Lab Tool
Sigma Rule Library
Example detection rules for common phishing TTPs, generated by the same rule-building engine /phish-report runs per analyzed message, fed synthetic, made-up indicators here rather than a real report.
Note: Every domain, hash, and subject line below is fictional, for illustration only. Each rule is explicitly a starting point. See the comments inside each one before using it anywhere.
Credential Phishing Link
A message pretending to be an account-security notice, driving the reader to a lookalike login page.
# Generated by the farksecurity.com phish-report analyzer.
#
# STARTING POINT, NOT A FINISHED RULE. Email telemetry field names differ
# per platform (Defender, Proofpoint, Mimecast, a mail gateway log...), so
# map sender / reply_to / url / attachment_name / attachment_hash / subject
# onto whatever your pipeline actually calls them before deploying. Review
# each selection: the sender domain may be a compromised legitimate host you
# do not want to block outright, and subject keywords are the most
# false-positive-prone part. attachment_hash is the exception — an exact
# hash match is high-confidence on its own and worth keeping as-is.
title: 'Phishing indicators observed in message - Your account will be suspended - verify now'
id: bdb8bfdc-8a4b-4d72-9872-6a8b8b6566a1
status: experimental
description: 'Indicators extracted from a single message assessed as High Risk (78/100) by heuristic analysis.'
author: farksecurity.com phish-report
date: 2026-09-27
logsource:
category: mail
detection:
sender_domain:
sender|endswith:
- '@paypa1-secure.com'
link_hosts:
url|contains:
- 'paypa1-secure.com'
subject_keywords:
subject|contains|all:
- 'account'
- 'suspended'
- 'verify'
condition: sender_domain or link_hosts or subject_keywords
falsepositives:
- Legitimate mail from a compromised but otherwise trusted sender
- Shared sending infrastructure where the domain is not attacker-controlled
- Subject keywords appearing in unrelated legitimate correspondence
level: high
tags:
- attack.t1204.001
- attack.t1566.002
Malicious Attachment (Double Extension)
An invoice-themed message carrying an executable disguised as a PDF via a double extension.
# Generated by the farksecurity.com phish-report analyzer.
#
# STARTING POINT, NOT A FINISHED RULE. Email telemetry field names differ
# per platform (Defender, Proofpoint, Mimecast, a mail gateway log...), so
# map sender / reply_to / url / attachment_name / attachment_hash / subject
# onto whatever your pipeline actually calls them before deploying. Review
# each selection: the sender domain may be a compromised legitimate host you
# do not want to block outright, and subject keywords are the most
# false-positive-prone part. attachment_hash is the exception — an exact
# hash match is high-confidence on its own and worth keeping as-is.
title: 'Phishing indicators observed in message - Invoice_2026_04521 - please review and remit'
id: 44503ed2-83fe-4baa-90c0-17278457c535
status: experimental
description: 'Indicators extracted from a single message assessed as High Risk (82/100) by heuristic analysis.'
author: farksecurity.com phish-report
date: 2026-09-27
logsource:
category: mail
detection:
sender_domain:
sender|endswith:
- '@invoices-billing-support.com'
attachment_type:
attachment_name|endswith:
- '.exe'
attachment_hash:
attachment_hash|contains:
- 'e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855'
subject_keywords:
subject|contains|all:
- 'invoice'
- '2026'
- '04521'
condition: sender_domain or attachment_type or attachment_hash or subject_keywords
falsepositives:
- Legitimate mail from a compromised but otherwise trusted sender
- Shared sending infrastructure where the domain is not attacker-controlled
- Subject keywords appearing in unrelated legitimate correspondence
level: high
tags:
- attack.t1036.007
- attack.t1204.002
- attack.t1566.001
BEC Reply-To Redirect
A wire-transfer request whose From address looks legitimate, but replies are quietly redirected to a lookalike domain.
# Generated by the farksecurity.com phish-report analyzer.
#
# STARTING POINT, NOT A FINISHED RULE. Email telemetry field names differ
# per platform (Defender, Proofpoint, Mimecast, a mail gateway log...), so
# map sender / reply_to / url / attachment_name / attachment_hash / subject
# onto whatever your pipeline actually calls them before deploying. Review
# each selection: the sender domain may be a compromised legitimate host you
# do not want to block outright, and subject keywords are the most
# false-positive-prone part. attachment_hash is the exception — an exact
# hash match is high-confidence on its own and worth keeping as-is.
title: 'Phishing indicators observed in message - Re: Wire transfer approval needed today'
id: 05ef56ee-cc8c-48ac-a67e-8e8ab760c7e4
status: experimental
description: 'Indicators extracted from a single message assessed as Medium Risk (45/100) by heuristic analysis.'
author: farksecurity.com phish-report
date: 2026-09-27
logsource:
category: mail
detection:
sender_domain:
sender|endswith:
- '@executive-office.com'
reply_to_domain:
reply_to|endswith:
- '@executive-0ffice.com'
subject_keywords:
subject|contains|all:
- 'wire'
- 'transfer'
- 'approval'
condition: sender_domain or reply_to_domain or subject_keywords
falsepositives:
- Legitimate mail from a compromised but otherwise trusted sender
- Shared sending infrastructure where the domain is not attacker-controlled
- Subject keywords appearing in unrelated legitimate correspondence
level: medium
tags:
- attack.t1656
Internal Spearphishing
A message from a likely-compromised internal account, sent to other employees inside the same organization.
# Generated by the farksecurity.com phish-report analyzer.
#
# STARTING POINT, NOT A FINISHED RULE. Email telemetry field names differ
# per platform (Defender, Proofpoint, Mimecast, a mail gateway log...), so
# map sender / reply_to / url / attachment_name / attachment_hash / subject
# onto whatever your pipeline actually calls them before deploying. Review
# each selection: the sender domain may be a compromised legitimate host you
# do not want to block outright, and subject keywords are the most
# false-positive-prone part. attachment_hash is the exception — an exact
# hash match is high-confidence on its own and worth keeping as-is.
title: 'Phishing indicators observed in message - IT: Password Reset Required'
id: 5bb04fca-2e8f-4107-b369-6e2da61760ec
status: experimental
description: 'Indicators extracted from a single message assessed as High Risk (65/100) by heuristic analysis.'
author: farksecurity.com phish-report
date: 2026-09-27
logsource:
category: mail
detection:
sender_domain:
sender|endswith:
- '@corp-example.com'
link_hosts:
url|contains:
- 'corp-example-portal.net'
subject_keywords:
subject|contains|all:
- 'password'
- 'reset'
- 'required'
condition: sender_domain or link_hosts or subject_keywords
falsepositives:
- Legitimate mail from a compromised but otherwise trusted sender
- Shared sending infrastructure where the domain is not attacker-controlled
- Subject keywords appearing in unrelated legitimate correspondence
level: high
tags:
- attack.t1534
- attack.t1566.002
Spearphishing for Information
A pretext survey or verification form designed to harvest information rather than credentials directly.
# Generated by the farksecurity.com phish-report analyzer.
#
# STARTING POINT, NOT A FINISHED RULE. Email telemetry field names differ
# per platform (Defender, Proofpoint, Mimecast, a mail gateway log...), so
# map sender / reply_to / url / attachment_name / attachment_hash / subject
# onto whatever your pipeline actually calls them before deploying. Review
# each selection: the sender domain may be a compromised legitimate host you
# do not want to block outright, and subject keywords are the most
# false-positive-prone part. attachment_hash is the exception — an exact
# hash match is high-confidence on its own and worth keeping as-is.
title: 'Phishing indicators observed in message - Please confirm your details for the upcoming audit'
id: fb3cc593-a50e-46d3-b5d2-78f0d6f543a5
status: experimental
description: 'Indicators extracted from a single message assessed as Medium Risk (40/100) by heuristic analysis.'
author: farksecurity.com phish-report
date: 2026-09-27
logsource:
category: mail
detection:
sender_domain:
sender|endswith:
- '@hr-benefits-verify.com'
link_hosts:
url|contains:
- 'hr-benefits-verify.com'
subject_keywords:
subject|contains|all:
- 'please'
- 'confirm'
- 'details'
condition: sender_domain or link_hosts or subject_keywords
falsepositives:
- Legitimate mail from a compromised but otherwise trusted sender
- Shared sending infrastructure where the domain is not attacker-controlled
- Subject keywords appearing in unrelated legitimate correspondence
level: medium
tags:
- attack.t1598.003