Lab Tool

Sigma Rule Library

Example detection rules for common phishing TTPs, generated by the same rule-building engine /phish-report runs per analyzed message, fed synthetic, made-up indicators here rather than a real report.

Note: Every domain, hash, and subject line below is fictional, for illustration only. Each rule is explicitly a starting point. See the comments inside each one before using it anywhere.

Credential Phishing Link

A message pretending to be an account-security notice, driving the reader to a lookalike login page.

# Generated by the farksecurity.com phish-report analyzer.
#
# STARTING POINT, NOT A FINISHED RULE. Email telemetry field names differ
# per platform (Defender, Proofpoint, Mimecast, a mail gateway log...), so
# map sender / reply_to / url / attachment_name / attachment_hash / subject
# onto whatever your pipeline actually calls them before deploying. Review
# each selection: the sender domain may be a compromised legitimate host you
# do not want to block outright, and subject keywords are the most
# false-positive-prone part. attachment_hash is the exception — an exact
# hash match is high-confidence on its own and worth keeping as-is.

title: 'Phishing indicators observed in message - Your account will be suspended - verify now'
id: bdb8bfdc-8a4b-4d72-9872-6a8b8b6566a1
status: experimental
description: 'Indicators extracted from a single message assessed as High Risk (78/100) by heuristic analysis.'
author: farksecurity.com phish-report
date: 2026-09-27
logsource:
  category: mail
detection:
  sender_domain:
    sender|endswith:
      - '@paypa1-secure.com'
  link_hosts:
    url|contains:
      - 'paypa1-secure.com'
  subject_keywords:
    subject|contains|all:
      - 'account'
      - 'suspended'
      - 'verify'
  condition: sender_domain or link_hosts or subject_keywords
falsepositives:
  - Legitimate mail from a compromised but otherwise trusted sender
  - Shared sending infrastructure where the domain is not attacker-controlled
  - Subject keywords appearing in unrelated legitimate correspondence
level: high
tags:
  - attack.t1204.001
  - attack.t1566.002

Malicious Attachment (Double Extension)

An invoice-themed message carrying an executable disguised as a PDF via a double extension.

# Generated by the farksecurity.com phish-report analyzer.
#
# STARTING POINT, NOT A FINISHED RULE. Email telemetry field names differ
# per platform (Defender, Proofpoint, Mimecast, a mail gateway log...), so
# map sender / reply_to / url / attachment_name / attachment_hash / subject
# onto whatever your pipeline actually calls them before deploying. Review
# each selection: the sender domain may be a compromised legitimate host you
# do not want to block outright, and subject keywords are the most
# false-positive-prone part. attachment_hash is the exception — an exact
# hash match is high-confidence on its own and worth keeping as-is.

title: 'Phishing indicators observed in message - Invoice_2026_04521 - please review and remit'
id: 44503ed2-83fe-4baa-90c0-17278457c535
status: experimental
description: 'Indicators extracted from a single message assessed as High Risk (82/100) by heuristic analysis.'
author: farksecurity.com phish-report
date: 2026-09-27
logsource:
  category: mail
detection:
  sender_domain:
    sender|endswith:
      - '@invoices-billing-support.com'
  attachment_type:
    attachment_name|endswith:
      - '.exe'
  attachment_hash:
    attachment_hash|contains:
      - 'e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855'
  subject_keywords:
    subject|contains|all:
      - 'invoice'
      - '2026'
      - '04521'
  condition: sender_domain or attachment_type or attachment_hash or subject_keywords
falsepositives:
  - Legitimate mail from a compromised but otherwise trusted sender
  - Shared sending infrastructure where the domain is not attacker-controlled
  - Subject keywords appearing in unrelated legitimate correspondence
level: high
tags:
  - attack.t1036.007
  - attack.t1204.002
  - attack.t1566.001

BEC Reply-To Redirect

A wire-transfer request whose From address looks legitimate, but replies are quietly redirected to a lookalike domain.

# Generated by the farksecurity.com phish-report analyzer.
#
# STARTING POINT, NOT A FINISHED RULE. Email telemetry field names differ
# per platform (Defender, Proofpoint, Mimecast, a mail gateway log...), so
# map sender / reply_to / url / attachment_name / attachment_hash / subject
# onto whatever your pipeline actually calls them before deploying. Review
# each selection: the sender domain may be a compromised legitimate host you
# do not want to block outright, and subject keywords are the most
# false-positive-prone part. attachment_hash is the exception — an exact
# hash match is high-confidence on its own and worth keeping as-is.

title: 'Phishing indicators observed in message - Re: Wire transfer approval needed today'
id: 05ef56ee-cc8c-48ac-a67e-8e8ab760c7e4
status: experimental
description: 'Indicators extracted from a single message assessed as Medium Risk (45/100) by heuristic analysis.'
author: farksecurity.com phish-report
date: 2026-09-27
logsource:
  category: mail
detection:
  sender_domain:
    sender|endswith:
      - '@executive-office.com'
  reply_to_domain:
    reply_to|endswith:
      - '@executive-0ffice.com'
  subject_keywords:
    subject|contains|all:
      - 'wire'
      - 'transfer'
      - 'approval'
  condition: sender_domain or reply_to_domain or subject_keywords
falsepositives:
  - Legitimate mail from a compromised but otherwise trusted sender
  - Shared sending infrastructure where the domain is not attacker-controlled
  - Subject keywords appearing in unrelated legitimate correspondence
level: medium
tags:
  - attack.t1656

Internal Spearphishing

A message from a likely-compromised internal account, sent to other employees inside the same organization.

# Generated by the farksecurity.com phish-report analyzer.
#
# STARTING POINT, NOT A FINISHED RULE. Email telemetry field names differ
# per platform (Defender, Proofpoint, Mimecast, a mail gateway log...), so
# map sender / reply_to / url / attachment_name / attachment_hash / subject
# onto whatever your pipeline actually calls them before deploying. Review
# each selection: the sender domain may be a compromised legitimate host you
# do not want to block outright, and subject keywords are the most
# false-positive-prone part. attachment_hash is the exception — an exact
# hash match is high-confidence on its own and worth keeping as-is.

title: 'Phishing indicators observed in message - IT: Password Reset Required'
id: 5bb04fca-2e8f-4107-b369-6e2da61760ec
status: experimental
description: 'Indicators extracted from a single message assessed as High Risk (65/100) by heuristic analysis.'
author: farksecurity.com phish-report
date: 2026-09-27
logsource:
  category: mail
detection:
  sender_domain:
    sender|endswith:
      - '@corp-example.com'
  link_hosts:
    url|contains:
      - 'corp-example-portal.net'
  subject_keywords:
    subject|contains|all:
      - 'password'
      - 'reset'
      - 'required'
  condition: sender_domain or link_hosts or subject_keywords
falsepositives:
  - Legitimate mail from a compromised but otherwise trusted sender
  - Shared sending infrastructure where the domain is not attacker-controlled
  - Subject keywords appearing in unrelated legitimate correspondence
level: high
tags:
  - attack.t1534
  - attack.t1566.002

Spearphishing for Information

A pretext survey or verification form designed to harvest information rather than credentials directly.

# Generated by the farksecurity.com phish-report analyzer.
#
# STARTING POINT, NOT A FINISHED RULE. Email telemetry field names differ
# per platform (Defender, Proofpoint, Mimecast, a mail gateway log...), so
# map sender / reply_to / url / attachment_name / attachment_hash / subject
# onto whatever your pipeline actually calls them before deploying. Review
# each selection: the sender domain may be a compromised legitimate host you
# do not want to block outright, and subject keywords are the most
# false-positive-prone part. attachment_hash is the exception — an exact
# hash match is high-confidence on its own and worth keeping as-is.

title: 'Phishing indicators observed in message - Please confirm your details for the upcoming audit'
id: fb3cc593-a50e-46d3-b5d2-78f0d6f543a5
status: experimental
description: 'Indicators extracted from a single message assessed as Medium Risk (40/100) by heuristic analysis.'
author: farksecurity.com phish-report
date: 2026-09-27
logsource:
  category: mail
detection:
  sender_domain:
    sender|endswith:
      - '@hr-benefits-verify.com'
  link_hosts:
    url|contains:
      - 'hr-benefits-verify.com'
  subject_keywords:
    subject|contains|all:
      - 'please'
      - 'confirm'
      - 'details'
  condition: sender_domain or link_hosts or subject_keywords
falsepositives:
  - Legitimate mail from a compromised but otherwise trusted sender
  - Shared sending infrastructure where the domain is not attacker-controlled
  - Subject keywords appearing in unrelated legitimate correspondence
level: medium
tags:
  - attack.t1598.003