Rule Name & Severity | Author | Last Updated | Labels | |
|---|---|---|---|---|
Request for Quote or Purchase (RFQ|RFP) with suspicious sender or recipient pattern | Sublime Security | 8d ago Jan 15th, 2026 | /feeds/core/detection-rules/request-for-quote-or-purchase-rfqorrfp-with-suspicious-sender-or-recipient-pattern-2ac0d329 | |
Salesforce infrastructure abuse | Sublime Security | 11d ago Jan 12th, 2026 | /feeds/core/detection-rules/salesforce-infrastructure-abuse-78a77c70 | |
Scam: Piano giveaway | Sublime Security | 1mo ago Dec 11th, 2025 | /feeds/core/detection-rules/scam-piano-giveaway-1a91a203 | |
Service abuse: AppSheet infrastructure with suspicious indicators | Sublime Security | 3mo ago Oct 6th, 2025 | /feeds/core/detection-rules/service-abuse-appsheet-infrastructure-with-suspicious-indicators-5937646a | |
Service Abuse: Box file sharing with credential phishing intent | Sublime Security | 11d ago Jan 12th, 2026 | /feeds/core/detection-rules/service-abuse-box-file-sharing-with-credential-phishing-intent-5bd0cb25 | |
Service abuse: Cisco secure email service with financial request | Sublime Security | 3mo ago Oct 1st, 2025 | /feeds/core/detection-rules/service-abuse-cisco-secure-email-service-with-financial-request-43a6daa8 | |
Service abuse: FlipHTML5 with attachment deception and credential theft language | Sublime Security | 11d ago Jan 12th, 2026 | /feeds/core/detection-rules/service-abuse-fliphtml5-with-attachment-deception-and-credential-theft-language-02464799 | |
Service abuse: GetAccept callback scam content | Sublime Security | 7d ago Jan 16th, 2026 | /feeds/core/detection-rules/service-abuse-getaccept-callback-scam-content-7ec2f70b | |
Service Abuse: GoDaddy infrastructure | Sublime Security | 16d ago Jan 7th, 2026 | /feeds/core/detection-rules/service-abuse-godaddy-infrastructure-8a2dd357 | |
Service abuse: Microsoft Power BI callback scam | Sublime Security | 1d ago Jan 22nd, 2026 | /feeds/core/detection-rules/service-abuse-microsoft-power-bi-callback-scam-7a55388e | |
Service abuse: Random Google Firebase sender address with suspicious content | Sublime Security | 11d ago Jan 12th, 2026 | /feeds/core/detection-rules/service-abuse-random-google-firebase-sender-address-with-suspicious-content-9f8899a9 | |
Service abuse: Recruiting with suspicious language patterns from legitimate platforms | Sublime Security | 3mo ago Oct 7th, 2025 | /feeds/core/detection-rules/service-abuse-recruiting-with-suspicious-language-patterns-from-legitimate-platforms-29e12696 | |
Service abuse: Roomsy with unrelated body content | Sublime Security | 1mo ago Dec 2nd, 2025 | /feeds/core/detection-rules/service-abuse-roomsy-with-unrelated-body-content-18e08a5a | |
Service abuse: Sendgrid credential theft with personalized request targeting single recipient | Sublime Security | 11d ago Jan 12th, 2026 | /feeds/core/detection-rules/service-abuse-sendgrid-credential-theft-with-personalized-request-targeting-single-recipient-b9680da1 | |
Service abuse: SendThisFile with credential theft and financial language | Sublime Security | 2mo ago Oct 27th, 2025 | /feeds/core/detection-rules/service-abuse-sendthisfile-with-credential-theft-and-financial-language-c1ebf25b | |
Spam: Fake dating profile notification | Sublime Security | 1mo ago Dec 3rd, 2025 | /feeds/core/detection-rules/spam-fake-dating-profile-notification-0f33fea2 | |
Spam/fraud: Predatory journal/research paper request | Sublime Security | 2mo ago Nov 3rd, 2025 | /feeds/core/detection-rules/spamfraud-predatory-journalresearch-paper-request-263ca56b | |
Spam: Mastercard promotional content with image-based body | Sublime Security | 2mo ago Nov 5th, 2025 | /feeds/core/detection-rules/spam-mastercard-promotional-content-with-image-based-body-5f2cb559 | |
Spam: New job cold outreach from unsolicited sender | Sublime Security | 3mo ago Sep 29th, 2025 | /feeds/core/detection-rules/spam-new-job-cold-outreach-from-unsolicited-sender-ec39b789 | |
Spam: Website errors solicitation | Sublime Security | 1mo ago Dec 11th, 2025 | /feeds/core/detection-rules/spam-website-errors-solicitation-122ea794 | |
Spoofable internal domain with suspicious signals | Sublime Security | 6mo ago Jul 23rd, 2025 | /feeds/core/detection-rules/spoofable-internal-domain-with-suspicious-signals-40089d69 | |
Suspected lookalike domain with suspicious language | Sublime Security | 11d ago Jan 12th, 2026 | /feeds/core/detection-rules/suspected-lookalike-domain-with-suspicious-language-3674ced0 | |
Suspicious attachment with unscannable Cloudflare link | Sublime Security | 11d ago Jan 12th, 2026 | /feeds/core/detection-rules/suspicious-attachment-with-unscannable-cloudflare-link-00f92b6f | |
Suspicious invoice reference with missing or image-only attachments | Sublime Security | 11d ago Jan 12th, 2026 | /feeds/core/detection-rules/suspicious-invoice-reference-with-missing-or-image-only-attachments-466c1680 | |
Suspicious newly registered reply-to domain with engaging financial or urgent language | Sublime Security | 11d ago Jan 12th, 2026 | /feeds/core/detection-rules/suspicious-newly-registered-reply-to-domain-with-engaging-financial-or-urgent-language-db4d9bb3 | |
Suspicious recipient pattern and language with low reputation link to login | Sublime Security | 11d ago Jan 12th, 2026 | /feeds/core/detection-rules/suspicious-recipient-pattern-and-language-with-low-reputation-link-to-login-a8ea0402 | |
Suspicious recipients pattern with NLU credential theft indicators | Sublime Security | 11d ago Jan 12th, 2026 | /feeds/core/detection-rules/suspicious-recipients-pattern-with-nlu-credential-theft-indicators-8e121c3e | |
Suspicious recipients pattern with no Compauth pass and suspicious content | Sublime Security | 11d ago Jan 12th, 2026 | /feeds/core/detection-rules/suspicious-recipients-pattern-with-no-compauth-pass-and-suspicious-content-34fb65f6 | |
Vendor compromise: GovDelivery message with suspicious link | Sublime Security | 5mo ago Aug 5th, 2025 | /feeds/core/detection-rules/vendor-compromise-govdelivery-message-with-suspicious-link-0d2d5172 | |
Vendor impersonation: Thread hijacking with typosquat domain | Sublime Security | 11d ago Jan 12th, 2026 | /feeds/core/detection-rules/vendor-impersonation-thread-hijacking-with-typosquat-domain-9c2f38ed | |
Venmo payment request abuse | Sublime Security | 4mo ago Sep 5th, 2025 | /feeds/core/detection-rules/venmo-payment-request-abuse-4450639a | |
VIP Impersonation via Google Group relay with suspicious indicators | Sublime Security | 2mo ago Nov 12th, 2025 | /feeds/core/detection-rules/vip-impersonation-via-google-group-relay-with-suspicious-indicators-57f9cd3b | |
VIP impersonation with BEC language (near match, untrusted sender) | Sublime Security | 11d ago Jan 12th, 2026 | /feeds/core/detection-rules/vip-impersonation-with-bec-language-near-match-untrusted-sender-303081da | |
VIP impersonation with charitable donation fraud | Sublime Security | 2mo ago Nov 12th, 2025 | /feeds/core/detection-rules/vip-impersonation-with-charitable-donation-fraud-35a56b8e | |
VIP impersonation with invoicing request | Sublime Security | 2y ago Apr 23rd, 2024 | /feeds/core/detection-rules/vip-impersonation-with-invoicing-request-a60f89a0 | |
VIP impersonation with urgent request (strict match, untrusted sender) | Sublime Security | 11d ago Jan 12th, 2026 | /feeds/core/detection-rules/vip-impersonation-with-urgent-request-strict-match-untrusted-sender-0dd1fa60 | |
Xero infrastructure abuse | Sublime Security | 2mo ago Nov 3rd, 2025 | /feeds/core/detection-rules/xero-infrastructure-abuse-918c4bd3 | |
Xero invoice abuse | Sublime Security | 1mo ago Dec 17th, 2025 | /feeds/core/detection-rules/xero-invoice-abuse-6538c600 | |
X (Twitter) impersonation with credential phishing motives | Sublime Security | 5mo ago Aug 5th, 2025 | /feeds/core/detection-rules/x-twitter-impersonation-with-credential-phishing-motives-0b60dca6 | |
Zoom Events newsletter abuse | Sublime Security | 11d ago Jan 12th, 2026 | /feeds/core/detection-rules/zoom-events-newsletter-abuse-c8fce846 |