> For the complete documentation index, see [llms.txt](https://docs.material.security/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.material.security/learn-more/risk-areas/email-threats/detect/material-email-threat-detections.md).

# Material Email Threat Detections

Material Detections protect against numerous attacker tactics and methods. These tactics, techniques, and procedures (TTP) are constantly changing; we update Email Threat Protection often to account for the ever-changing nature of phishing attacks. We send release notes in Slack and update [What's New](/whats-new.md) with those changes.

Material Detections are enabled by default. [Customize your response and remediation as needed](/learn-more/risk-areas/email-threats/auto-respond.md).

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXcRjKe5WC-1OIqGhKKZrV82M1KKIOpBsy2JEbYnytr2BL2QCc3S3cPRq3LFVRUQRY5Qi1jICFNqD0wBAkX18yfa_8mQQrsH-mTEpYpEjA38yXoVbRjDaIcQKXF5QniKVCI4eEhvvw?key=ODnCgu6jY0Il7_5uYj_u2L0q" alt=""><figcaption><p>Some of the tactics, techniques, and procedures</p></figcaption></figure>

{% hint style="info" %}
You can get a visual understanding of what trends look like in your issues in [Reports](/learn-more/risk-areas/email-threats/reports.md).

You can filter by these objective and tactics in [Issues](/getting-started/fundamentals/investigate.md).
{% endhint %}

Some of the detections we include are:

### Objectives

<details>

<summary>Credential Theft</summary>

* **Brand Impersonation**: Messages attempting to steal login credentials from the recipient by impersonating a major brand.
* **Fake Login Page**: Messages attempting to steal login credentials from the recipient by directing them to a malicious URL that impersonates a known identity provider before providing access to the resource.

</details>

<details>

<summary>Fraud and BEC (Business Email Compromise)</summary>

* **Callback Fraud:** Messages containing a fraudulent customer support phone number that leads to a scam call center when dialed.
* **Crypto Fraud:** Messages advertising a fraudulent cryptocurrency airdrop, giveaway, or pyramid scheme.
* **Extortion:** Messages attempting to blackmail the recipient, typically by threatening to expose sensitive or embarrassing information and requesting payment in cryptocurrency.
* **Gift Card Fraud:** Messages attempting to socially engineer the recipient into purchasing gift cards for the sender.
* **Invoice Fraud:** Messages impersonating a vendor, or sent via a compromised vendor account, that include payment instructions directing funds to a bank account controlled by the attacker.
* **Payroll Fraud:** Messages impersonating an employee that attempt to socially engineer the recipient to change payroll information to a bank account controlled by the attacker
* **PII (Personal, Identifiable, Information) Theft:** Messages attempting to socially engineer the recipient into divulging additional contact methods or personal information.

</details>

<details>

<summary>Malware and Ransomware</summary>

* **Malware Link:** Messages that include a link to download a first-stage loader, spyware, infostealer, or other malware from an external website.
* **Malware Payload:** Messages which include a malicious attachment that will install a first-stage loader, spyware, infostealer, or other malware.
* **Ransomware Link:** Messages that include a link to download a known ransomware variant from an external website.
* **Ransomware Payload:** Messages which include a malicious attachment that will install a known ransomware variant when downloaded and opened by the recipient.

</details>

### Tactics and Techniques

<details>

<summary>Account Compromise</summary>

* **Compromised External Sender:** A legitimate third-party account that has been hijacked and is being used to send phishing emails, leveraging the trusted reputation of the hijacked account.
* **Compromised Internal Sender:** An account within the organization that has been hijacked and is being used to send phishing emails, leveraging the trusted reputation of the hijacked account.
* **Thread Hijacking:** Manipulating the contents of a legitimate email thread to add credibility to the attacker's message or request.

</details>

<details>

<summary>Email Bomb Attack</summary>

Material automatically detects [email bomb attacks](#user-content-fn-1)[^1] and remediates to restore availability to the inbox. You need to enable it separately from email remediation.

* To view issues created by this detection: filter issues by the detection called `Account is experiencing a potential email bombing attack` .

<figure><img src="/files/6baWQOln6VUo6A40SwCm" alt="" width="375"><figcaption></figcaption></figure>

Learn more about how Email Bomb Protection works and your enablement options [here](/learn-more/risk-areas/email-threats/detect/material-email-threat-detections/email-bomb-protection.md).

</details>

<details>

<summary>External Redirection</summary>

* **Fraudulent Callback Number:** Including a spoofed invoice or notification that contains a fraudulent customer support phone number which leads to a scam call center when dialed.
* **Link to Credential Theft URL:** Including a link to a malicious webpage that attempts to steal user credentials when visited.
* **Link to Free Fileshare Hose:** Includes a link to malicious content hosted on a legitimate free filesharing service, such as OneDrive or Dropbox.
* **Link to Malware Dropping URL:** Including a link to a malicious webpage that automatically downloads unwanted or malicious software when visited.
* **Link to Open Redirect:** Including a link to a trusted domain (such as LinkedIn) that permits redirects to arbitrary URLs, where the final destination is a malicious webpage.

</details>

<details>

<summary>Legitimate Service Abuse</summary>

* **Dropbox Notification Abuse:** Inserting malicious links or a malicious call to action in the user-editable fields in Dropbox notifications, such as the display name of the sharing account and the name of the shared document.
* **Google Drive Notification Abuse:** Inserting malicious links or a malicious call to action in the user-editable fields in Google Drive notifications, such as the display name of the sharing account and the name of the shared document.
* **Malicious Content on Legitimate Fileshare Services:** Inserting a link to a legitimate filesharing service such as OneDrive or Dropbox, where the specific file being shared is malicious when downloaded.
* **Paypal Notification Abuse:** Inserting malicious links or a malicious call to action into user-editable fields in PayPal notifications, such as the invoice line item and the business name.

</details>

<details>

<summary>Obfuscation</summary>

* **Content as Image:** Embedding text within a static image in the message to evade filters and keyword detection.
* **Encrypted Attachment:** Use of encryption or password-protecting an attachment to evade security scanners.
* **HTML Smuggling:** Abuse of HTML and JavaScript features to inject malicious content or code when a document is opened.
* **Malicious QR Code:** Embedding a QR code in the message that contains a link to a phishing website.
* **RTLO Characters:** Use of Right-to-Left Override (RTLO) characters to obfuscate the text of a message while still rendering it in a readable way to the recipient.

</details>

<details>

<summary>Social Engineering</summary>

* **Fake Password Expiration Notification:** A fraudulent password expiration notification that leads to a credential-stealing webpage.
* **Fake Payment Instructions:** An attempt to trick the victim into sending funds to the attacker.
* **Fake Storage Limit Notification:** A fraudulent cloud storage capacity limit notification that leads to a credential-stealing webpage.
* **Fake Voicemail Notification:** A fraudulent voicemail notification that leads to a credential-stealing webpage.
* **Request for Financial Info:** An attempt to trick the victim into providing banking or credit card information.
* **Request For PII:** An attempt to trick the victim into providing sensitive personal or contact information.
* **Urgent Language:** Use of language that encourages the victim to act or respond quickly without validating the request.

</details>

<details>

<summary>Spoofing</summary>

* **Brand Impersonation:** Impersonating a well-known brand to trick the victim into opening or interacting with a message.
* **Display Name or Subject Spoofing:** Impersonating a legitimate sender by changing the display name or subject displayed on the message.
* **Employee Impersonation:** Impersonating the personal or work email address of a legitimate employee at the organization.
* **HR Impersonation:** Impersonating the organization's HR department to make the communication appear authoritative and legitimate.
* **IT or IdP Impersonation:** Impersonating the organization's IT department or identity provider (such as Okta).
* **Lookalike Domain:** Impersonating a trusted legitimate sender domain by registering an IDN domain or similar-looking domain with homoglyph characters.
* **Vendor Impersonation:** Impersonating a trusted vendor to trick the victim into providing confidential information or payment details.
* **VIP Impersonation:** Impersonating an executive or high-profile individual with authority to instruct the victim to perform the attacker's request.

</details>

[^1]: an attack method that involves sending a large volume of emails within a short period, with the goal of overwhelming the receiver's inbox and potentially obscuring legitimate emails


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.material.security/learn-more/risk-areas/email-threats/detect/material-email-threat-detections.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
