mismatched sender domain
- Sublime MQL Link: Tax document lure Portuguese/Spanish with suspicious domains
- Sublime MQL Link: Uncommon SharePoint document type with sender's display name
- Sublime MQL Link: Unformatted template with literal placeholder in mailto link
- Sublime MQL Link: Unicode character obfuscation in display name with base64-encoded URL fragment
- Sublime MQL Link: Unsolicited email contains link leading to Tycoon URL structure
- Sublime MQL Link: Unsolicited email contains link to page containing Tycoon URI structure
- Sublime MQL Link: URL fragmented by hidden spans
- Sublime MQL Link: URL scheme obfuscation via split HTML anchors
- Sublime MQL Link: URL shortener chaining to workers.dev redirect
- Sublime MQL Link: URL shortener with copy-paste instructions and credential theft language
- Sublime MQL Link: URL using underscore-dot substitution in display text
- Sublime MQL Link: WordPress admin targeting with recipient identifier in URL parts
- Sublime MQL Link: WordPress login page with Blogspot Binance scam
- Sublime MQL Lookalike sender domain (untrusted sender)
- Sublime MQL Low reputation link to auto-downloaded HTML file with smuggling indicators
- Sublime MQL Mass campaign: recipient address in subject, body, and link (untrusted sender)
- Sublime MQL Microsoft device code phishing
- Sublime MQL Mismatched links: Free file share with urgent language
- Sublime MQL Newly registered sender or reply-to domain with newly registered linked domain
- Sublime MQL Observed IOC: Mail transiting bulletproof host - SmartApe
- Sublime MQL Observed IOC: Mail transiting OFAC-sanctioned bulletproof host Aeza Group
- Sublime MQL Observed IOC: Malicious sender domains
- Sublime MQL Observed IOC: Malicious sender email addresses
- Sublime MQL Observed IOC: Malicious sender root domains
- Sublime MQL Open redirect: City of Calgary
- Sublime MQL Open redirect: giving.lluh.org
- Sublime MQL Open redirect: Klaviyo
- Sublime MQL Open redirect: marketing.edinburghairport.com
- Sublime MQL Open redirect: next2.io
- Sublime MQL Open redirect: people.anuneo.com
- Sublime MQL Open redirect: queue.swytchbike.com
- Sublime MQL Open redirect: Recipient address embedded in redirect URL pointing to newly registered domain
- Sublime MQL Open redirect: slubnaglowie.pl
- Sublime MQL Open redirect: typedrawers.com
- Sublime MQL Potential prompt injection attack in body HTML
- Sublime MQL Punycode sender domain
- Sublime MQL QR Code with suspicious indicators
- Sublime MQL Reconnaissance: Email address harvesting attempt
- Sublime MQL Reconnaissance: Empty subject with mismatched reply-to from new sender
- Sublime MQL Recruitee Infrastructure Abuse
- Sublime MQL Salesforce infrastructure abuse
- Sublime MQL Scam soliciting employer review/rating
- Sublime MQL Self-impersonation: Sender matches recipient with bolded name and suspicious link
- Sublime MQL Self-sender with copy/paste instructions and suspicious domains (French/Français)
- Sublime MQL Self-sent fake PDF attachment with misleading link
- Sublime MQL Sendgrid voicemail phish
- Sublime MQL Service abuse: Adobe Creative Cloud share from an unsolicited sender address
- Sublime MQL Service abuse: Adobe legitimate domain with document approval language
- Sublime MQL Service abuse: Adobe message from newly registered domain
- Sublime MQL Service abuse: Adobe share containing newly observed email address domain
- Sublime MQL Service abuse: AppSheet infrastructure with suspicious indicators
- Sublime MQL Service abuse: Behance document sharing with suspicious language
- Sublime MQL Service Abuse: Box file sharing with credential phishing intent
- Sublime MQL Service abuse: Citrix ShareFile impersonation via Outlook plugin
- Sublime MQL Service abuse: Cognito Forms with short body from unknown sender
- Sublime MQL Service abuse: DocSend share from an unsolicited reply-to address
- Sublime MQL Service abuse: DocSend share from newly registered domain
- Sublime MQL Service abuse: DocuSign share from an unsolicited reply-to address
- Sublime MQL Service abuse: Domains By Proxy sender
- Sublime MQL Service abuse: Dropbox Paper with copy-paste instructions
- Sublime MQL Service abuse: Dropbox share from new domain
- Sublime MQL Service abuse: Evernote link
- Sublime MQL Service Abuse: ExactTarget with suspicious sender indicators
- Sublime MQL Service abuse: Facebook business with action required subject
- Sublime MQL Service abuse: Fake loan/funding verification lure via Mailgun
- Sublime MQL Service abuse: File sharing impersonation with external SharePoint links
- Sublime MQL Service abuse: FlipHTML5 with attachment deception and credential theft language
- Sublime MQL Service abuse: Formester with suspicious link behavior
- Sublime MQL Service abuse: GitHub notification with excessive mentions and suspicious links
- Sublime MQL Service abuse: Google account notification with links to free file host
- Sublime MQL Service abuse: Google Drive share from an unsolicited reply-to address
- Sublime MQL Service abuse: Google Drive share from new reply-to domain
- Sublime MQL Service abuse: Google Firebase sender address with suspicious content
- Sublime MQL Service abuse: Google OAuth with suspicious redirect destination
- Sublime MQL Service abuse: HelloSign from an unsolicited sender address
- Sublime MQL Service abuse: Microsoft Forms Pro with suspicious links or QR codes
- Sublime MQL Service abuse: Microsoft with suspicious indicators in subject
- Sublime MQL Service abuse: Monday.com infrastructure with phishing intent
- Sublime MQL Service abuse: Notion free-tier account impersonating VIP
- Sublime MQL Service abuse: Nylas tracking subdomain with suspicious content
- Sublime MQL Service abuse: Outlook Groups with Google Sites link and evasion tag
- Sublime MQL Service abuse: PayPal manager account creation with callback scam indicators
- Sublime MQL Service abuse: Postman reply-to mismatch with credential theft intent
- Sublime MQL Service abuse: QuickBooks notification from new domain
- Sublime MQL Service abuse: QuickBooks notification with suspicious comments
- Sublime MQL Service abuse: Roomsy with unrelated body content
- Sublime MQL Service abuse: Sendgrid credential theft with personalized request targeting single recipient
- Sublime MQL Service abuse: SendGrid impersonation via Sendgrid from new sender
- Sublime MQL Service abuse: SendGrid-formatted link with actor-controlled fragment
- Sublime MQL Service abuse: SendThisFile with credential theft and financial language
- Sublime MQL Service abuse: Soundestlink.com Microsoft impersonation
- Sublime MQL Service abuse: Substack credential theft with confusable characters and branded button redirects
- Sublime MQL Service abuse: SurveyMonkey survey from newly registered domain
- Sublime MQL Service abuse: SurveyMonkey with suspicious outbound links
- Sublime MQL Service abuse: Suspicious Zoom Docs link
- Sublime MQL Service abuse: Task management message sent via SendGrid
- Sublime MQL Service abuse: Trello board invitation with VIP impersonation
- Sublime MQL Service abuse: Vimeo with external plain-text links in message
- Sublime MQL Service abuse: Wufoo credential theft
- Sublime MQL Sharepoint link likely unrelated to sender
- Sublime MQL SharePoint OTP for filename matching org name
- Sublime MQL Spam: Default Microsoft Exchange Online sender domain (onmicrosoft.com)
- Sublime MQL Spam: Firebase password reset from suspicious sender
- Sublime MQL Spam: Mastercard promotional content with image-based body
- Sublime MQL Spoofable internal domain with suspicious signals
- Sublime MQL Subject and sender display name contains matching long alphanumeric string
- Sublime MQL Suspected WordPress abuse with cross-site scripting (XSS) indicators
- Sublime MQL Suspicious attachment with unscannable Cloudflare link
- Sublime MQL Suspicious display name: Gmail sender with engaging language
- Sublime MQL Suspicious DocuSign share from new domain
- Sublime MQL Suspicious invoice reference with missing or image-only attachments
- Sublime MQL Suspicious link to Looker Studio (lookerstudio.google.com) from a new and unsolicited sender
- Sublime MQL Suspicious recipient pattern and language with low reputation link to login
- Sublime MQL Tax Form: W-8BEN solicitation
- Sublime MQL Truth Social infrastructure abuse via link redirect
- Sublime MQL Twitter infrastructure abuse via link shortener
- Sublime MQL URL with Unicode U+2044 (⁄) or U+2215 (∕) characters
- Sublime MQL Vendor compromise: GovDelivery message with suspicious link
- Sublime MQL VIP Impersonation via Google Group relay with suspicious indicators
- Sublime MQL X (Twitter) impersonation with credential phishing motives
- Sublime MQL Xero infrastructure abuse
- Sublime MQL Xero invoice abuse
- Sublime MQL Zoom Events newsletter abuse
Spoofing 26 rules
- Sublime MQL Attachment: ICS calendar with embedded file from internal sender with SPF failure
- Sublime MQL Attachment: PDF with credential theft language and invalid reply-to domain
- Sublime MQL Body: Embedded email headers indicative of thread hijacking/abuse
- Sublime MQL Body: Fake secure email portal with HTML obfuscation
- Sublime MQL Body: Suspicious date format
- Sublime MQL Brand impersonation: Bids & Tenders
- Sublime MQL Brand impersonation: DocuSign
- Sublime MQL Brand impersonation: Navan
- Sublime MQL Brand impersonation: State Farm
- Sublime MQL Brand impersonation: Survey request with credential theft indicators
- Sublime MQL Brand spoof: Dropbox
- Sublime MQL Cyrillic vowel substitution in subject or display name from unknown sender
- Sublime MQL DocuSign impersonation via spoofed Intuit sender
- Sublime MQL Headers: Fake in-reply-to with wildcard sender and missing thread context
- Sublime MQL Headers: Outlook Express mailer
- Sublime MQL Headers: Self-sender using Microsoft CompAuth bypass with credential theft content
- Sublime MQL Headers: System account impersonation with empty sender address
- Sublime MQL Impersonation: SharePoint reply header anomaly
- Sublime MQL Link: Invalid reply-to with recipient details in subject, body, and encoded link
- Sublime MQL Link: Suspicious wp-admin path from mismatched sender domain
- Sublime MQL Reconnaissance: Empty subject with mismatched reply-to from new sender
- Sublime MQL Sender: IP address in local part
- Sublime MQL Service Abuse: Nifty.com with impersonation
- Sublime MQL Service abuse: PayPal manager account creation with callback scam indicators
- Sublime MQL Spoofable internal domain with suspicious signals
- Sublime MQL VIP Impersonation via Google Group relay with suspicious indicators
No specific technique 8 rules
- Sublime MQL AnonymousFox indicators
- Sublime MQL Attachment: RDP connection file
- Sublime MQL Attachment: Uncommon compressed file
- Sublime MQL New link domain (<=10d) from untrusted sender
- Sublime MQL Russia return-path TLD (untrusted sender)
- Sublime MQL Sender name contains Active Directory distinguished name
- Sublime MQL Suspicious message with unscannable Cloudflare link
- Sublime MQL Suspicious Office 365 app authorization (OAuth) link
Malware/Ransomware
Encryption 18 rules
- Sublime MQL Adobe branded PDF file linking to a password-protected file from untrusted sender
- Sublime MQL Attachment with encrypted zip (unsolicited)
- Sublime MQL Attachment with unscannable encrypted zip
- Sublime MQL Attachment: Base64 encoded bash command in filename
- Sublime MQL Attachment: EML with Encrypted ZIP
- Sublime MQL Attachment: Encrypted Microsoft Office file (unsolicited)
- Sublime MQL Attachment: Encrypted ZIP containing VHDX file
- Sublime MQL Attachment: Encrypted zip file with payment-related lure
- Sublime MQL Attachment: HTML smuggling with excessive line break obfuscation
- Sublime MQL Attachment: HTML smuggling with RC4 decryption
- Sublime MQL Attachment: HTML smuggling with ROT13
- Sublime MQL Attachment: Password-protected PDF with fake document indicators
- Sublime MQL Attachment: PDF with password in filename matching body text
- Sublime MQL Encrypted Microsoft Office files from untrusted sender
- Sublime MQL Link to auto-download of a suspicious file type (unsolicited)
- Sublime MQL Link to auto-downloaded disk image in encrypted zip
- Sublime MQL Link to auto-downloaded DMG in encrypted zip
- Sublime MQL Link: Excessive URL rewrite encoders
Evasion 160 rules
- Sublime MQL Adobe branded PDF file linking to a password-protected file from untrusted sender
- Sublime MQL Attachment with encrypted zip (unsolicited)
- Sublime MQL Attachment with macro calling executable
- Sublime MQL Attachment with unscannable encrypted zip
- Sublime MQL Attachment: .csproj with suspicious commands
- Sublime MQL Attachment: 7z Archive Containing RAR File
- Sublime MQL Attachment: Any .sap file (unsolicited)
- Sublime MQL Attachment: Any HTML file within archive (unsolicited)
- Sublime MQL Attachment: Archive containing disallowed file type
- Sublime MQL Attachment: Archive with embedded CHM file
- Sublime MQL Attachment: Archive with embedded EXE file
- Sublime MQL Attachment: Archive with pdf, txt and wsf files
- Sublime MQL Attachment: Base64 encoded bash command in filename
- Sublime MQL Attachment: Calendar file with invisible Unicode characters
- Sublime MQL Attachment: DocX embedded binary
- Sublime MQL Attachment: DOCX with hyperlink targeting recipient address
- Sublime MQL Attachment: Double base64-encoded zip file in HTML smuggling attachment
- Sublime MQL Attachment: Embedded VBScript in MHT file
- Sublime MQL Attachment: EML file with HTML attachment (unsolicited)
- Sublime MQL Attachment: EML with embedded Javascript in SVG file
- Sublime MQL Attachment: EML with Encrypted ZIP
- Sublime MQL Attachment: EML with QR code redirecting to Cloudflare challenges
- Sublime MQL Attachment: Emotet heavily padded doc in zip file
- Sublime MQL Attachment: Employment contract update with suspicious file naming
- Sublime MQL Attachment: Encrypted ZIP containing VHDX file
- Sublime MQL Attachment: Encrypted zip file with payment-related lure
- Sublime MQL Attachment: Excel Web Query File (IQY)
- Sublime MQL Attachment: Fake attachment image lure
- Sublime MQL Attachment: Fake Slack installer
- Sublime MQL Attachment: Fake Zoom installer
- Sublime MQL Attachment: File execution via Javascript
- Sublime MQL Attachment: Filename containing Unicode braille pattern blank character
- Sublime MQL Attachment: Filename containing Unicode right-to-left override character
- Sublime MQL Attachment: HTML attachment with Javascript location
- Sublime MQL Attachment: HTML file contains exclusively Javascript
- Sublime MQL Attachment: HTML file with excessive 'const' declarations and abnormally long timeouts
- Sublime MQL Attachment: HTML file with excessive padding and suspicious patterns
- Sublime MQL Attachment: HTML smuggling 'body onload' linking to suspicious destination
- Sublime MQL Attachment: HTML smuggling 'body onload' with high entropy and suspicious text
- Sublime MQL Attachment: HTML smuggling with atob and high entropy via calendar invite
- Sublime MQL Attachment: HTML smuggling with base64 encoded ZIP file
- Sublime MQL Attachment: HTML smuggling with concatenation obfuscation
- Sublime MQL Attachment: HTML smuggling with decimal encoding
- Sublime MQL Attachment: HTML smuggling with embedded base64-encoded executable
- Sublime MQL Attachment: HTML smuggling with embedded base64-encoded ISO
- Sublime MQL Attachment: HTML smuggling with eval and atob
- Sublime MQL Attachment: HTML smuggling with eval and atob via calendar invite
- Sublime MQL Attachment: HTML smuggling with excessive line break obfuscation
- Sublime MQL Attachment: HTML smuggling with fromCharCode and other signals
- Sublime MQL Attachment: HTML smuggling with hex strings
- Sublime MQL Attachment: HTML smuggling with high entropy and other signals
- Sublime MQL Attachment: HTML smuggling with raw array buffer
- Sublime MQL Attachment: HTML smuggling with RC4 decryption
- Sublime MQL Attachment: HTML smuggling with ROT13
- Sublime MQL Attachment: HTML smuggling with setTimeout
- Sublime MQL Attachment: HTML smuggling with unescape
- Sublime MQL Attachment: ICS file with AWS Lambda URL
- Sublime MQL Attachment: ICS file with excessive custom properties
- Sublime MQL Attachment: ICS with embedded document
- Sublime MQL Attachment: ICS with embedded Javascript in SVG file
- Sublime MQL Attachment: JavaScript file with suspicious base64-encoded executable
- Sublime MQL Attachment: Macro files containing MHT content
- Sublime MQL Attachment: Malformed OLE file
- Sublime MQL Attachment: MS Office or RTF file with Shell.Explorer.1 com object with embedded LNK
- Sublime MQL Attachment: MS OOXML file created by Administrator with zero edit time
- Sublime MQL Attachment: MSI installer file
- Sublime MQL Attachment: Office file with suspicious function calls or downloaded file path
- Sublime MQL Attachment: OLE external relationship containing file scheme link to executable filetype
- Sublime MQL Attachment: OLE external relationship containing file scheme link to IP address
- Sublime MQL Attachment: Password-protected PDF with fake document indicators
- Sublime MQL Attachment: PDF file with low reputation link to ZIP file (unsolicited)
- Sublime MQL Attachment: PDF file with low reputation links to suspicious filetypes (unsolicited)
- Sublime MQL Attachment: PDF generated with wkhtmltopdf tool and default title
- Sublime MQL Attachment: PDF Object Hash - Encrypted PDFs with fake payment notification
- Sublime MQL Attachment: PDF Object Hash associated with fake Canada Revenue Agency documents
- Sublime MQL Attachment: PDF Object Hash with Blue File Icon
- Sublime MQL Attachment: PDF with base64 JavaScript and eval functions
- Sublime MQL Attachment: PDF with JSFck obfuscation
- Sublime MQL Attachment: PDF with link to DMG file download
- Sublime MQL Attachment: PDF with link to zip containing a wsf file
- Sublime MQL Attachment: PDF with localhost IP in EXIF title metadata
- Sublime MQL Attachment: PDF with password in filename matching body text
- Sublime MQL Attachment: PDF with suspicious HeadlessChrome metadata
- Sublime MQL Attachment: PDF with suspicious language and redirect to suspicious file type
- Sublime MQL Attachment: PDF with suspicious view document characteristics
- Sublime MQL Attachment: Potential sandbox evasion in Office file
- Sublime MQL Attachment: PowerPoint with suspicious hyperlink
- Sublime MQL Attachment: QR code with userinfo portion
- Sublime MQL Attachment: RTF with embedded content
- Sublime MQL Attachment: Self-sender PDF with minimal content and view prompt
- Sublime MQL Attachment: SFX archive containing commands
- Sublime MQL Attachment: SVG file with HTML entity encoded href attributes
- Sublime MQL Attachment: SVG files with evasion elements
- Sublime MQL Attachment: TAR file with RAR type
- Sublime MQL Attachment: Web files with suspicious comments
- Sublime MQL Attachment: WinRAR CVE-2025-8088 exploitation
- Sublime MQL Attachment: ZIP file with CVE-2026-0866 exploit
- Sublime MQL CVE-2023-5631 - Roundcube Webmail XSS via crafted SVG
- Sublime MQL Encrypted Microsoft Office files from untrusted sender
- Sublime MQL Google Drive direct download link from unsolicited sender
- Sublime MQL Headers: iOS/iPadOS mailer with invalid build number
- Sublime MQL Headers: Outlook Express mailer
- Sublime MQL HTML smuggling containing recipient email address
- Sublime MQL Image as content with a link to an open redirect
- Sublime MQL Link to auto-download of a suspicious file type (unsolicited)
- Sublime MQL Link to auto-downloaded disk image in encrypted zip
- Sublime MQL Link to auto-downloaded DMG in archive
- Sublime MQL Link to auto-downloaded DMG in encrypted zip
- Sublime MQL Link: .onion From Unsolicited Sender
- Sublime MQL Link: 9WOLF phishkit initial landing URI
- Sublime MQL Link: Apple App Store malicious ad manager themed apps from free email provider
- Sublime MQL Link: Commonly Abused Web Service redirecting to ZIP file
- Sublime MQL Link: CVE-2024-21413 Microsoft Outlook Remote Code Execution Vulnerability
- Sublime MQL Link: Direct download of executable file
- Sublime MQL Link: Direct link to gamma.app document with mode parameter
- Sublime MQL Link: Direct link to keap.app contact-us page
- Sublime MQL Link: Direct MSI download from low reputation domain
- Sublime MQL Link: Document-themed link to newly registered domain
- Sublime MQL Link: Excessive URL rewrite encoders
- Sublime MQL Link: Executable file download with suspicious message content
- Sublime MQL Link: Free file hosting with undisclosed recipients
- Sublime MQL Link: Google Cloud Storage redirect to external domain
- Sublime MQL Link: Google Firebase dynamic link that redirects to new domain (<7 days old)
- Sublime MQL Link: GoPhish query param values
- Sublime MQL Link: IPv4-mapped IPv6 address obfuscation
- Sublime MQL Link: Landing page with search-ms protocol redirect
- Sublime MQL Link: Mixed case HTTPS protocol
- Sublime MQL Link: Multiple HTTP protocols in single URL
- Sublime MQL Link: Multistage landing - ClickUp abuse
- Sublime MQL Link: Non-standard port 8443 in display URL
- Sublime MQL Link: Numeric IP obfuscation in URL
- Sublime MQL Link: Obfuscation via userinfo with suspicious indicators
- Sublime MQL Link: PDF display text with fake copyright claim template
- Sublime MQL Link: PDF file disguised as HTML page
- Sublime MQL Link: ScreenConnect installer with suspicious relay domain
- Sublime MQL Link: URL redirecting to blob URL
- Sublime MQL macOS malware: Compiled AppleScript with document double-extension
- Sublime MQL Malformed URL prefix
- Sublime MQL Malware: Pikabot delivery via URL auto-download
- Sublime MQL MalwareBazaar: Malicious attachment hash in archive (trusted reporters)
- Sublime MQL Notion suspicious file share
- Sublime MQL Observed IOC: Mail transiting bulletproof host - SmartApe
- Sublime MQL Observed IOC: Mail transiting OFAC-sanctioned bulletproof host Aeza Group
- Sublime MQL Open redirect: JustPaste.it
- Sublime MQL Potential prompt injection attack in body HTML
- Sublime MQL Punycode sender domain
- Sublime MQL QR code to auto-download of a suspicious file type (unsolicited)
- Sublime MQL Service abuse: Google application integration redirecting to suspicious hosts
- Sublime MQL Service abuse: Linode Objects HTML file hosting
- Sublime MQL Service abuse: Mimecast URL with excessive path length
- Sublime MQL Service abuse: Soundestlink redirect with suspicious indicators
- Sublime MQL Service abuse: Suspicious Datadog alert
- Sublime MQL Service abuse: Wix redirect through bulk mailer domains
- Sublime MQL Sharepoint file share with suspicious recipients pattern
- Sublime MQL Subject and sender display name contains matching long alphanumeric string
- Sublime MQL Truth Social infrastructure abuse via link redirect
- Sublime MQL Twitter infrastructure abuse via link shortener
- Sublime MQL URI protocol handler: search-ms
- Sublime MQL Vendor compromise: GovDelivery message with suspicious link
- Sublime MQL VIP Impersonation via Google Group relay with suspicious indicators
Exploit 10 rules
- Sublime MQL Anthropic Magic String in HTML
- Sublime MQL Attachment: Archive contains DLL-loading macro
- Sublime MQL Attachment: CVE-2021-40444 - MSHTML Remote Code Execution Vulnerability
- Sublime MQL Attachment: CVE-2023-21716 - Microsoft Office Remote Code Execution Vulnerability
- Sublime MQL Attachment: LNK with embedded content
- Sublime MQL Attachment: WinRAR CVE-2025-8088 exploitation
- Sublime MQL Attachment: ZIP file with CVE-2026-0866 exploit
- Sublime MQL CVE-2023-5631 - Roundcube Webmail XSS via crafted SVG
- Sublime MQL Link: CVE-2024-21413 Microsoft Outlook Remote Code Execution Vulnerability
- Sublime MQL Mass campaign: Cross Site Scripting (XSS) attempt
Free email provider 3 rules
Free file host 22 rules
- Sublime MQL Attachment: ICS file with AWS Lambda URL
- Sublime MQL Catbox.moe link from untrusted source
- Sublime MQL File sharing link from suspicious sender domain
- Sublime MQL Google Drive direct download link from unsolicited sender
- Sublime MQL Link: Commonly Abused Web Service redirecting to ZIP file
- Sublime MQL Link: Direct link to gamma.app document with mode parameter
- Sublime MQL Link: Direct link to keap.app contact-us page
- Sublime MQL Link: Direct link to limewire hosted file
- Sublime MQL Link: Free file hosting with undisclosed recipients
- Sublime MQL Link: Google Cloud Storage redirect to external domain
- Sublime MQL Link: IPFS
- Sublime MQL Link: Multistage landing - ClickUp abuse
- Sublime MQL Link: Personalized URL with recipient address on commonly abused web service
- Sublime MQL Link: Tax document lure Portuguese/Spanish with suspicious domains
- Sublime MQL Link: URL redirecting to blob URL
- Sublime MQL Mismatched links: Free file share with urgent language
- Sublime MQL Notion suspicious file share
- Sublime MQL Open redirect: JustPaste.it
- Sublime MQL Service abuse: GitHub notification with excessive mentions and suspicious links
- Sublime MQL Service abuse: Google application integration redirecting to suspicious hosts
- Sublime MQL Service abuse: Linode Objects HTML file hosting
- Sublime MQL Suspicious Links to Cloudflare R2 and Edge Services
Free subdomain host 10 rules
- Sublime MQL Attachment: HTML smuggling with raw array buffer
- Sublime MQL Link: Commonly Abused Web Service redirecting to ZIP file
- Sublime MQL Link: Free file hosting with undisclosed recipients
- Sublime MQL Link: IPFS
- Sublime MQL Link: Multistage landing - ClickUp abuse
- Sublime MQL Link: Tax document lure Portuguese/Spanish with suspicious domains
- Sublime MQL Service abuse: GitHub notification with excessive mentions and suspicious links
- Sublime MQL Service abuse: Google application integration redirecting to suspicious hosts
- Sublime MQL Service abuse: Suspicious Datadog alert
- Sublime MQL Vendor compromise: GovDelivery message with suspicious link
HTML smuggling 37 rules
- Sublime MQL Attachment: Any HTML file within archive (unsolicited)
- Sublime MQL Attachment: Double base64-encoded zip file in HTML smuggling attachment
- Sublime MQL Attachment: EML file with HTML attachment (unsolicited)
- Sublime MQL Attachment: Fake Slack installer
- Sublime MQL Attachment: Fake Zoom installer
- Sublime MQL Attachment: HTML attachment with Javascript location
- Sublime MQL Attachment: HTML file contains exclusively Javascript
- Sublime MQL Attachment: HTML file with excessive 'const' declarations and abnormally long timeouts
- Sublime MQL Attachment: HTML file with excessive padding and suspicious patterns
- Sublime MQL Attachment: HTML smuggling 'body onload' linking to suspicious destination
- Sublime MQL Attachment: HTML smuggling 'body onload' with high entropy and suspicious text
- Sublime MQL Attachment: HTML smuggling with atob and high entropy
- Sublime MQL Attachment: HTML smuggling with atob and high entropy via calendar invite
- Sublime MQL Attachment: HTML smuggling with auto-downloaded file
- Sublime MQL Attachment: HTML smuggling with base64 encoded JavaScript function
- Sublime MQL Attachment: HTML smuggling with base64 encoded ZIP file
- Sublime MQL Attachment: HTML smuggling with concatenation obfuscation
- Sublime MQL Attachment: HTML smuggling with decimal encoding
- Sublime MQL Attachment: HTML smuggling with embedded base64 streamed file download
- Sublime MQL Attachment: HTML smuggling with embedded base64-encoded executable
- Sublime MQL Attachment: HTML smuggling with embedded base64-encoded ISO
- Sublime MQL Attachment: HTML smuggling with eval and atob
- Sublime MQL Attachment: HTML smuggling with eval and atob via calendar invite
- Sublime MQL Attachment: HTML smuggling with excessive line break obfuscation
- Sublime MQL Attachment: HTML smuggling with fromCharCode and other signals
- Sublime MQL Attachment: HTML smuggling with hex strings
- Sublime MQL Attachment: HTML smuggling with high entropy and other signals
- Sublime MQL Attachment: HTML smuggling with raw array buffer
- Sublime MQL Attachment: HTML smuggling with RC4 decryption
- Sublime MQL Attachment: HTML smuggling with ROT13
- Sublime MQL Attachment: HTML smuggling with setTimeout
- Sublime MQL Attachment: HTML smuggling with unescape
- Sublime MQL Attachment: SVG file with HTML entity encoded href attributes
- Sublime MQL Attachment: Web files with suspicious comments
- Sublime MQL CVE-2023-5631 - Roundcube Webmail XSS via crafted SVG
- Sublime MQL HTML smuggling containing recipient email address
- Sublime MQL HTML smuggling with atob in message body
ICS Phishing 7 rules
- Sublime MQL Attachment: Calendar file with invisible Unicode characters
- Sublime MQL Attachment: HTML smuggling with atob and high entropy via calendar invite
- Sublime MQL Attachment: HTML smuggling with eval and atob via calendar invite
- Sublime MQL Attachment: ICS file with AWS Lambda URL
- Sublime MQL Attachment: ICS file with excessive custom properties
- Sublime MQL Attachment: ICS with embedded document
- Sublime MQL Attachment: ICS with embedded Javascript in SVG file
IPFS 2 rules
- Sublime MQL Link: IPFS
- Sublime MQL Vendor compromise: GovDelivery message with suspicious link
ISO 1 rule
Image as content 6 rules
- Sublime MQL Attachment: Fake attachment image lure
- Sublime MQL Attachment: Microsoft impersonation via PDF with link and suspicious language
- Sublime MQL Attachment: QR code with userinfo portion
- Sublime MQL Attachment: SVG files with evasion elements
- Sublime MQL Image as content with a link to an open redirect
- Sublime MQL Link: PDF display text with fake copyright claim template
Impersonation: Brand 19 rules
- Sublime MQL Adobe branded PDF file linking to a password-protected file from untrusted sender
- Sublime MQL Attachment: Fake Slack installer
- Sublime MQL Attachment: Fake Zoom installer
- Sublime MQL Attachment: Microsoft impersonation via PDF with link and suspicious language
- Sublime MQL Brand impersonation: Google Drive fake file share
- Sublime MQL Brand impersonation: Paperless Post
- Sublime MQL Brand impersonation: Sharepoint fake file share
- Sublime MQL Brand impersonation: Vanguard
- Sublime MQL Brand impersonation: WeTransfer
- Sublime MQL Brand impersonation: Zoom with deceptive link display
- Sublime MQL Brand spoof: Dropbox
- Sublime MQL Google Accelerated Mobile Pages (AMP) abuse
- Sublime MQL Link to auto-downloaded file with Adobe branding
- Sublime MQL Link to auto-downloaded file with Google Drive branding
- Sublime MQL Link: Google Cloud Storage redirect to external domain
- Sublime MQL Suspected WordPress abuse with cross-site scripting (XSS) indicators
- Sublime MQL Truth Social infrastructure abuse via link redirect
- Sublime MQL Twitter infrastructure abuse via link shortener
- Sublime MQL Vendor compromise: GovDelivery message with suspicious link
Impersonation: Domain 2 rules
- Sublime MQL Observed IOC: Malicious sender domains
- Sublime MQL Observed IOC: Malicious sender root domains
Impersonation: Email address 1 rule
- Sublime MQL Observed IOC: Malicious sender email addresses
Impersonation: Employee 2 rules
LNK 6 rules
- Sublime MQL Attachment: Archive contains DLL-loading macro
- Sublime MQL Attachment: LNK file
- Sublime MQL Attachment: LNK with embedded content
- Sublime MQL Attachment: Malicious zip file matching zipline campaign
- Sublime MQL Link to auto-download of a suspicious file type (unsolicited)
- Sublime MQL QR code to auto-download of a suspicious file type (unsolicited)
Lookalike domain 2 rules
- Sublime MQL Lookalike sender domain (untrusted sender)
- Sublime MQL Punycode sender domain
Macros 13 rules
- Sublime MQL Attachment soliciting user to enable macros
- Sublime MQL Attachment with auto-executing macro (unsolicited)
- Sublime MQL Attachment with auto-opening VBA macro (unsolicited)
- Sublime MQL Attachment with high risk VBA macro (unsolicited)
- Sublime MQL Attachment with macro calling executable
- Sublime MQL Attachment with VBA macros from employee impersonation (unsolicited)
- Sublime MQL Attachment: Archive contains DLL-loading macro
- Sublime MQL Attachment: CVE-2021-40444 - MSHTML Remote Code Execution Vulnerability
- Sublime MQL Attachment: Encrypted Microsoft Office file (unsolicited)
- Sublime MQL Attachment: Macro files containing MHT content
- Sublime MQL Attachment: Macro with suspected use of COM ShellBrowserWindow object for process creation
- Sublime MQL Attachment: Potential sandbox evasion in Office file
- Sublime MQL Suspicious VBA macros from untrusted sender
OneNote 1 rule
- Sublime MQL Attachment: Malicious OneNote commands
Open redirect 104 rules
- Sublime MQL Google Accelerated Mobile Pages (AMP) abuse
- Sublime MQL Image as content with a link to an open redirect
- Sublime MQL Link to Google Apps Script macro (unsolicited)
- Sublime MQL Link: Commonly Abused Web Service redirecting to ZIP file
- Sublime MQL Link: Google Cloud Storage redirect to external domain
- Sublime MQL Link: Multistage landing - ClickUp abuse
- Sublime MQL Link: URL redirecting to blob URL
- Sublime MQL Open redirect: adnxs.com
- Sublime MQL Open redirect: agena-smile.com
- Sublime MQL Open redirect: amaterasu-for-website-5.com
- Sublime MQL Open redirect: api.spently.com
- Sublime MQL Open redirect: artkaderne
- Sublime MQL Open Redirect: asemailmgmteu.com
- Sublime MQL Open redirect: astroarts.co.jp
- Sublime MQL Open redirect: Atdmt
- Sublime MQL Open redirect: Avast
- Sublime MQL Open redirect: bananaguide.com
- Sublime MQL Open redirect: bangkoksync.com
- Sublime MQL Open redirect: bestdeals.today
- Sublime MQL Open redirect: BMW USA
- Sublime MQL Open redirect: bubblelife.com
- Sublime MQL Open redirect: buildingengines.com
- Sublime MQL Open redirect: business.google.com website_shared URL Param
- Sublime MQL Open redirect: chkc.com.hk
- Sublime MQL Open redirect: Club-OS
- Sublime MQL Open redirect: convertcart.com
- Sublime MQL Open redirect: Dell
- Sublime MQL Open redirect: designsori.com
- Sublime MQL Open redirect: documentmailbox.com
- Sublime MQL Open redirect: Doubleclick.net
- Sublime MQL Open redirect: eaoko.org
- Sublime MQL Open redirect: easycamp.com
- Sublime MQL Open redirect: embluemail.com
- Sublime MQL Open redirect: emlakarsa
- Sublime MQL Open redirect: emp.eduyield.com
- Sublime MQL Open redirect: eodcnetworkdirect.com
- Sublime MQL Open redirect: events.csiro.au
- Sublime MQL Open redirect: ExacTag
- Sublime MQL Open redirect: fenc.com
- Sublime MQL Open redirect: g7.fr
- Sublime MQL Open redirect: Google Ad Services
- Sublime MQL Open redirect: Google Web Light
- Sublime MQL Open redirect: HHS
- Sublime MQL Open redirect: ijf.org
- Sublime MQL Open redirect: Indeed
- Sublime MQL Open redirect: IndiaTimes
- Sublime MQL Open redirect: isadatalab.com
- Sublime MQL Open redirect: JustPaste.it
- Sublime MQL Open redirect: k-mil.net
- Sublime MQL Open redirect: labcluster.com
- Sublime MQL Open redirect: LearningApps
- Sublime MQL Open redirect: Linkedin
- Sublime MQL Open redirect: LinkedIn Redirect
- Sublime MQL Open redirect: listing.ca
- Sublime MQL Open redirect: magic4media.com
- Sublime MQL Open redirect: magiccity.ne.jp
- Sublime MQL Open redirect: magneticmarketing.com
- Sublime MQL Open redirect: mail.spiceworks.com
- Sublime MQL Open redirect: McGill University
- Sublime MQL Open redirect: Medium
- Sublime MQL Open redirect: MSN
- Sublime MQL Open redirect: museepicassoparis.fr
- Sublime MQL Open redirect: Nested Doubleclick.net
- Sublime MQL Open redirect: Newegg
- Sublime MQL Open redirect: obunsha.co.jp
- Sublime MQL Open redirect: Panera Bread
- Sublime MQL Open redirect: phoenixartstudio.net
- Sublime MQL Open redirect: PIRL San Diego
- Sublime MQL Open redirect: plasticsurgery.or.kr
- Sublime MQL Open redirect: pmifunds.com
- Sublime MQL Open redirect: predictiveresponse.net
- Sublime MQL Open redirect: PremierBet
- Sublime MQL Open redirect: qrxtech.com
- Sublime MQL Open redirect: radiopublic.com
- Sublime MQL Open redirect: retailrocket.net
- Sublime MQL Open redirect: ringaraja.net
- Sublime MQL Open redirect: Samsung
- Sublime MQL Open redirect: sciencebuddies.org
- Sublime MQL Open redirect: secondstreetapp.com
- Sublime MQL Open redirect: shoppermeet.net
- Sublime MQL Open redirect: shoppingwebapi.didatravel.com
- Sublime MQL Open redirect: Slack
- Sublime MQL Open redirect: smartadserver.com
- Sublime MQL Open redirect: Snapchat
- Sublime MQL Open redirect: social.bigpress.net
- Sublime MQL Open redirect: ssg-financial.com
- Sublime MQL Open redirect: stats.lib.pdx.edu
- Sublime MQL Open redirect: storematch.jp
- Sublime MQL Open redirect: Ticketmaster
- Sublime MQL Open redirect: TikTok
- Sublime MQL Open redirect: tkqlhce.com
- Sublime MQL Open redirect: tuttocauzioni.it
- Sublime MQL Open redirect: U.S. Antarctic Program Data Center (USAP-DC)
- Sublime MQL Open redirect: unitedwaynwvt.org
- Sublime MQL Open redirect: ust.hk
- Sublime MQL Open redirect: vconfex.com
- Sublime MQL Open redirect: VK
- Sublime MQL Open redirect: whitefox.pl
- Sublime MQL Open redirect: xfinity.com
- Sublime MQL Open redirect: YouTube
- Sublime MQL PDF attachment with Google (AE) redirecting to a php or zip file
- Sublime MQL Service abuse: Google application integration redirecting to suspicious hosts
- Sublime MQL Service abuse: Mimecast URL with excessive path length
- Sublime MQL Service abuse: Wix redirect through bulk mailer domains
Out of band pivot 2 rules
PDF 29 rules
- Sublime MQL Adobe branded PDF file linking to a password-protected file from untrusted sender
- Sublime MQL Attachment: Archive with pdf, txt and wsf files
- Sublime MQL Attachment: Fake PDF Invoices Yara
- Sublime MQL Attachment: Microsoft impersonation via PDF with link and suspicious language
- Sublime MQL Attachment: Password-protected PDF with fake document indicators
- Sublime MQL Attachment: PDF file with low reputation link to ZIP file (unsolicited)
- Sublime MQL Attachment: PDF file with low reputation links to suspicious filetypes (unsolicited)
- Sublime MQL Attachment: PDF generated with wkhtmltopdf tool and default title
- Sublime MQL Attachment: PDF Object Hash - Encrypted PDFs with fake payment notification
- Sublime MQL Attachment: PDF Object Hash associated with fake Canada Revenue Agency documents
- Sublime MQL Attachment: PDF Object Hash with Blue File Icon
- Sublime MQL Attachment: PDF with base64 JavaScript and eval functions
- Sublime MQL Attachment: PDF with CVE-2026-34621 lures
- Sublime MQL Attachment: PDF with JSFck obfuscation
- Sublime MQL Attachment: PDF with link to DMG file download
- Sublime MQL Attachment: PDF with link to zip containing a wsf file
- Sublime MQL Attachment: PDF with localhost IP in EXIF title metadata
- Sublime MQL Attachment: PDF with password in filename matching body text
- Sublime MQL Attachment: PDF with quote lure
- Sublime MQL Attachment: PDF with suspicious document view lure
- Sublime MQL Attachment: PDF with suspicious HeadlessChrome metadata
- Sublime MQL Attachment: PDF with suspicious language and redirect to suspicious file type
- Sublime MQL Attachment: PDF with suspicious view document characteristics
- Sublime MQL Attachment: QR code with userinfo portion
- Sublime MQL Attachment: Self-sender PDF with minimal content and view prompt
- Sublime MQL Link: PDF display text with fake copyright claim template
- Sublime MQL Link: PDF file disguised as HTML page
- Sublime MQL PDF attachment with Google (AE) redirecting to a php or zip file
- Sublime MQL URLhaus: Malicious domain in message body or pdf attachment (trusted reporters)
Punycode 1 rule
- Sublime MQL Punycode sender domain
QR code 3 rules
Scripting 53 rules
- Sublime MQL Attachment: .csproj with suspicious commands
- Sublime MQL Attachment: Any .sap file (unsolicited)
- Sublime MQL Attachment: Archive contains DLL-loading macro
- Sublime MQL Attachment: cmd file extension
- Sublime MQL Attachment: CVE-2021-40444 - MSHTML Remote Code Execution Vulnerability
- Sublime MQL Attachment: Double base64-encoded zip file in HTML smuggling attachment
- Sublime MQL Attachment: Embedded Javascript in SVG file
- Sublime MQL Attachment: Embedded VBScript in MHT file
- Sublime MQL Attachment: EML with embedded Javascript in SVG file
- Sublime MQL Attachment: Encrypted Microsoft Office file (unsolicited)
- Sublime MQL Attachment: Fake Slack installer
- Sublime MQL Attachment: Fake Zoom installer
- Sublime MQL Attachment: File execution via Javascript
- Sublime MQL Attachment: HTML attachment with Javascript location
- Sublime MQL Attachment: HTML file contains exclusively Javascript
- Sublime MQL Attachment: HTML file with excessive 'const' declarations and abnormally long timeouts
- Sublime MQL Attachment: HTML smuggling 'body onload' linking to suspicious destination
- Sublime MQL Attachment: HTML smuggling 'body onload' with high entropy and suspicious text
- Sublime MQL Attachment: HTML smuggling with atob and high entropy
- Sublime MQL Attachment: HTML smuggling with atob and high entropy via calendar invite
- Sublime MQL Attachment: HTML smuggling with auto-downloaded file
- Sublime MQL Attachment: HTML smuggling with base64 encoded JavaScript function
- Sublime MQL Attachment: HTML smuggling with base64 encoded ZIP file
- Sublime MQL Attachment: HTML smuggling with concatenation obfuscation
- Sublime MQL Attachment: HTML smuggling with decimal encoding
- Sublime MQL Attachment: HTML smuggling with embedded base64 streamed file download
- Sublime MQL Attachment: HTML smuggling with eval and atob
- Sublime MQL Attachment: HTML smuggling with eval and atob via calendar invite
- Sublime MQL Attachment: HTML smuggling with excessive line break obfuscation
- Sublime MQL Attachment: HTML smuggling with fromCharCode and other signals
- Sublime MQL Attachment: HTML smuggling with high entropy and other signals
- Sublime MQL Attachment: HTML smuggling with RC4 decryption
- Sublime MQL Attachment: HTML smuggling with ROT13
- Sublime MQL Attachment: HTML smuggling with setTimeout
- Sublime MQL Attachment: HTML smuggling with unescape
- Sublime MQL Attachment: ICS with embedded Javascript in SVG file
- Sublime MQL Attachment: JavaScript file with suspicious base64-encoded executable
- Sublime MQL Attachment: LNK with embedded content
- Sublime MQL Attachment: Macro files containing MHT content
- Sublime MQL Attachment: Macro with suspected use of COM ShellBrowserWindow object for process creation
- Sublime MQL Attachment: Malicious OneNote commands
- Sublime MQL Attachment: Microsoft impersonation via PDF with link and suspicious language
- Sublime MQL Attachment: Office document with VSTO add-in
- Sublime MQL Attachment: Office file with suspicious function calls or downloaded file path
- Sublime MQL Attachment: PowerPoint with suspicious hyperlink
- Sublime MQL Attachment: PowerShell content
- Sublime MQL Attachment: SFX archive containing commands
- Sublime MQL Attachment: SVG file execution
- Sublime MQL CVE-2023-5631 - Roundcube Webmail XSS via crafted SVG
- Sublime MQL HTML smuggling containing recipient email address
- Sublime MQL Link: Landing page with search-ms protocol redirect
- Sublime MQL Mass campaign: Cross Site Scripting (XSS) attempt
- Sublime MQL Suspected WordPress abuse with cross-site scripting (XSS) indicators
Social engineering 57 rules
- Sublime MQL Attachment with VBA macros from employee impersonation (unsolicited)
- Sublime MQL Attachment: DOCX with hyperlink targeting recipient address
- Sublime MQL Attachment: Employment contract update with suspicious file naming
- Sublime MQL Attachment: Encrypted zip file with payment-related lure
- Sublime MQL Attachment: Fake attachment image lure
- Sublime MQL Attachment: Fake PDF Invoices Yara
- Sublime MQL Attachment: Fake Slack installer
- Sublime MQL Attachment: Fake Zoom installer
- Sublime MQL Attachment: HTML smuggling with embedded base64 streamed file download
- Sublime MQL Attachment: Microsoft impersonation via PDF with link and suspicious language
- Sublime MQL Attachment: PDF with quote lure
- Sublime MQL Attachment: PDF with suspicious document view lure
- Sublime MQL Attachment: PDF with suspicious view document characteristics
- Sublime MQL Attachment: Self-sender PDF with minimal content and view prompt
- Sublime MQL Brand impersonation: Google Drive fake file share
- Sublime MQL Brand impersonation: Sharepoint fake file share
- Sublime MQL Catbox.moe link from untrusted source
- Sublime MQL Fake request for tax preparation
- Sublime MQL Google Drive direct download link from unsolicited sender
- Sublime MQL Image as content with a link to an open redirect
- Sublime MQL Link to auto-download of a suspicious file type (unsolicited)
- Sublime MQL Link to auto-downloaded disk image in encrypted zip
- Sublime MQL Link to auto-downloaded DMG in encrypted zip
- Sublime MQL Link to auto-downloaded file with Adobe branding
- Sublime MQL Link to auto-downloaded file with Google Drive branding
- Sublime MQL Link to Google Apps Script macro (unsolicited)
- Sublime MQL Link to Google Apps Script macro via comment tagging
- Sublime MQL Link: .onion From Unsolicited Sender
- Sublime MQL Link: /index.php enclosed in three asterisks
- Sublime MQL Link: Apple App Store malicious ad manager themed apps from free email provider
- Sublime MQL Link: Document-themed link to newly registered domain
- Sublime MQL Link: Executable file download with suspicious message content
- Sublime MQL Link: Google Cloud Storage redirect to external domain
- Sublime MQL Link: Personalized URL with recipient address on commonly abused web service
- Sublime MQL Link: ScreenConnect installer with suspicious relay domain
- Sublime MQL Link: ScreenConnect remote access tool delivery with unattended guest access
- Sublime MQL Link: Tax document lure Portuguese/Spanish with suspicious domains
- Sublime MQL Lookalike sender domain (untrusted sender)
- Sublime MQL macOS malware: Compiled AppleScript with document double-extension
- Sublime MQL Mass campaign: Cross Site Scripting (XSS) attempt
- Sublime MQL Mismatched links: Free file share with urgent language
- Sublime MQL Newly registered sender or reply-to domain with newly registered linked domain
- Sublime MQL Observed IOC: Mail transiting bulletproof host - SmartApe
- Sublime MQL Observed IOC: Mail transiting OFAC-sanctioned bulletproof host Aeza Group
- Sublime MQL Observed IOC: Malicious sender domains
- Sublime MQL Observed IOC: Malicious sender email addresses
- Sublime MQL Observed IOC: Malicious sender root domains
- Sublime MQL Potential prompt injection attack in body HTML
- Sublime MQL Punycode sender domain
- Sublime MQL QR code to auto-download of a suspicious file type (unsolicited)
- Sublime MQL Service abuse: GitHub notification with excessive mentions and suspicious links
- Sublime MQL Subject and sender display name contains matching long alphanumeric string
- Sublime MQL Suspected WordPress abuse with cross-site scripting (XSS) indicators
- Sublime MQL Truth Social infrastructure abuse via link redirect
- Sublime MQL Twitter infrastructure abuse via link shortener
- Sublime MQL Vendor compromise: GovDelivery message with suspicious link
- Sublime MQL VIP Impersonation via Google Group relay with suspicious indicators
Spoofing 3 rules
- Sublime MQL Brand spoof: Dropbox
- Sublime MQL Headers: Outlook Express mailer
- Sublime MQL VIP Impersonation via Google Group relay with suspicious indicators
No specific technique 9 rules
- Sublime MQL AnonymousFox indicators
- Sublime MQL Attachment with suspicious author (unsolicited)
- Sublime MQL Attachment: EICAR string present
- Sublime MQL Attachment: Office document loads remote document template
- Sublime MQL Attachment: RDP connection file
- Sublime MQL Attachment: Uncommon compressed file
- Sublime MQL MalwareBazaar: Malicious attachment hash (trusted reporters)
- Sublime MQL New link domain (<=10d) from untrusted sender
- Sublime MQL Russia return-path TLD (untrusted sender)
BEC/Fraud
Encryption 2 rules
Evasion 79 rules
- Sublime MQL Attachment: Calendar file with invisible Unicode characters
- Sublime MQL Attachment: EML with Sharepoint link likely unrelated to sender
- Sublime MQL Attachment: Encrypted zip file with payment-related lure
- Sublime MQL Attachment: ICS with employee policy review lure
- Sublime MQL Attachment: Legal themed message or PDF with suspicious indicators
- Sublime MQL Attachment: Link to Doubleclick.net open redirect
- Sublime MQL Attachment: PDF generated with wkhtmltopdf tool and default title
- Sublime MQL Attachment: PDF Object Hash associated with a fake invoice and a W-9
- Sublime MQL Attachment: PDF with self-service platform links with self sender or blank recipients
- Sublime MQL BEC with unusual reply-to or return-path mismatch
- Sublime MQL BEC/Fraud: Reply-chain manipulation with urgent keywords and self-reply
- Sublime MQL Body: Embedded email headers indicative of thread hijacking/abuse
- Sublime MQL Body: Invisible Unicode obfuscation student loan callback phishing
- Sublime MQL Body: Yellow highlighted text markers
- Sublime MQL Brand impersonation: QuickBooks notification from Intuit themed company name
- Sublime MQL Business Email Compromise (BEC) attempt with masked recipients and reply-to mismatch (unsolicited)
- Sublime MQL Callback phishing via Zelle Service Abuse
- Sublime MQL Callback phishing: SumUp infrastructure abuse
- Sublime MQL Credential phishing: Generic document share with unicode and proceedural greeting template
- Sublime MQL Credential phishing: Generic document sharing
- Sublime MQL Display Name Emoji with Financial Symbols
- Sublime MQL Encrypted Microsoft Office files from untrusted sender
- Sublime MQL Fake thread with suspicious indicators
- Sublime MQL Fake warning banner using confusable characters
- Sublime MQL Generic service abuse from newly registered domain
- Sublime MQL Headers: Fake in-reply-to with wildcard sender and missing thread context
- Sublime MQL Headers: Invalid recipient domain with mismatched reply-to from new sender
- Sublime MQL Headers: iOS/iPadOS mailer with invalid build number
- Sublime MQL Headers: Outlook Express mailer
- Sublime MQL HR impersonation via e-sign agreement comment
- Sublime MQL HTML: Bidirectional (BIDI) HTML override with right to left obfuscation
- Sublime MQL HTML: Template placeholders or recipient email in element class attributes
- Sublime MQL Impersonation: Suspected supplier impersonation with suspicious content
- Sublime MQL Link: Apple App Store malicious ad manager themed apps from free email provider
- Sublime MQL Link: BEC with newly registered domains and financial keywords
- Sublime MQL Link: Compromised WordPress site redirecting to suspicious root domain
- Sublime MQL Link: Cryptocurrency fraud with suspicious links
- Sublime MQL Link: Display text matches subject line
- Sublime MQL Link: Fake forwarded message with suspicious URL in plain text
- Sublime MQL Link: Generic financial document with proceedural timeline template
- Sublime MQL Link: Hotel booking spoofed display URL
- Sublime MQL Link: Invalid reply-to with recipient details in subject, body, and encoded link
- Sublime MQL Link: Self-sent message with quarterly document review request
- Sublime MQL Link: Self-sent PDF lure with subject correlation
- Sublime MQL Link: Shortened URL with fragment matching subject
- Sublime MQL Link: URL scheme obfuscation via split HTML anchors
- Sublime MQL Microsoft infrastructure abuse with suspicious patterns
- Sublime MQL Observed IOC: Mail transiting bulletproof host - SmartApe
- Sublime MQL Observed IOC: Mail transiting OFAC-sanctioned bulletproof host Aeza Group
- Sublime MQL Open redirect: Mailtrack Korea
- Sublime MQL PayPal invoice abuse
- Sublime MQL Potential prompt injection attack in body HTML
- Sublime MQL Reconnaissance: Empty subject with mismatched reply-to from new sender
- Sublime MQL Request for Quote or Purchase (RFQ|RFP) with suspicious sender or recipient pattern
- Sublime MQL Sender: IP address in local part
- Sublime MQL Service Abuse: Box file sharing with credential phishing intent
- Sublime MQL Service abuse: Cisco secure email service with financial request
- Sublime MQL Service abuse: DocSend share from newly registered domain
- Sublime MQL Service abuse: DocuSign notification with suspicious sender or document name
- Sublime MQL Service abuse: Domains By Proxy sender
- Sublime MQL Service abuse: Dropbox share from an unsolicited reply-to address
- Sublime MQL Service abuse: Dropbox share from new domain
- Sublime MQL Service abuse: Dropbox share with suspicious sender or document name
- Sublime MQL Service Abuse: ExactTarget with suspicious sender indicators
- Sublime MQL Service Abuse: HelloSign share with suspicious sender or document name
- Sublime MQL Service abuse: HungerRush domain with SendGrid tracking targeting ProtonMail
- Sublime MQL Service abuse: Nylas tracking subdomain with suspicious content
- Sublime MQL Service abuse: Payoneer callback scam
- Sublime MQL Service abuse: QuickBooks notification from new domain
- Sublime MQL Service abuse: QuickBooks notification with suspicious comments
- Sublime MQL Spam/fraud: Predatory journal/research paper request
- Sublime MQL Suspected lookalike domain with suspicious language
- Sublime MQL Suspicious DocuSign share from new domain
- Sublime MQL Venmo payment request abuse
- Sublime MQL VIP Impersonation via Google Group relay with suspicious indicators
- Sublime MQL VIP impersonation: Fabricated thread history with fake VIP recipients
- Sublime MQL VIP impersonation: Fake forwarded indicator with VIP recipient impersonation
- Sublime MQL VIP impersonation: Fake thread with display name match, email mismatch
- Sublime MQL VIP impersonation: VIP recipient of previous thread with HTML generator
Free email provider 34 rules
- Sublime MQL Attachment: Canva PDF with susupicious author metadata
- Sublime MQL Attachment: PDF file with link to fake Bitcoin exchange
- Sublime MQL Attachment: Romance scam with image lure and advance-fee or suspicious link indicators
- Sublime MQL BEC with unusual reply-to or return-path mismatch
- Sublime MQL BEC/Fraud: Job scam fake thread or plaintext pivot to freemail
- Sublime MQL BEC/Fraud: Penpal scam
- Sublime MQL BEC/Fraud: Romance scam
- Sublime MQL BEC/Fraud: Scam lure with freemail pivot
- Sublime MQL BEC/Fraud: Student loan callback phishing
- Sublime MQL BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns
- Sublime MQL Business Email Compromise (BEC) attempt with masked recipients and reply-to mismatch (unsolicited)
- Sublime MQL Canva infrastructure abuse
- Sublime MQL COVID-19 themed fraud with sender and reply-to mismatch or compensation award
- Sublime MQL Employee impersonation: Payroll fraud
- Sublime MQL Extortion / Sextortion - PDF attachment leveraging breach data from freemail sender
- Sublime MQL Fake message thread - Untrusted sender with a mismatched freemail reply-to address
- Sublime MQL Free email provider sender with mismatched provider reply-to
- Sublime MQL Honorific greeting BEC attempt with sender and reply-to mismatch
- Sublime MQL Impersonation: Employee name in subject with suspicious sender
- Sublime MQL Impersonation: Executive using numbered local part
- Sublime MQL Impersonation: Suspected supplier impersonation with suspicious content
- Sublime MQL Link abuse: Self-service creation platform link with suspicious recipient behavior
- Sublime MQL Link: Apple App Store malicious ad manager themed apps from free email provider
- Sublime MQL Link: Invoice or receipt from freemail sender with customer service number
- Sublime MQL Reconnaissance: Email address harvesting attempt
- Sublime MQL Reconnaissance: Hotel booking reply-to redirect
- Sublime MQL Reconnaissance: Short generic greeting message
- Sublime MQL Request for Quote or Purchase (RFQ|RFP) with suspicious sender or recipient pattern
- Sublime MQL Scam: Fake estate sale offering welding equipment and tools
- Sublime MQL Scam: Piano giveaway
- Sublime MQL Service abuse: Google Drive share from an unsolicited reply-to address
- Sublime MQL Service abuse: Google Drive share from new reply-to domain
- Sublime MQL Suspicious request for financial information
- Sublime MQL VIP Impersonation via Google Group relay with suspicious indicators
Free file host 17 rules
- Sublime MQL Attachment: PDF bid/proposal lure with credential theft indicators
- Sublime MQL Attachment: PDF with self-service platform links with self sender or blank recipients
- Sublime MQL Attachment: Romance scam with image lure and advance-fee or suspicious link indicators
- Sublime MQL DocuSign impersonation via CloudHQ links
- Sublime MQL File sharing link with a suspicious subject
- Sublime MQL Impersonation: Fake product discount promotion
- Sublime MQL Link: Mismatched free file host links with document lure
- Sublime MQL Link: Tax document lure Portuguese/Spanish with suspicious domains
- Sublime MQL Mismatched links: Free file share with urgent language
- Sublime MQL Service abuse: Citrix ShareFile impersonation via Outlook plugin
- Sublime MQL Service abuse: DocSend share from newly registered domain
- Sublime MQL Service abuse: Formester with suspicious link behavior
- Sublime MQL Service abuse: Google Drive share from an unsolicited reply-to address
- Sublime MQL Service abuse: Google Drive share from new reply-to domain
- Sublime MQL Service abuse: SendThisFile with credential theft and financial language
- Sublime MQL Suspicious DocuSign share from new domain
- Sublime MQL Suspicious Links to Cloudflare R2 and Edge Services
Free subdomain host 6 rules
- Sublime MQL Attachment: PDF bid/proposal lure with credential theft indicators
- Sublime MQL Link: Breely link masquerading as PDF
- Sublime MQL Link: Cryptocurrency fraud with suspicious links
- Sublime MQL Link: File sharing impersonation with suspicious language and sending patterns
- Sublime MQL Link: Tax document lure Portuguese/Spanish with suspicious domains
- Sublime MQL Link: WordPress login page with Blogspot Binance scam
HTML injection 1 rule
ICS Phishing 4 rules
Image as content 3 rules
Impersonation: Brand 56 rules
- Sublime MQL Attachment: EML with Sharepoint link likely unrelated to sender
- Sublime MQL Attachment: Invoice and W-9 PDFs with suspicious creators
- Sublime MQL Attachment: PDF file with link to fake Bitcoin exchange
- Sublime MQL Attachment: PDF with W-9 form indicators
- Sublime MQL Attachment: RFP/RFQ impersonating government entities
- Sublime MQL Attachment: USDA bid invitation impersonation
- Sublime MQL BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns
- Sublime MQL BEC: Executive coaching vendor impersonation
- Sublime MQL Body: PayApp transaction reference pattern
- Sublime MQL Brand impersonation: AARP
- Sublime MQL Brand impersonation: Aquent
- Sublime MQL Brand impersonation: Aramco
- Sublime MQL Brand impersonation: AuthentiSign
- Sublime MQL Brand impersonation: Canada Revenue Agency
- Sublime MQL Brand impersonation: Enbridge
- Sublime MQL Brand impersonation: Fake procurement/RFQ PDF from energy and industrial companies
- Sublime MQL Brand impersonation: Interac
- Sublime MQL Brand impersonation: Internal Revenue Service
- Sublime MQL Brand impersonation: Mailgun
- Sublime MQL Brand impersonation: McAfee
- Sublime MQL Brand impersonation: MetaMask
- Sublime MQL Brand impersonation: Microsoft logo or suspicious language with open redirect
- Sublime MQL Brand Impersonation: Procore
- Sublime MQL Brand impersonation: Purdue ePlanroom with suspicious links
- Sublime MQL Brand impersonation: QuickBooks dispute notification
- Sublime MQL Brand impersonation: Robert Half
- Sublime MQL Brand impersonation: SendGrid
- Sublime MQL Brand impersonation: Social Security Administration
- Sublime MQL Brand impersonation: Trust Wallet
- Sublime MQL Brand impersonation: UK government Home Office
- Sublime MQL Brand impersonation: Vanguard
- Sublime MQL Brand impersonation: WeTransfer
- Sublime MQL Canva infrastructure abuse
- Sublime MQL Credential phishing: Personalized document signing request
- Sublime MQL Credential phishing: Tax form impersonation with payment request
- Sublime MQL DocuSign impersonation via CloudHQ links
- Sublime MQL Fraudulent e-commerce operators
- Sublime MQL HR impersonation via e-sign agreement comment
- Sublime MQL Impersonation: Australian Federal Police with criminal case language
- Sublime MQL Impersonation: Legal firm with copyright infringement notice
- Sublime MQL Impersonation: SAM/SBA federal registration
- Sublime MQL Link: File sharing impersonation with suspicious language and sending patterns
- Sublime MQL Link: Invoice or receipt from freemail sender with customer service number
- Sublime MQL Link: WordPress login page with Blogspot Binance scam
- Sublime MQL Microsoft infrastructure abuse with suspicious patterns
- Sublime MQL Recruitee Infrastructure Abuse
- Sublime MQL Scam soliciting employer review/rating
- Sublime MQL Service abuse: Adobe Sign notification from an unsolicited reply-to address
- Sublime MQL Service abuse: Cisco secure email service with financial request
- Sublime MQL Service abuse: DocSend share from newly registered domain
- Sublime MQL Service abuse: Google classroom solicitation
- Sublime MQL Service abuse: Roomsy with unrelated body content
- Sublime MQL Spam/fraud: Predatory journal/research paper request
- Sublime MQL Suspicious DocuSign share from new domain
- Sublime MQL Venmo payment request abuse
- Sublime MQL Xero invoice abuse
Impersonation: Domain 2 rules
- Sublime MQL Observed IOC: Malicious sender domains
- Sublime MQL Observed IOC: Malicious sender root domains
Impersonation: Email address 1 rule
- Sublime MQL Observed IOC: Malicious sender email addresses
Impersonation: Employee 15 rules
- Sublime MQL BEC: Employee impersonation with subject manipulation
- Sublime MQL Canva infrastructure abuse
- Sublime MQL Credential phishing: Generic document sharing
- Sublime MQL Employee impersonation with urgent request (untrusted sender)
- Sublime MQL Employee impersonation: Payroll fraud
- Sublime MQL Headers: System account impersonation with empty sender address
- Sublime MQL Impersonation: Employee name in subject with suspicious sender
- Sublime MQL Impersonation: Employee using fabricated identity in initial contact
- Sublime MQL Impersonation: Human Resources with link or attachment and engaging language
- Sublime MQL Service Abuse: Box file sharing with credential phishing intent
- Sublime MQL Sharepoint link likely unrelated to sender
- Sublime MQL Suspicious request for financial information
- Sublime MQL VIP Impersonation via Google Group relay with suspicious indicators
- Sublime MQL VIP impersonation with charitable donation fraud
- Sublime MQL Xero invoice abuse
Impersonation: VIP 22 rules
- Sublime MQL Attachment: Fake lawyer & sports agent identities
- Sublime MQL Impersonation: Employee name in subject with suspicious sender
- Sublime MQL Impersonation: Executive using numbered local part
- Sublime MQL Service Abuse: Box file sharing with credential phishing intent
- Sublime MQL Suspicious request for financial information
- Sublime MQL VIP / Executive impersonation (strict match, untrusted)
- Sublime MQL VIP / Executive impersonation in subject (untrusted)
- Sublime MQL VIP impersonation with BEC language (near match, untrusted sender)
- Sublime MQL VIP impersonation with charitable donation fraud
- Sublime MQL VIP impersonation with invoicing request
- Sublime MQL VIP impersonation with urgent request (strict match, untrusted sender)
- Sublime MQL VIP impersonation with w2 request with reply-to mismatch
- Sublime MQL VIP impersonation: Fabricated thread history with fake VIP recipients
- Sublime MQL VIP impersonation: Fake forwarded indicator with VIP recipient impersonation
- Sublime MQL VIP impersonation: Fake thread with display name match, email mismatch
- Sublime MQL VIP impersonation: Fake thread with VIPs missing email metadata
- Sublime MQL VIP impersonation: Invoice fraud with mobile device sign-off
- Sublime MQL VIP impersonation: Payment handoff with VIP display name authored fake threads
- Sublime MQL VIP Impersonation: VIP handoff with fake forwarded invoice thread
- Sublime MQL VIP impersonation: VIP name within a delimited subject with fake previous threads
- Sublime MQL VIP impersonation: VIP payment redirect handoff via fake threads
- Sublime MQL VIP impersonation: VIP recipient of previous thread with HTML generator
Lookalike domain 12 rules
- Sublime MQL Brand impersonation: Anthropic/Claude with newly registered domain
- Sublime MQL Brand impersonation: Aramco
- Sublime MQL Brand impersonation: AuthentiSign
- Sublime MQL Brand impersonation: Interac
- Sublime MQL Brand impersonation: UK government Home Office
- Sublime MQL Fraudulent e-commerce operators
- Sublime MQL Impersonation: Suspected supplier impersonation with suspicious content
- Sublime MQL Lookalike sender domain (untrusted sender)
- Sublime MQL Sharepoint link likely unrelated to sender
- Sublime MQL Spam/fraud: Predatory journal/research paper request
- Sublime MQL Suspected lookalike domain with suspicious language
- Sublime MQL Vendor impersonation: Thread hijacking with typosquat domain
Macros 1 rule
- Sublime MQL Attachment: USDA bid invitation impersonation
OneNote 1 rule
- Sublime MQL Sharepoint link likely unrelated to sender
Open redirect 6 rules
- Sublime MQL Attachment: Calendar invite with Google redirect and invoice request
- Sublime MQL Attachment: Link to Doubleclick.net open redirect
- Sublime MQL Brand impersonation: Microsoft logo or suspicious language with open redirect
- Sublime MQL Link: Compromised WordPress site redirecting to suspicious root domain
- Sublime MQL Open redirect: Mailtrack Korea
- Sublime MQL Service abuse: Formester with suspicious link behavior
Out of band pivot 11 rules
- Sublime MQL Attachment: Credit card application with WhatsApp contact
- Sublime MQL Attachment: Romance scam with image lure and advance-fee or suspicious link indicators
- Sublime MQL BEC/Fraud: Job scam fake thread or plaintext pivot to freemail
- Sublime MQL BEC/Fraud: Scam lure with freemail pivot
- Sublime MQL BEC/Fraud: Student loan callback phishing
- Sublime MQL HR impersonation via e-sign agreement comment
- Sublime MQL Scam: Fake estate sale offering welding equipment and tools
- Sublime MQL Service abuse: Adobe share containing newly observed email address domain
- Sublime MQL Service abuse: Google classroom solicitation
- Sublime MQL Service abuse: Zohodesk reply-to mismatch with job scam indicators
- Sublime MQL VIP Impersonation: VIP handoff with fake forwarded invoice thread
PDF 23 rules
- Sublime MQL Attachment: Canva PDF with susupicious author metadata
- Sublime MQL Attachment: Duplicated header pages in fraudulent multi-page PDF Request for Quotation
- Sublime MQL Attachment: Fictitious invoice using LinkedIn's address
- Sublime MQL Attachment: Invoice and W-9 PDFs with suspicious creators
- Sublime MQL Attachment: Legal themed message or PDF with suspicious indicators
- Sublime MQL Attachment: PDF bid/proposal lure with credential theft indicators
- Sublime MQL Attachment: PDF contains W9 or invoice YARA signatures
- Sublime MQL Attachment: PDF file with link to fake Bitcoin exchange
- Sublime MQL Attachment: PDF file with recipient domain and ATT eCheckRun pattern
- Sublime MQL Attachment: PDF generated with wkhtmltopdf tool and default title
- Sublime MQL Attachment: PDF Object Hash associated with a fake invoice and a W-9
- Sublime MQL Attachment: PDF with fake invoice using suspicious font sizing
- Sublime MQL Attachment: PDF with self-service platform links with self sender or blank recipients
- Sublime MQL Attachment: PDF with specific W-9 lure
- Sublime MQL Attachment: PDF with suspicious internal object reference identifier
- Sublime MQL Attachment: PDF with W-9 form indicators
- Sublime MQL Attachment: RFP/RFQ impersonating government entities
- Sublime MQL Attachment: USDA bid invitation impersonation
- Sublime MQL Brand impersonation: Fake procurement/RFQ PDF from energy and industrial companies
- Sublime MQL Credential phishing: Tax form impersonation with payment request
- Sublime MQL Extortion / Sextortion - PDF attachment leveraging breach data from freemail sender
- Sublime MQL Sharepoint link likely unrelated to sender
- Sublime MQL Stripe invoice abuse
QR code 1 rule
Scripting 2 rules
Social engineering 202 rules
- Sublime MQL Advance Fee Fraud (AFF) from freemail provider or suspicious TLD
- Sublime MQL Attachment: Calendar invite with Google redirect and invoice request
- Sublime MQL Attachment: Credit card application with WhatsApp contact
- Sublime MQL Attachment: Duplicated header pages in fraudulent multi-page PDF Request for Quotation
- Sublime MQL Attachment: EML with Sharepoint link likely unrelated to sender
- Sublime MQL Attachment: Encrypted zip file with payment-related lure
- Sublime MQL Attachment: Fake lawyer & sports agent identities
- Sublime MQL Attachment: Fictitious invoice using LinkedIn's address
- Sublime MQL Attachment: ICS calendar file with suspicious UID domain
- Sublime MQL Attachment: ICS file with meeting prefix
- Sublime MQL Attachment: ICS with employee policy review lure
- Sublime MQL Attachment: Invoice and W-9 PDFs with suspicious creators
- Sublime MQL Attachment: Legal themed message or PDF with suspicious indicators
- Sublime MQL Attachment: Link to Doubleclick.net open redirect
- Sublime MQL Attachment: PDF bid/proposal lure with credential theft indicators
- Sublime MQL Attachment: PDF contains W9 or invoice YARA signatures
- Sublime MQL Attachment: PDF file with link to fake Bitcoin exchange
- Sublime MQL Attachment: PDF file with recipient domain and ATT eCheckRun pattern
- Sublime MQL Attachment: PDF with fake invoice using suspicious font sizing
- Sublime MQL Attachment: PDF with specific W-9 lure
- Sublime MQL Attachment: PDF with W-9 form indicators
- Sublime MQL Attachment: RFP/RFQ impersonating government entities
- Sublime MQL Attachment: Romance scam with image lure and advance-fee or suspicious link indicators
- Sublime MQL Attachment: USDA bid invitation impersonation
- Sublime MQL BEC with unusual reply-to or return-path mismatch
- Sublime MQL BEC/Fraud: Fake investment outreach from suspicious TLD
- Sublime MQL BEC/Fraud: Generic scam attempt to undisclosed recipients
- Sublime MQL BEC/Fraud: Penpal scam
- Sublime MQL BEC/Fraud: Reply-chain manipulation with urgent keywords and self-reply
- Sublime MQL BEC/Fraud: Romance scam
- Sublime MQL BEC/Fraud: Student loan callback phishing
- Sublime MQL BEC/Fraud: Unsolicited business acquisition offer
- Sublime MQL BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns
- Sublime MQL BEC: Employee impersonation with subject manipulation
- Sublime MQL BEC: Executive coaching vendor impersonation
- Sublime MQL BEC: Financial fraud from newly registered sender domain
- Sublime MQL BEC: Tax document request
- Sublime MQL Body: Embedded email headers indicative of thread hijacking/abuse
- Sublime MQL Body: Invisible Unicode obfuscation student loan callback phishing
- Sublime MQL Body: PayApp transaction reference pattern
- Sublime MQL Brand impersonation: AARP
- Sublime MQL Brand impersonation: Anthropic/Claude with newly registered domain
- Sublime MQL Brand impersonation: Aquent
- Sublime MQL Brand impersonation: Aramco
- Sublime MQL Brand impersonation: AuthentiSign
- Sublime MQL Brand impersonation: Canada Revenue Agency
- Sublime MQL Brand impersonation: Enbridge
- Sublime MQL Brand impersonation: Fake procurement/RFQ PDF from energy and industrial companies
- Sublime MQL Brand impersonation: Interac
- Sublime MQL Brand impersonation: Internal Revenue Service
- Sublime MQL Brand impersonation: McAfee
- Sublime MQL Brand impersonation: MetaMask
- Sublime MQL Brand impersonation: Microsoft logo or suspicious language with open redirect
- Sublime MQL Brand Impersonation: Procore
- Sublime MQL Brand impersonation: Purdue ePlanroom with suspicious links
- Sublime MQL Brand impersonation: QuickBooks notification from Intuit themed company name
- Sublime MQL Brand impersonation: Robert Half
- Sublime MQL Brand impersonation: SendGrid
- Sublime MQL Brand impersonation: Social Security Administration
- Sublime MQL Brand impersonation: Trust Wallet
- Sublime MQL Brand impersonation: UK government Home Office
- Sublime MQL Business Email Compromise (BEC) attempt from unsolicited sender
- Sublime MQL Business Email Compromise (BEC) attempt from untrusted sender
- Sublime MQL Business Email Compromise (BEC) attempt from untrusted sender (French/Français)
- Sublime MQL Business Email Compromise (BEC) with request for mobile number
- Sublime MQL Business Email Compromise: Request for mobile number via reply thread hijacking
- Sublime MQL Callback phishing via Zelle Service Abuse
- Sublime MQL Callback phishing: SumUp infrastructure abuse
- Sublime MQL Canva infrastructure abuse
- Sublime MQL COVID-19 themed fraud with sender and reply-to mismatch or compensation award
- Sublime MQL Credential phishing: Generic document share with unicode and proceedural greeting template
- Sublime MQL Credential phishing: Generic document sharing
- Sublime MQL Credential phishing: Personalized document signing request
- Sublime MQL Credential phishing: Tax form impersonation with payment request
- Sublime MQL Display Name Emoji with Financial Symbols
- Sublime MQL Employee impersonation with urgent request (untrusted sender)
- Sublime MQL Employee impersonation: Payroll fraud
- Sublime MQL Extortion / Sextortion - PDF attachment leveraging breach data from freemail sender
- Sublime MQL Fake message thread - Untrusted sender with a mismatched freemail reply-to address
- Sublime MQL Fake request for tax preparation
- Sublime MQL Fake thread with suspicious indicators
- Sublime MQL Fake warning banner using confusable characters
- Sublime MQL File sharing link with a suspicious subject
- Sublime MQL Fraudulent e-commerce operators
- Sublime MQL Fraudulent order confirmation/shipping notification from Chinese sender domain
- Sublime MQL Free email provider sender with mismatched provider reply-to
- Sublime MQL Generic service abuse from newly registered domain
- Sublime MQL Headers: Fake in-reply-to with wildcard sender and missing thread context
- Sublime MQL Headers: Invalid recipient domain with mismatched reply-to from new sender
- Sublime MQL Headers: System account impersonation with empty sender address
- Sublime MQL Headers: X-Source-Auth mismatch with mismatched reply-to domain
- Sublime MQL Honorific greeting BEC attempt with sender and reply-to mismatch
- Sublime MQL HR impersonation via e-sign agreement comment
- Sublime MQL HTML: Bidirectional (BIDI) HTML override with right to left obfuscation
- Sublime MQL HTML: Template placeholders or recipient email in element class attributes
- Sublime MQL Impersonation: Australian Federal Police with criminal case language
- Sublime MQL Impersonation: Employee name in subject with suspicious sender
- Sublime MQL Impersonation: Employee using fabricated identity in initial contact
- Sublime MQL Impersonation: Executive using numbered local part
- Sublime MQL Impersonation: Fake product discount promotion
- Sublime MQL Impersonation: Human Resources with link or attachment and engaging language
- Sublime MQL Impersonation: Legal firm with copyright infringement notice
- Sublime MQL Impersonation: SAM/SBA federal registration
- Sublime MQL Impersonation: Suspected supplier impersonation with suspicious content
- Sublime MQL Investor solicitation with organization targeting
- Sublime MQL Job scam (unsolicited sender)
- Sublime MQL Job scam with specific salary pattern
- Sublime MQL Link abuse: Self-service creation platform link with suspicious recipient behavior
- Sublime MQL Link: Apple App Store malicious ad manager themed apps from free email provider
- Sublime MQL Link: BEC with newly registered domains and financial keywords
- Sublime MQL Link: Breely link masquerading as PDF
- Sublime MQL Link: Compromised WordPress site redirecting to suspicious root domain
- Sublime MQL Link: Cryptocurrency fraud with suspicious links
- Sublime MQL Link: Display text matches subject line
- Sublime MQL Link: Fake forwarded message with suspicious URL in plain text
- Sublime MQL Link: File sharing impersonation with suspicious language and sending patterns
- Sublime MQL Link: Generic financial document with proceedural timeline template
- Sublime MQL Link: Google Drawings link from new sender
- Sublime MQL Link: Hotel booking spoofed display URL
- Sublime MQL Link: Invalid reply-to with recipient details in subject, body, and encoded link
- Sublime MQL Link: Invoice or receipt from freemail sender with customer service number
- Sublime MQL Link: Mismatched free file host links with document lure
- Sublime MQL Link: Remittance payment request with timeline template
- Sublime MQL Link: RFI document reference pattern in display text
- Sublime MQL Link: Self-sent message with quarterly document review request
- Sublime MQL Link: Self-sent PDF lure with subject correlation
- Sublime MQL Link: Shortened URL with fragment matching subject
- Sublime MQL Link: Tax document lure Portuguese/Spanish with suspicious domains
- Sublime MQL Link: URL scheme obfuscation via split HTML anchors
- Sublime MQL Link: WordPress login page with Blogspot Binance scam
- Sublime MQL Lookalike sender domain (untrusted sender)
- Sublime MQL Microsoft infrastructure abuse with suspicious patterns
- Sublime MQL Mismatched links: Free file share with urgent language
- Sublime MQL Newly registered sender or reply-to domain with newly registered linked domain
- Sublime MQL Observed IOC: Mail transiting bulletproof host - SmartApe
- Sublime MQL Observed IOC: Mail transiting OFAC-sanctioned bulletproof host Aeza Group
- Sublime MQL Observed IOC: Malicious sender domains
- Sublime MQL Observed IOC: Malicious sender email addresses
- Sublime MQL Observed IOC: Malicious sender root domains
- Sublime MQL PayPal invoice abuse
- Sublime MQL Potential prompt injection attack in body HTML
- Sublime MQL Reconnaissance: Email address harvesting attempt
- Sublime MQL Reconnaissance: Empty subject with mismatched reply-to from new sender
- Sublime MQL Reconnaissance: Fake real estate inquiry with empty body
- Sublime MQL Reconnaissance: Hotel booking reply-to redirect
- Sublime MQL Reconnaissance: Short generic greeting message
- Sublime MQL Recruitee Infrastructure Abuse
- Sublime MQL Scam soliciting employer review/rating
- Sublime MQL Scam: Fake estate sale offering welding equipment and tools
- Sublime MQL Service abuse: Adobe legitimate domain with document approval language
- Sublime MQL Service abuse: Adobe share containing newly observed email address domain
- Sublime MQL Service abuse: Adobe Sign notification from an unsolicited reply-to address
- Sublime MQL Service Abuse: Box file sharing with credential phishing intent
- Sublime MQL Service abuse: Cisco secure email service with financial request
- Sublime MQL Service abuse: Citrix ShareFile impersonation via Outlook plugin
- Sublime MQL Service abuse: DocSend share from newly registered domain
- Sublime MQL Service abuse: DocuSign notification with suspicious sender or document name
- Sublime MQL Service abuse: Domains By Proxy sender
- Sublime MQL Service abuse: Dropbox share from an unsolicited reply-to address
- Sublime MQL Service abuse: Dropbox share from new domain
- Sublime MQL Service abuse: Dropbox share with suspicious sender or document name
- Sublime MQL Service abuse: Evernote link
- Sublime MQL Service Abuse: ExactTarget with suspicious sender indicators
- Sublime MQL Service abuse: Formester with suspicious link behavior
- Sublime MQL Service abuse: Google classroom solicitation
- Sublime MQL Service abuse: Google Drive share from an unsolicited reply-to address
- Sublime MQL Service abuse: Google Drive share from new reply-to domain
- Sublime MQL Service Abuse: HelloSign share with suspicious sender or document name
- Sublime MQL Service abuse: Nylas tracking subdomain with suspicious content
- Sublime MQL Service abuse: Payoneer callback scam
- Sublime MQL Service abuse: QuickBooks notification from new domain
- Sublime MQL Service abuse: QuickBooks notification with suspicious comments
- Sublime MQL Service abuse: Recruiting with suspicious language patterns from legitimate platforms
- Sublime MQL Service abuse: Roomsy with unrelated body content
- Sublime MQL Service abuse: SendThisFile with credential theft and financial language
- Sublime MQL Service abuse: Zohodesk reply-to mismatch with job scam indicators
- Sublime MQL Sharepoint link likely unrelated to sender
- Sublime MQL Spam/fraud: Predatory journal/research paper request
- Sublime MQL Spam: Large financial amount mention from newly registered sender domain
- Sublime MQL Suspected lookalike domain with suspicious language
- Sublime MQL Suspicious display name: Gmail sender with engaging language
- Sublime MQL Suspicious DocuSign share from new domain
- Sublime MQL Suspicious newly registered reply-to domain with engaging financial or urgent language
- Sublime MQL Suspicious request for financial information
- Sublime MQL Tax Form: W-8BEN solicitation
- Sublime MQL Vendor impersonation: Thread hijacking with typosquat domain
- Sublime MQL Venmo payment request abuse
- Sublime MQL VIP Impersonation via Google Group relay with suspicious indicators
- Sublime MQL VIP impersonation with BEC language (near match, untrusted sender)
- Sublime MQL VIP impersonation with charitable donation fraud
- Sublime MQL VIP impersonation with urgent request (strict match, untrusted sender)
- Sublime MQL VIP impersonation: Fabricated thread history with fake VIP recipients
- Sublime MQL VIP impersonation: Fake forwarded indicator with VIP recipient impersonation
- Sublime MQL VIP impersonation: Fake thread with display name match, email mismatch
- Sublime MQL VIP impersonation: Fake thread with VIPs missing email metadata
- Sublime MQL VIP impersonation: Invoice fraud with mobile device sign-off
- Sublime MQL VIP impersonation: Payment handoff with VIP display name authored fake threads
- Sublime MQL VIP Impersonation: VIP handoff with fake forwarded invoice thread
- Sublime MQL VIP impersonation: VIP name within a delimited subject with fake previous threads
- Sublime MQL VIP impersonation: VIP payment redirect handoff via fake threads
- Sublime MQL VIP impersonation: VIP recipient of previous thread with HTML generator
- Sublime MQL Xero invoice abuse
Spoofing 22 rules
- Sublime MQL BEC: Financial fraud from newly registered sender domain
- Sublime MQL BEC: Tax document request
- Sublime MQL Body: Embedded email headers indicative of thread hijacking/abuse
- Sublime MQL Brand impersonation: Anthropic/Claude with newly registered domain
- Sublime MQL Business Email Compromise (BEC) attempt from unsolicited sender
- Sublime MQL Headers: Fake in-reply-to with wildcard sender and missing thread context
- Sublime MQL Headers: Outlook Express mailer
- Sublime MQL Headers: System account impersonation with empty sender address
- Sublime MQL Headers: X-Source-Auth mismatch with mismatched reply-to domain
- Sublime MQL Impersonation: Employee name in subject with suspicious sender
- Sublime MQL Link: BEC with newly registered domains and financial keywords
- Sublime MQL Link: Invalid reply-to with recipient details in subject, body, and encoded link
- Sublime MQL Reconnaissance: Empty subject with mismatched reply-to from new sender
- Sublime MQL Sender: IP address in local part
- Sublime MQL Service abuse: Zohodesk reply-to mismatch with job scam indicators
- Sublime MQL Vendor impersonation: Thread hijacking with typosquat domain
- Sublime MQL VIP Impersonation via Google Group relay with suspicious indicators
- Sublime MQL VIP impersonation: Fabricated thread history with fake VIP recipients
- Sublime MQL VIP impersonation: Fake thread with display name match, email mismatch
- Sublime MQL VIP impersonation: Fake thread with VIPs missing email metadata
- Sublime MQL VIP Impersonation: VIP handoff with fake forwarded invoice thread
- Sublime MQL VIP impersonation: VIP name within a delimited subject with fake previous threads
No specific technique 2 rules
- Sublime MQL AnonymousFox indicators
- Sublime MQL Russia return-path TLD (untrusted sender)
Callback Phishing
Encryption 1 rule
Evasion 34 rules
- Sublime MQL Attachment: Calendar invite from recently registered domain
- Sublime MQL Attachment: Callback phishing solicitation via image file
- Sublime MQL Attachment: Callback phishing solicitation via pdf file
- Sublime MQL Attachment: Callback phishing solicitation via text-based file
- Sublime MQL Attachment: PDF generated with wkhtmltopdf tool and default title
- Sublime MQL Brand impersonation: QuickBooks notification from Intuit themed company name
- Sublime MQL Callback phishing via Adobe Sign comment
- Sublime MQL Callback phishing via calendar invite
- Sublime MQL Callback phishing via DocuSign comment
- Sublime MQL Callback phishing via Intuit service abuse
- Sublime MQL Callback phishing via Zelle Service Abuse
- Sublime MQL Callback phishing via Zoho service abuse
- Sublime MQL Callback phishing: Social Security Administration fraud
- Sublime MQL Callback phishing: SumUp infrastructure abuse
- Sublime MQL Callback phishing: Zero-width character obfuscation from freemail sender
- Sublime MQL Display Name Emoji with Financial Symbols
- Sublime MQL Encrypted Microsoft Office files from untrusted sender
- Sublime MQL Generic service abuse from newly registered domain
- Sublime MQL Inbound message from popular service via newly observed distribution list
- Sublime MQL Message traversed multiple onmicrosoft.com tenants
- Sublime MQL Microsoft infrastructure abuse with suspicious patterns
- Sublime MQL PayPal invoice abuse
- Sublime MQL Potential prompt injection attack in body HTML
- Sublime MQL Service Abuse: Box file sharing with credential phishing intent
- Sublime MQL Service abuse: DocuSign notification with suspicious sender or document name
- Sublime MQL Service abuse: Dropbox share from an unsolicited reply-to address
- Sublime MQL Service abuse: Dropbox share from new domain
- Sublime MQL Service abuse: Dropbox share with suspicious sender or document name
- Sublime MQL Service Abuse: GoDaddy infrastructure
- Sublime MQL Service Abuse: HelloSign share with suspicious sender or document name
- Sublime MQL Service abuse: Payoneer callback scam
- Sublime MQL Service abuse: QuickBooks notification from new domain
- Sublime MQL Service abuse: QuickBooks notification with suspicious comments
- Sublime MQL Venmo payment request abuse
Exploit 3 rules
- Sublime MQL Callback Phishing via Signable E-Signature Request
- Sublime MQL Callback phishing via SignFree e-signature request
- Sublime MQL Callback phishing via Xodo Sign comment
Free email provider 21 rules
- Sublime MQL Attachment: Callback phishing solicitation via image file
- Sublime MQL Attachment: Callback phishing solicitation via pdf file
- Sublime MQL BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns
- Sublime MQL Brand impersonation: SiriusXM
- Sublime MQL Callback phishing solicitation in message body
- Sublime MQL Callback phishing via e-signature service
- Sublime MQL Callback phishing via Google Group abuse
- Sublime MQL Callback phishing via Intuit service abuse
- Sublime MQL Callback phishing via Zoho service abuse
- Sublime MQL Callback phishing: AOL senders with suspicious HTML template or PDF attachment
- Sublime MQL Callback phishing: Social Security Administration fraud
- Sublime MQL Callback phishing: Zero-width character obfuscation from freemail sender
- Sublime MQL Canva infrastructure abuse
- Sublime MQL Link: Invoice or receipt from freemail sender with customer service number
- Sublime MQL Message traversed multiple onmicrosoft.com tenants
- Sublime MQL Reconnaissance: Short generic greeting message
- Sublime MQL Service abuse: Google Drive share from an unsolicited reply-to address
- Sublime MQL Service abuse: Google Drive share from new reply-to domain
- Sublime MQL Service abuse: Google Groups callback scam
- Sublime MQL Spam: Default Microsoft Exchange Online sender domain (onmicrosoft.com)
- Sublime MQL Suspicious mailer received from Gmail servers
Free file host 8 rules
- Sublime MQL Link: Jensi file preview link from unsolicited sender
- Sublime MQL Link: Webflow link from unsolicited sender
- Sublime MQL Link: Zoho form link from unsolicited sender
- Sublime MQL Mismatched links: Free file share with urgent language
- Sublime MQL Service abuse: FileMail callback scam
- Sublime MQL Service abuse: Google Drive share from an unsolicited reply-to address
- Sublime MQL Service abuse: Google Drive share from new reply-to domain
- Sublime MQL Suspicious Links to Cloudflare R2 and Edge Services
Free subdomain host 3 rules
ICS Phishing 3 rules
Image as content 1 rule
Impersonation: Brand 43 rules
- Sublime MQL BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns
- Sublime MQL Body: PayApp transaction reference pattern
- Sublime MQL Brand impersonation: AliExpress
- Sublime MQL Brand impersonation: GitHub with callback scam indicators
- Sublime MQL Brand impersonation: McAfee
- Sublime MQL Brand impersonation: Quickbooks
- Sublime MQL Brand impersonation: SiriusXM
- Sublime MQL Brand impersonation: Vanguard
- Sublime MQL Brand impersonation: WeTransfer
- Sublime MQL Callback phishing solicitation in message body
- Sublime MQL Callback phishing via Adobe Sign comment
- Sublime MQL Callback phishing via Apple ID display name abuse
- Sublime MQL Callback phishing via DocuSign comment
- Sublime MQL Callback phishing via e-signature service
- Sublime MQL Callback phishing via extensionless rfc822 attachment
- Sublime MQL Callback phishing via Google Group abuse
- Sublime MQL Callback phishing via Intuit service abuse
- Sublime MQL Callback phishing via Microsoft comment
- Sublime MQL Callback Phishing via Signable E-Signature Request
- Sublime MQL Callback phishing via SignFree e-signature request
- Sublime MQL Callback phishing via Xodo Sign comment
- Sublime MQL Callback phishing via Yammer comment
- Sublime MQL Callback phishing via Zoho service abuse
- Sublime MQL Callback Phishing via Zoom comment
- Sublime MQL Callback phishing: Branded invoice from sender/reply-to domain less than 30 days old
- Sublime MQL Callback scam: Impersonation via TimeTrade infrastructure
- Sublime MQL Canva infrastructure abuse
- Sublime MQL Link: Invoice or receipt from freemail sender with customer service number
- Sublime MQL Microsoft infrastructure abuse with suspicious patterns
- Sublime MQL Service abuse: Adobe Sign notification from an unsolicited reply-to address
- Sublime MQL Service abuse: AWS SNS callback scam impersonation
- Sublime MQL Service abuse: Calendly callback scam detection
- Sublime MQL Service abuse: Callback phishing via Microsoft Teams invite
- Sublime MQL Service abuse: Coursera callback scam
- Sublime MQL Service abuse: Facebook mail notification callback scam
- Sublime MQL Service abuse: Google classroom solicitation
- Sublime MQL Service abuse: IBM IAM account notification with callback scam indicators
- Sublime MQL Service abuse: Microsoft Power Apps callback scam
- Sublime MQL Service abuse: MongoDB Atlas callback scam
- Sublime MQL Service abuse: Oracle Cloud Workflow callback scam
- Sublime MQL Service abuse: PayPal manager account creation with callback scam indicators
- Sublime MQL Spam: Default Microsoft Exchange Online sender domain (onmicrosoft.com)
- Sublime MQL Venmo payment request abuse
Impersonation: Employee 2 rules
- Sublime MQL Canva infrastructure abuse
- Sublime MQL Service Abuse: Box file sharing with credential phishing intent
Impersonation: VIP 1 rule
Lookalike domain 1 rule
- Sublime MQL Service abuse: Coursera callback scam
Out of band pivot 33 rules
- Sublime MQL Attachment: Callback phishing solicitation via image file
- Sublime MQL Attachment: Callback phishing solicitation via pdf file
- Sublime MQL Attachment: Callback phishing solicitation via text-based file
- Sublime MQL Brand impersonation: GitHub with callback scam indicators
- Sublime MQL Callback phishing in body or attachment (untrusted sender)
- Sublime MQL Callback phishing solicitation in message body
- Sublime MQL Callback phishing via Adobe Sign comment
- Sublime MQL Callback phishing via Apple ID display name abuse
- Sublime MQL Callback phishing via DocuSign comment
- Sublime MQL Callback phishing via Google Meet
- Sublime MQL Callback phishing via Microsoft comment
- Sublime MQL Callback Phishing via Signable E-Signature Request
- Sublime MQL Callback phishing via SignFree e-signature request
- Sublime MQL Callback phishing via Xodo Sign comment
- Sublime MQL Callback phishing via Yammer comment
- Sublime MQL Callback Phishing via Zoom comment
- Sublime MQL Callback phishing: Branded invoice from sender/reply-to domain less than 30 days old
- Sublime MQL Callback phishing: Social Security Administration fraud
- Sublime MQL Callback scam: Impersonation via TimeTrade infrastructure
- Sublime MQL Service abuse: Amazon invitation with suspected callback phishing
- Sublime MQL Service abuse: AWS SNS callback scam impersonation
- Sublime MQL Service abuse: Callback phishing via Microsoft Teams invite
- Sublime MQL Service abuse: FileMail callback scam
- Sublime MQL Service abuse: GetAccept callback scam content
- Sublime MQL Service abuse: Google Calendar notification with callback scam language
- Sublime MQL Service abuse: Google classroom solicitation
- Sublime MQL Service abuse: IBM IAM account notification with callback scam indicators
- Sublime MQL Service abuse: Microsoft Power Apps callback scam
- Sublime MQL Service abuse: Microsoft Power Automate callback scam impersonation
- Sublime MQL Service abuse: Microsoft Power BI callback scam
- Sublime MQL Service abuse: Monday.com callback scam
- Sublime MQL Service abuse: Settime.io sender with callback scam intent
- Sublime MQL Service abuse: WeTransfer callback scam
PDF 5 rules
- Sublime MQL Attachment: Callback phishing solicitation via pdf file
- Sublime MQL Attachment: PDF generated with wkhtmltopdf tool and default title
- Sublime MQL Attachment: PDF with fake invoice using suspicious font sizing
- Sublime MQL Callback phishing: Social Security Administration fraud
- Sublime MQL Stripe invoice abuse
Social engineering 85 rules
- Sublime MQL Attachment: Calendar invite from recently registered domain
- Sublime MQL Attachment: Callback phishing solicitation via image file
- Sublime MQL Attachment: Callback phishing solicitation via pdf file
- Sublime MQL Attachment: Callback phishing solicitation via text-based file
- Sublime MQL Attachment: PDF with fake invoice using suspicious font sizing
- Sublime MQL BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns
- Sublime MQL Body: PayApp transaction reference pattern
- Sublime MQL Brand impersonation: AliExpress
- Sublime MQL Brand impersonation: GitHub with callback scam indicators
- Sublime MQL Brand impersonation: McAfee
- Sublime MQL Brand impersonation: Quickbooks
- Sublime MQL Brand impersonation: QuickBooks notification from Intuit themed company name
- Sublime MQL Brand impersonation: SiriusXM
- Sublime MQL Callback phishing in body or attachment (untrusted sender)
- Sublime MQL Callback phishing solicitation in message body
- Sublime MQL Callback phishing via Adobe Sign comment
- Sublime MQL Callback phishing via Apple ID display name abuse
- Sublime MQL Callback phishing via calendar invite
- Sublime MQL Callback phishing via DocuSign comment
- Sublime MQL Callback phishing via e-signature service
- Sublime MQL Callback phishing via extensionless rfc822 attachment
- Sublime MQL Callback phishing via Google Group abuse
- Sublime MQL Callback phishing via Intuit service abuse
- Sublime MQL Callback phishing via Microsoft comment
- Sublime MQL Callback Phishing via Signable E-Signature Request
- Sublime MQL Callback phishing via SignFree e-signature request
- Sublime MQL Callback phishing via Xodo Sign comment
- Sublime MQL Callback phishing via Yammer comment
- Sublime MQL Callback phishing via Zelle Service Abuse
- Sublime MQL Callback phishing via Zoho service abuse
- Sublime MQL Callback Phishing via Zoom comment
- Sublime MQL Callback phishing: AOL senders with suspicious HTML template or PDF attachment
- Sublime MQL Callback phishing: Branded invoice from sender/reply-to domain less than 30 days old
- Sublime MQL Callback phishing: Social Security Administration fraud
- Sublime MQL Callback phishing: SumUp infrastructure abuse
- Sublime MQL Callback phishing: Zero-width character obfuscation from freemail sender
- Sublime MQL Callback scam: Impersonation via TimeTrade infrastructure
- Sublime MQL Canva infrastructure abuse
- Sublime MQL Display Name Emoji with Financial Symbols
- Sublime MQL Generic service abuse from newly registered domain
- Sublime MQL Inbound message from popular service via newly observed distribution list
- Sublime MQL Link: /index.php enclosed in three asterisks
- Sublime MQL Link: Direct POWR.io Form Builder with suspicious patterns
- Sublime MQL Link: Invoice or receipt from freemail sender with customer service number
- Sublime MQL Microsoft infrastructure abuse with suspicious patterns
- Sublime MQL Mismatched links: Free file share with urgent language
- Sublime MQL PayPal invoice abuse
- Sublime MQL Potential prompt injection attack in body HTML
- Sublime MQL Reconnaissance: Short generic greeting message
- Sublime MQL Service abuse: Adobe Sign notification from an unsolicited reply-to address
- Sublime MQL Service abuse: Amazon invitation with suspected callback phishing
- Sublime MQL Service abuse: AWS SNS callback scam impersonation
- Sublime MQL Service Abuse: Box file sharing with credential phishing intent
- Sublime MQL Service abuse: Calendly callback scam detection
- Sublime MQL Service abuse: Callback phishing via Microsoft Teams invite
- Sublime MQL Service abuse: Coursera callback scam
- Sublime MQL Service abuse: DocuSign notification with suspicious sender or document name
- Sublime MQL Service abuse: Dropbox share from an unsolicited reply-to address
- Sublime MQL Service abuse: Dropbox share from new domain
- Sublime MQL Service abuse: Dropbox share with suspicious sender or document name
- Sublime MQL Service abuse: Facebook mail notification callback scam
- Sublime MQL Service abuse: FileMail callback scam
- Sublime MQL Service abuse: GetAccept callback scam content
- Sublime MQL Service abuse: Google Calendar notification with callback scam language
- Sublime MQL Service abuse: Google classroom solicitation
- Sublime MQL Service abuse: Google Drive share from an unsolicited reply-to address
- Sublime MQL Service abuse: Google Drive share from new reply-to domain
- Sublime MQL Service abuse: Google Groups callback scam
- Sublime MQL Service Abuse: HelloSign share with suspicious sender or document name
- Sublime MQL Service abuse: IBM IAM account notification with callback scam indicators
- Sublime MQL Service abuse: Microsoft Power Apps callback scam
- Sublime MQL Service abuse: Microsoft Power Automate callback scam impersonation
- Sublime MQL Service abuse: Microsoft Power BI callback scam
- Sublime MQL Service abuse: Monday.com callback scam
- Sublime MQL Service abuse: MongoDB Atlas callback scam
- Sublime MQL Service abuse: Oracle Cloud Workflow callback scam
- Sublime MQL Service abuse: Payoneer callback scam
- Sublime MQL Service abuse: PayPal manager account creation with callback scam indicators
- Sublime MQL Service abuse: QuickBooks notification from new domain
- Sublime MQL Service abuse: QuickBooks notification with suspicious comments
- Sublime MQL Service abuse: Settime.io sender with callback scam intent
- Sublime MQL Service abuse: WeTransfer callback scam
- Sublime MQL Spam: Default Microsoft Exchange Online sender domain (onmicrosoft.com)
- Sublime MQL Suspicious mailer received from Gmail servers
- Sublime MQL Venmo payment request abuse
Spoofing 2 rules
Spam
Encryption 1 rule
Evasion 35 rules
- Sublime MQL Body HTML: Comment with 24-character hex token
- Sublime MQL Body: CSS Hidden text via clip-path
- Sublime MQL Body: CSS zero-value calc() obfuscation
- Sublime MQL Body: Embedded email headers indicative of thread hijacking/abuse
- Sublime MQL Body: Invisible Unicode obfuscation student loan callback phishing
- Sublime MQL Credential theft: Gophish abuse with hidden tracking image
- Sublime MQL Encrypted Microsoft Office files from untrusted sender
- Sublime MQL Fake shipping notification with suspicious language
- Sublime MQL Fake thread with suspicious indicators
- Sublime MQL Headers: Invalid recipient domain with mismatched reply-to from new sender
- Sublime MQL Headers: risky-recover-production message ID
- Sublime MQL Link: .su domain link redirection from new sender domains
- Sublime MQL Link: Google Cloud Storage redirect to external domain
- Sublime MQL Link: Google Cloud Storage with short-path link delivery
- Sublime MQL Link: Spam website with evasion indicators
- Sublime MQL Open redirect: Cartoon Network
- Sublime MQL Open redirect: Klaviyo
- Sublime MQL Potential prompt injection attack in body HTML
- Sublime MQL Reconnaissance: Empty message from uncommon sender
- Sublime MQL Sender: IP address in local part
- Sublime MQL Service abuse: Domains By Proxy sender
- Sublime MQL Service abuse: Zoom Clips with unregistered reply-to domain
- Sublime MQL Service abuse: Zoom with newly registered reply-to domain
- Sublime MQL Sharepoint online with external recipients and external display name
- Sublime MQL Spam/fraud: Predatory journal/research paper request
- Sublime MQL Spam: BlackBaud infrastructure abuse
- Sublime MQL Spam: Cold outreach from Cloudflare-hosted newly registered domain
- Sublime MQL Spam: Fake photo share
- Sublime MQL Spam: Firebase password reset from suspicious sender
- Sublime MQL Spam: Sendersrv.com with financial communications and unsubscribe language
- Sublime MQL Spam: Unsolicited malformed PDF
- Sublime MQL Suspicious subject with long procedurally generated text blob
- Sublime MQL Truth Social infrastructure abuse via link redirect
- Sublime MQL Twitter infrastructure abuse via link shortener
- Sublime MQL Unusually long local part from untrusted sender address
Exploit 1 rule
Free email provider 23 rules
- Sublime MQL Attachment: Calendar invite with suspicious link leading to an open redirect
- Sublime MQL Attachment: Romance scam with image lure and advance-fee or suspicious link indicators
- Sublime MQL BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns
- Sublime MQL Brand impersonation: Hulu
- Sublime MQL Brand impersonation: KnowBe4
- Sublime MQL Brand impersonation: SiriusXM
- Sublime MQL Link abuse: Self-service creation platform link with suspicious recipient behavior
- Sublime MQL Link: Google Calendar invite linking to an open redirect from an untrusted freemail sender
- Sublime MQL Link: Observed URL pattern with specific domain registrar
- Sublime MQL Mass campaign: Cross Site Scripting (XSS) attempt
- Sublime MQL Reconnaissance: Email address harvesting attempt
- Sublime MQL Service Abuse: Zoom with freemail reply-to and recipient address in greeting
- Sublime MQL Spam: Default Microsoft Exchange Online sender domain (onmicrosoft.com)
- Sublime MQL Spam: Fake dating profile notification
- Sublime MQL Spam: New link domain (<=10d) and emojis
- Sublime MQL Spam: Sexually explicit content with emoji in subject from freemail provider
- Sublime MQL Spam: Sexually explicit Google Drive share
- Sublime MQL Spam: Sexually explicit Google group invitation
- Sublime MQL Spam: Sexually explicit Looker Studio report
- Sublime MQL Spam: SMTP & Proxy Communications in Email Body
- Sublime MQL Spam: Unsolicited malformed PDF
- Sublime MQL Spam: URL shortener with short body content and emojis
- Sublime MQL Suspicious mailer received from Gmail servers
Free file host 10 rules
- Sublime MQL Attachment: Calendar invite with suspicious link leading to an open redirect
- Sublime MQL Attachment: Romance scam with image lure and advance-fee or suspicious link indicators
- Sublime MQL Fake shipping notification with link to free file hosting
- Sublime MQL Invoicera infrastructure abuse
- Sublime MQL Link: Google Calendar invite linking to an open redirect from an untrusted freemail sender
- Sublime MQL Link: Google Cloud Storage redirect to external domain
- Sublime MQL Link: Google Cloud Storage with short-path link delivery
- Sublime MQL Mismatched links: Free file share with urgent language
- Sublime MQL Spam: Campaign with excessive space/char obfuscation and free file hosted link
- Sublime MQL Suspicious Links to Cloudflare R2 and Edge Services
Free subdomain host 5 rules
- Sublime MQL Attachment: Calendar invite with suspicious link leading to an open redirect
- Sublime MQL Invoicera infrastructure abuse
- Sublime MQL Link: Blogspot hosting explicit romance content
- Sublime MQL Service abuse: Google Firebase sender address with suspicious content
- Sublime MQL Spam: Link to blob.core.windows.net from new domain (<30d)
ICS Phishing 2 rules
Image as content 7 rules
- Sublime MQL Attachment: Cold outreach with invitation subject and not attachment
- Sublime MQL Attachment: Romance scam with image lure and advance-fee or suspicious link indicators
- Sublime MQL Credential theft: Gophish abuse with hidden tracking image
- Sublime MQL Invoicera infrastructure abuse
- Sublime MQL Spam: BlackBaud infrastructure abuse
- Sublime MQL Spam: Item giveaway spam template
- Sublime MQL Spam: Mastercard promotional content with image-based body
Impersonation: Brand 25 rules
- Sublime MQL BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns
- Sublime MQL Brand impersonation: Hulu
- Sublime MQL Brand impersonation: KnowBe4
- Sublime MQL Brand impersonation: SendGrid
- Sublime MQL Brand Impersonation: Shein
- Sublime MQL Brand impersonation: SiriusXM
- Sublime MQL Brand impersonation: Vanguard
- Sublime MQL Brand impersonation: WeTransfer
- Sublime MQL Fake shipping notification with link to free file hosting
- Sublime MQL Link: Google Cloud Storage redirect to external domain
- Sublime MQL Link: Google Cloud Storage with short-path link delivery
- Sublime MQL Link: Squarespace infrastructure abuse
- Sublime MQL Open redirect: Klaviyo
- Sublime MQL Service abuse: Adobe Sign notification from an unsolicited reply-to address
- Sublime MQL Service abuse: Demio notifications with suspicious content patterns
- Sublime MQL Service abuse: Microsoft with suspicious indicators in subject
- Sublime MQL Spam/fraud: Predatory journal/research paper request
- Sublime MQL Spam: BlackBaud infrastructure abuse
- Sublime MQL Spam: Commonly observed formatting of unauthorized free giveaways
- Sublime MQL Spam: Cryptocurrency airdrop/giveaway
- Sublime MQL Spam: Default Microsoft Exchange Online sender domain (onmicrosoft.com)
- Sublime MQL Spam: Mastercard promotional content with image-based body
- Sublime MQL Spam: Single recipient duplicated in cc
- Sublime MQL Truth Social infrastructure abuse via link redirect
- Sublime MQL Twitter infrastructure abuse via link shortener
Lookalike domain 4 rules
- Sublime MQL Brand impersonation: Anthropic/Claude with newly registered domain
- Sublime MQL Brand impersonation: Hulu
- Sublime MQL Brand impersonation: KnowBe4
- Sublime MQL Spam/fraud: Predatory journal/research paper request
Open redirect 6 rules
- Sublime MQL Attachment: Calendar invite with suspicious link leading to an open redirect
- Sublime MQL Link: .su domain link redirection from new sender domains
- Sublime MQL Link: Google Calendar invite linking to an open redirect from an untrusted freemail sender
- Sublime MQL Link: Google Cloud Storage redirect to external domain
- Sublime MQL Open redirect: Cartoon Network
- Sublime MQL Open redirect: Klaviyo
Out of band pivot 2 rules
PDF 1 rule
- Sublime MQL Spam: Unsolicited malformed PDF
Scripting 1 rule
Social engineering 66 rules
- Sublime MQL Attachment: Cold outreach with invitation subject and not attachment
- Sublime MQL Attachment: Romance scam with image lure and advance-fee or suspicious link indicators
- Sublime MQL BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns
- Sublime MQL Body: Embedded email headers indicative of thread hijacking/abuse
- Sublime MQL Body: Invisible Unicode obfuscation student loan callback phishing
- Sublime MQL Brand impersonation: Anthropic/Claude with newly registered domain
- Sublime MQL Brand impersonation: Hulu
- Sublime MQL Brand impersonation: KnowBe4
- Sublime MQL Brand impersonation: SendGrid
- Sublime MQL Brand Impersonation: Shein
- Sublime MQL Brand impersonation: SiriusXM
- Sublime MQL Fake shipping notification with link to free file hosting
- Sublime MQL Fake thread with suspicious indicators
- Sublime MQL Headers: Invalid recipient domain with mismatched reply-to from new sender
- Sublime MQL Invoicera infrastructure abuse
- Sublime MQL Link abuse: Self-service creation platform link with suspicious recipient behavior
- Sublime MQL Link: .su domain link redirection from new sender domains
- Sublime MQL Link: Blogspot hosting explicit romance content
- Sublime MQL Link: Google Calendar invite linking to an open redirect from an untrusted freemail sender
- Sublime MQL Link: Google Cloud Storage redirect to external domain
- Sublime MQL Link: Google Cloud Storage with short-path link delivery
- Sublime MQL Link: Romance/Sexual Language With Suspicious Link
- Sublime MQL Link: Squarespace infrastructure abuse
- Sublime MQL Link: Suspicious single-domain link with suspicious path and financial lure indicators
- Sublime MQL Mass campaign: Cross Site Scripting (XSS) attempt
- Sublime MQL Message content: Request for author engagement
- Sublime MQL Mismatched links: Free file share with urgent language
- Sublime MQL Open redirect: Klaviyo
- Sublime MQL Potential prompt injection attack in body HTML
- Sublime MQL Reconnaissance: Email address harvesting attempt
- Sublime MQL Reconnaissance: Empty message from uncommon sender
- Sublime MQL Service abuse: Adobe Sign notification from an unsolicited reply-to address
- Sublime MQL Service abuse: Apple TestFlight with suspicious developer reference
- Sublime MQL Service abuse: Demio notifications with suspicious content patterns
- Sublime MQL Service abuse: Domains By Proxy sender
- Sublime MQL Service abuse: Google Firebase sender address with suspicious content
- Sublime MQL Service abuse: Microsoft with suspicious indicators in subject
- Sublime MQL Service abuse: Zohodesk reply-to mismatch with job scam indicators
- Sublime MQL Service abuse: Zoom Clips with unregistered reply-to domain
- Sublime MQL Service Abuse: Zoom with freemail reply-to and recipient address in greeting
- Sublime MQL Service abuse: Zoom with newly registered reply-to domain
- Sublime MQL Spam/fraud: Predatory journal/research paper request
- Sublime MQL Spam: BlackBaud infrastructure abuse
- Sublime MQL Spam: Cold outreach from Cloudflare-hosted newly registered domain
- Sublime MQL Spam: Commonly observed formatting of unauthorized free giveaways
- Sublime MQL Spam: Cryptocurrency airdrop/giveaway
- Sublime MQL Spam: Default Microsoft Exchange Online sender domain (onmicrosoft.com)
- Sublime MQL Spam: Fake dating profile notification
- Sublime MQL Spam: Fake photo share
- Sublime MQL Spam: Firebase password reset from suspicious sender
- Sublime MQL Spam: Ghostwriting services scam with manipulative language
- Sublime MQL Spam: Large financial amount mention from newly registered sender domain
- Sublime MQL Spam: Mastercard promotional content with image-based body
- Sublime MQL Spam: Personalized subject and greetings via Salesforce Marketing Cloud
- Sublime MQL Spam: Sendersrv.com with financial communications and unsubscribe language
- Sublime MQL Spam: Sexually explicit content with emoji in subject from freemail provider
- Sublime MQL Spam: Sexually explicit Google Drive share
- Sublime MQL Spam: Sexually explicit Google group invitation
- Sublime MQL Spam: Sexually explicit Looker Studio report
- Sublime MQL Spam: Single recipient duplicated in cc
- Sublime MQL Spam: Suspicious toll-free phone number
- Sublime MQL Spam: Unsolicited WordPress account creation or password reset request
- Sublime MQL Suspicious mailer received from Gmail servers
- Sublime MQL Targeting: Specific AOL address
- Sublime MQL Truth Social infrastructure abuse via link redirect
- Sublime MQL Twitter infrastructure abuse via link shortener
Spoofing 4 rules
No specific technique 4 rules
- Sublime MQL Spam: Attendee list solicitation
- Sublime MQL Spam: Campaign with excessive display-text and keywords found
- Sublime MQL Spam: New job cold outreach from unsolicited sender
- Sublime MQL Spam: Website errors solicitation
Extortion
Encryption 1 rule
Evasion 4 rules
Free file host 2 rules
Impersonation: Brand 5 rules
- Sublime MQL Brand impersonation: Vanguard
- Sublime MQL Brand impersonation: WeTransfer
- Sublime MQL Impersonation: Australian Federal Police with criminal case language
- Sublime MQL Impersonation: Legal firm with copyright infringement notice
- Sublime MQL Service abuse: Elastic alerts extortion
PDF 1 rule
Social engineering 8 rules
- Sublime MQL Attachment: Legal themed message or PDF with suspicious indicators
- Sublime MQL Extortion / sextortion (untrusted sender)
- Sublime MQL Extortion / sextortion in attachment from untrusted sender
- Sublime MQL Impersonation: Australian Federal Police with criminal case language
- Sublime MQL Impersonation: Legal firm with copyright infringement notice
- Sublime MQL Mismatched links: Free file share with urgent language
- Sublime MQL Potential prompt injection attack in body HTML
- Sublime MQL Service abuse: Elastic alerts extortion
Spoofing 2 rules
Reconnaissance
No specific technique 2 rules
DLP: Credential Exposure
No specific technique 7 rules
- Sublime MQL beta.DLP: AWS Access Key
- Sublime MQL beta.DLP: Basic Auth Header
- Sublime MQL beta.DLP: GitHub Token
- Sublime MQL beta.DLP: OAuth Client Secret
- Sublime MQL beta.DLP: Private Key
- Sublime MQL beta.DLP: SSL/TLS Certificate
- Sublime MQL DLP - Clear-Text Credentials Outbound
DLP: Data Exfiltration
No specific technique 1 rule
- Sublime MQL DLP - Outbound to Personal Email Domains
DLP: Financial
No specific technique 4 rules
- Sublime MQL beta.DLP: Crypto Wallet Address
- Sublime MQL beta.DLP: IBAN Code
- Sublime MQL beta.DLP: US ABA Routing Number
- Sublime MQL beta.DLP: US Bank Account Number
DLP: Financial Data
No specific technique 1 rule
- Sublime MQL beta.DLP: SWIFT/BIC Code
DLP: GDPR
No specific technique 6 rules
- Sublime MQL beta.DLP: NHS Number
- Sublime MQL beta.DLP: UK Driver's License
- Sublime MQL beta.DLP: UK Electoral Roll
- Sublime MQL beta.DLP: UK National Insurance Number
- Sublime MQL beta.DLP: UK Passport
- Sublime MQL beta.DLP: UK UTR (Tax)
DLP: HIPAA
No specific technique 3 rules
- Sublime MQL beta.DLP: ICD-10 Code
- Sublime MQL beta.DLP: ICD-9 Code
- Sublime MQL beta.DLP: US Social Security Number (SSN)
DLP: Infrastructure
No specific technique 2 rules
- Sublime MQL beta.DLP: IP Address
- Sublime MQL beta.DLP: SSL/TLS Certificate
DLP: PCI
No specific technique 4 rules
- Sublime MQL beta.DLP: IBAN Code
- Sublime MQL beta.DLP: PCI US Credit Card Number (Any Network)
- Sublime MQL beta.DLP: US ABA Routing Number
- Sublime MQL beta.DLP: US Bank Account Number
DLP: PII
No specific technique 13 rules
- Sublime MQL beta.DLP: Canadian Social Insurance Number (SIN)
- Sublime MQL beta.DLP: Date of Birth
- Sublime MQL beta.DLP: NHS Number
- Sublime MQL beta.DLP: Person Name
- Sublime MQL beta.DLP: Phone Number
- Sublime MQL beta.DLP: UK Driver's License
- Sublime MQL beta.DLP: UK National Insurance Number
- Sublime MQL beta.DLP: UK Passport
- Sublime MQL beta.DLP: US Driver's License
- Sublime MQL beta.DLP: US Individual Taxpayer Identification Number (ITIN)
- Sublime MQL beta.DLP: US Passport Number
- Sublime MQL beta.DLP: US Physical Address
- Sublime MQL beta.DLP: US Social Security Number (SSN)
ICS Phishing
Social engineering 1 rule
Uncategorized
Evasion 1 rule
Free subdomain host 1 rule
HTML smuggling 2 rules
- Sublime MQL Attachment: Any HTML file (unsolicited)
- Sublime MQL Attachment: Any HTML file (untrusted sender)
ICS Phishing 1 rule
Impersonation: VIP 1 rule
Social engineering 1 rule
Spoofing 2 rules
- Sublime MQL SPF temp error
- Sublime MQL VIP local_part impersonation from unsolicited sender
Cloud & SaaS activity monitoring
Cloud, SaaS, and identity governance: app registrations, OAuth grants, role and permission changes, sharing and config drift -- audit activity no single ATT&CK technique describes.Veeam 96 rules
GCP 30 rules
AWS 27 rules
Kubernetes 24 rules
Google Workspace 17 rules
Auth0 16 rules
Notion 16 rules
Duo 15 rules
Entra ID / Azure AD 15 rules
GitHub 15 rules
Okta 14 rules
Snowflake 13 rules
Asana 11 rules
Snyk 10 rules
Dropbox 9 rules
Tines 9 rules
Microsoft Graph 7 rules
Push Security 7 rules
Zoom 7 rules
MongoDB 6 rules
Docusign 5 rules
Microsoft 365 5 rules
Axonius 4 rules
VMware SD-WAN and SASE 4 rules
CrowdStrike 3 rules
OneLogin 3 rules
Tailscale 3 rules
Other cloud & SaaS 19 rules
Endpoint & network anomalies
Statistical and behavioral outliers on hosts and networks: process-tree analysis, command-line and volume spikes, baselining.Panther 17 rules
Splunk 6 rules
Kusto 4 rules
YARA-L 4 rules
Elastic 2 rules
Threat-intelligence matching
Indicator and reputation matching: hash, IP, URL, and domain lookups against threat feeds, VirusTotal, Safebrowsing, and prevalence sources.YARA-L 28 rules
Panther 15 rules
Elastic 7 rules
Splunk 2 rules
Sublime MQL 1 rule
Alert correlation & meta-detections
Meta-detections that consume the output of other detections or tools: multi-alert aggregation and vendor-verdict passthroughs.Elastic 33 rules
Panther 28 rules
Kusto 17 rules
Splunk 4 rules
Sigma 2 rules
YARA-L 1 rule
Threat hunting
Exploratory hunting queries that surface broad activity for analyst triage rather than firing on a specific malicious match.YARA-L 17 rules
Kusto 7 rules
Panther 1 rule
AI & LLM governance
AI and LLM content-safety and governance: prompt-injection, toxicity, bias, banned-topic, and model-policy violations.Kusto 38 rules
Elastic 2 rules
Splunk 1 rule
Data loss prevention
Data-loss-prevention content patterns: payment cards, national IDs, passports, bank accounts, and other regulated or sensitive data.National IDs & passports 33 rules
Payment cards (PCI) 17 rules
Bank & financial accounts 15 rules
Health & medical 3 rules
Other sensitive data 62 rules
Operational & security hygiene
Operational and security-hygiene checks: agent and signature staleness, unsupported versions, deployment posture, and outbreak thresholds.Panther 46 rules
Kusto 22 rules
Sigma 3 rules
Splunk 3 rules
Elastic 1 rule