Rule Name & Severity | Author | Last Updated | Labels | |
|---|---|---|---|---|
Link: SharePoint filename matches org name | Sublime Security | 1mo ago Feb 6th, 2026 | /feeds/core/detection-rules/link-sharepoint-filename-matches-org-name-cb954726 | |
Link: SharePoint files shared from GoDaddy federated tenants | Sublime Security | 7mo ago Jul 16th, 2025 | /feeds/core/detection-rules/link-sharepoint-files-shared-from-godaddy-federated-tenants-0e26cdd2 | |
Link: SharePoint OneNote or PDF link with self sender behavior | Sublime Security | 11d ago Feb 27th, 2026 | /feeds/core/detection-rules/link-sharepoint-onenote-or-pdf-link-with-self-sender-behavior-588e7203 | |
Link: Spam website with evasion indicators | Sublime Security | 3mo ago Nov 25th, 2025 | /feeds/core/detection-rules/link-spam-website-with-evasion-indicators-08bcd353 | |
Link: Squarespace infrastructure abuse | Sublime Security | 7mo ago Aug 5th, 2025 | /feeds/core/detection-rules/link-squarespace-infrastructure-abuse-a8fe9d30 | |
Link: Suspicious go.php redirect with document lure | Sublime Security | 1mo ago Feb 6th, 2026 | /feeds/core/detection-rules/link-suspicious-gophp-redirect-with-document-lure-f3d8c227 | |
Link: Suspicious Sharepoint folder share | Sublime Security | 7mo ago Aug 5th, 2025 | /feeds/core/detection-rules/link-suspicious-sharepoint-folder-share-6168a08c | |
Link: Suspicious URL with recipient targeting and special characters | Sublime Security | 17d ago Feb 21st, 2026 | /feeds/core/detection-rules/link-suspicious-url-with-recipient-targeting-and-special-characters-e808be3a | |
Link to a domain with punycode characters | @ajpc500 | 3mo ago Nov 12th, 2025 | /feeds/core/detection-rules/link-to-a-domain-with-punycode-characters-74b3698c | |
Link to auto-downloaded disk image in encrypted zip | @ajpc500 | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/link-to-auto-downloaded-disk-image-in-encrypted-zip-b50f0cb1 | |
Link to auto-downloaded DMG in archive | Sublime Security | 7mo ago Jul 16th, 2025 | /feeds/core/detection-rules/link-to-auto-downloaded-dmg-in-archive-dc04cdd8 | |
Link to auto-downloaded DMG in encrypted zip | Sublime Security | 7mo ago Jul 16th, 2025 | /feeds/core/detection-rules/link-to-auto-downloaded-dmg-in-encrypted-zip-43af98d3 | |
Link to auto-downloaded file with Adobe branding | Sublime Security | 7mo ago Jul 16th, 2025 | /feeds/core/detection-rules/link-to-auto-downloaded-file-with-adobe-branding-e826c2cf | |
Link to auto-downloaded file with Google Drive branding | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/link-to-auto-downloaded-file-with-google-drive-branding-4b5343be | |
Link to auto-download of a suspicious file type (unsolicited) | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/link-to-auto-download-of-a-suspicious-file-type-unsolicited-67ae2152 | |
Link to Google Apps Script macro (unsolicited) | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/link-to-google-apps-script-macro-unsolicited-d10146df | |
Link to Google Apps Script macro via comment tagging | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/link-to-google-apps-script-macro-via-comment-tagging-66fecd30 | |
Link: Tycoon2FA phishing kit (non-exhaustive) | Sublime Security | 1mo ago Jan 23rd, 2026 | /feeds/core/detection-rules/link-tycoon2fa-phishing-kit-non-exhaustive-a070d4e2 | |
Link: Uncommon SharePoint document type with sender's display name | Sublime Security | 7mo ago Aug 5th, 2025 | /feeds/core/detection-rules/link-uncommon-sharepoint-document-type-with-senders-display-name-02d290b2 | |
Link: URL fragment with hexadecimal pattern obfuscation | Sublime Security | 1mo ago Jan 29th, 2026 | /feeds/core/detection-rules/link-url-fragment-with-hexadecimal-pattern-obfuscation-51f51aa0 | |
Link: URL redirecting to blob URL | Sublime Security | 14d ago Feb 24th, 2026 | /feeds/core/detection-rules/link-url-redirecting-to-blob-url-1677135b | |
Link: URL scheme obfuscation via split HTML anchors | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/link-url-scheme-obfuscation-via-split-html-anchors-10375948 | |
Link: URL shortener with copy-paste instructions and credential theft language | Sublime Security | 1mo ago Feb 6th, 2026 | /feeds/core/detection-rules/link-url-shortener-with-copy-paste-instructions-and-credential-theft-language-a0a2c573 | |
Link: Webflow link from unsolicited sender | Sublime Security | 7mo ago Aug 5th, 2025 | /feeds/core/detection-rules/link-webflow-link-from-unsolicited-sender-d4f3b8cf | |
Link: WordPress login page with Blogspot Binance scam | Sublime Security | 21d ago Feb 17th, 2026 | /feeds/core/detection-rules/link-wordpress-login-page-with-blogspot-binance-scam-909dfae5 | |
Link: Zoho form link from unsolicited sender | Sublime Security | 7mo ago Aug 5th, 2025 | /feeds/core/detection-rules/link-zoho-form-link-from-unsolicited-sender-eb04a9f2 | |
Low reputation link to auto-downloaded HTML file with smuggling indicators | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/low-reputation-link-to-auto-downloaded-html-file-with-smuggling-indicators-339676c6 | |
Malformed URL prefix | Sublime Security | 6mo ago Sep 4th, 2025 | /feeds/core/detection-rules/malformed-url-prefix-4e659d28 | |
Malware: Pikabot delivery via URL auto-download | Sublime Security | 2y ago Apr 25th, 2024 | /feeds/core/detection-rules/malware-pikabot-delivery-via-url-auto-download-f4be4572 | |
Microsoft device code phishing | @ajpc500 | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/microsoft-device-code-phishing-61f3ae67 | |
Mismatched links: Free file share with urgent language | Sublime Security | 7mo ago Aug 5th, 2025 | /feeds/core/detection-rules/mismatched-links-free-file-share-with-urgent-language-478334c8 | |
New link domain (<=10d) from untrusted sender | Sublime Security | 1mo ago Feb 6th, 2026 | /feeds/core/detection-rules/new-link-domain-less10d-from-untrusted-sender-4805b0e6 | |
Newly registered sender or reply-to domain with newly registered linked domain | Sublime Security | 7mo ago Aug 5th, 2025 | /feeds/core/detection-rules/newly-registered-sender-or-reply-to-domain-with-newly-registered-linked-domain-e5b6a81f | |
Notion suspicious file share | Sublime Security | 7mo ago Jul 16th, 2025 | /feeds/core/detection-rules/notion-suspicious-file-share-f7307929 | |
Open redirect: adnxs.com | Sublime Security | 7mo ago Aug 5th, 2025 | /feeds/core/detection-rules/open-redirect-adnxscom-7fc92916 | |
Open redirect: agena-smile.com | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/open-redirect-agena-smilecom-4a8ebce6 | |
Open redirect: amaterasu-for-website-5.com | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/open-redirect-amaterasu-for-website-5com-d31f7cb8 | |
Open redirect: api.spently.com | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/open-redirect-apispentlycom-69740e97 | |
Open redirect: Artisteer | Sublime Security | 9mo ago May 23rd, 2025 | /feeds/core/detection-rules/open-redirect-artisteer-1f65eec3 | |
Open redirect: artkaderne | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/open-redirect-artkaderne-cc16a3f4 | |
Open Redirect: asemailmgmteu.com | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/open-redirect-asemailmgmteucom-368871ea | |
Open redirect: astroarts.co.jp | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/open-redirect-astroartscojp-6dd617af | |
Open redirect: Atdmt | @vector_sec | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/open-redirect-atdmt-fafbd230 | |
Open redirect: Avast | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/open-redirect-avast-5f635658 | |
Open redirect: bananaguide.com | Sublime Security | 7mo ago Aug 5th, 2025 | /feeds/core/detection-rules/open-redirect-bananaguidecom-92fecf26 | |
Open redirect: bangkoksync.com | Sublime Security | 7mo ago Aug 5th, 2025 | /feeds/core/detection-rules/open-redirect-bangkoksynccom-e1449ccd | |
Open redirect: bestdeals.today | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/open-redirect-bestdealstoday-666de100 | |
Open redirect: Bitrix24 URL Path | Sublime Security | 7mo ago Aug 5th, 2025 | /feeds/core/detection-rules/open-redirect-bitrix24-url-path-e3c85e59 | |
Open redirect: BMW USA | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/open-redirect-bmw-usa-1bf4e69a | |
Open redirect: bubblelife.com | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/open-redirect-bubblelifecom-53c9b893 |