Rule Name & Severity | Author | Last Updated | Labels | |
|---|---|---|---|---|
URLhaus: Malicious domain in message body or pdf attachment (trusted reporters) | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/urlhaus-malicious-domain-in-message-body-or-pdf-attachment-trusted-reporters-cfca2986 | |
URL with Unicode U+2044 (⁄) or U+2215 (∕) characters | @delivr_to | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/url-with-unicode-u2044-or-u2215-characters-12069f5b | |
Vendor compromise: GovDelivery message with suspicious link | Sublime Security | 7mo ago Aug 5th, 2025 | /feeds/core/detection-rules/vendor-compromise-govdelivery-message-with-suspicious-link-0d2d5172 | |
Xero infrastructure abuse | Sublime Security | 4mo ago Nov 3rd, 2025 | /feeds/core/detection-rules/xero-infrastructure-abuse-918c4bd3 | |
Zoom Events newsletter abuse | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/zoom-events-newsletter-abuse-c8fce846 |