Rule Name & Severity | Author | Last Updated | Labels | |
|---|---|---|---|---|
Attachment: EML with link to credential phishing page | Sublime Security | 5mo ago Jul 16th, 2025 | /feeds/core/detection-rules/attachment-eml-with-link-to-credential-phishing-page-1df41cca | |
Attachment: HTML smuggling - QR Code with suspicious links | Sublime Security | 5mo ago Jul 16th, 2025 | /feeds/core/detection-rules/attachment-html-smuggling-qr-code-with-suspicious-links-010e757d | |
Attachment: QR code with credential phishing indicators | Sublime Security | 3mo ago Sep 4th, 2025 | /feeds/core/detection-rules/attachment-qr-code-with-credential-phishing-indicators-9f1681e1 | |
Brand impersonation: DocuSign branded attachment lure with no DocuSign links | Sublime Security | 2mo ago Oct 22nd, 2025 | /feeds/core/detection-rules/brand-impersonation-docusign-branded-attachment-lure-with-no-docusign-links-814a5694 | |
Credential phishing content and link (untrusted sender) | Sublime Security | 5d ago Dec 17th, 2025 | /feeds/core/detection-rules/credential-phishing-content-and-link-untrusted-sender-f0c95bb7 | |
Credential phishing link (unknown sender) | Sublime Security | 5mo ago Jul 16th, 2025 | /feeds/core/detection-rules/credential-phishing-link-unknown-sender-a278012b | |
Free subdomain link with credential theft indicators | Sublime Security | 1y ago Dec 12th, 2024 | /feeds/core/detection-rules/free-subdomain-link-with-credential-theft-indicators-9187479c | |
Free subdomain link with login or captcha (untrusted sender) | Sublime Security | 5mo ago Jul 16th, 2025 | /feeds/core/detection-rules/free-subdomain-link-with-login-or-captcha-untrusted-sender-93288f82 | |
Google Accelerated Mobile Pages (AMP) abuse | Sublime Security | 3mo ago Sep 22nd, 2025 | /feeds/core/detection-rules/google-accelerated-mobile-pages-amp-abuse-46907029 | |
Google Drive abuse: Credential phishing link | Sublime Security | 1y ago Jul 31st, 2024 | /feeds/core/detection-rules/google-drive-abuse-credential-phishing-link-c74aece0 | |
Issuu document with suspicious embedded link | Sublime Security | 4mo ago Aug 5th, 2025 | /feeds/core/detection-rules/issuu-document-with-suspicious-embedded-link-0d73f43d | |
Link: Adobe share with suspicious indicators | Sublime Security | 4mo ago Aug 5th, 2025 | /feeds/core/detection-rules/link-adobe-share-with-suspicious-indicators-b33cae80 | |
Link: chatbot.page platform abuse | Sublime Security | 4mo ago Aug 5th, 2025 | /feeds/core/detection-rules/link-chatbotpage-platform-abuse-bfd6a076 | |
Link: Credential phishing link with undisclosed recipients | Sublime Security | 4mo ago Aug 5th, 2025 | /feeds/core/detection-rules/link-credential-phishing-link-with-undisclosed-recipients-06fc155e | |
Link: Cryptocurrency fraud with suspicious links | Sublime Security | 21d ago Dec 1st, 2025 | /feeds/core/detection-rules/link-cryptocurrency-fraud-with-suspicious-links-d0da37ce | |
Link: Figma design deck with credential theft language | Sublime Security | 4mo ago Aug 5th, 2025 | /feeds/core/detection-rules/link-figma-design-deck-with-credential-theft-language-87601924 | |
Link: HR impersonation with suspicious domain indicators and credential theft | Sublime Security | 19d ago Dec 3rd, 2025 | /feeds/core/detection-rules/link-hr-impersonation-with-suspicious-domain-indicators-and-credential-theft-f31f8831 | |
Link: Microsoft Dynamics 365 form phishing | Sublime Security | 17d ago Dec 5th, 2025 | /feeds/core/detection-rules/link-microsoft-dynamics-365-form-phishing-f72b9085 | |
Link: Multistage landing - FreshDesk knowledge base abuse | Sublime Security | 4mo ago Aug 21st, 2025 | /feeds/core/detection-rules/link-multistage-landing-freshdesk-knowledge-base-abuse-edd6acf7 | |
Link: Multistage landing - Ludus presentation | Sublime Security | 4mo ago Aug 5th, 2025 | /feeds/core/detection-rules/link-multistage-landing-ludus-presentation-a8b3c311 | |
Link: Multistage landing - Scribd document | Sublime Security | 4mo ago Aug 5th, 2025 | /feeds/core/detection-rules/link-multistage-landing-scribd-document-afa9807d | |
Link: Multistage landing - Trello board abuse | Sublime Security | 4mo ago Aug 20th, 2025 | /feeds/core/detection-rules/link-multistage-landing-trello-board-abuse-14a5b23a | |
Link: Spam website with evasion indicators | Sublime Security | 27d ago Nov 25th, 2025 | /feeds/core/detection-rules/link-spam-website-with-evasion-indicators-08bcd353 | |
Link to auto-downloaded file with Adobe branding | Sublime Security | 5mo ago Jul 16th, 2025 | /feeds/core/detection-rules/link-to-auto-downloaded-file-with-adobe-branding-e826c2cf | |
Link to auto-downloaded file with Google Drive branding | Sublime Security | 5mo ago Jul 16th, 2025 | /feeds/core/detection-rules/link-to-auto-downloaded-file-with-google-drive-branding-4b5343be | |
Service abuse: Formester with suspicious link behavior | Sublime Security | 3d ago Dec 19th, 2025 | /feeds/core/detection-rules/service-abuse-formester-with-suspicious-link-behavior-e4b74fd4 | |
Suspicious recipient pattern and language with low reputation link to login | Sublime Security | 1y ago Apr 30th, 2024 | /feeds/core/detection-rules/suspicious-recipient-pattern-and-language-with-low-reputation-link-to-login-a8ea0402 | |
Suspicious recipients pattern with no Compauth pass and suspicious content | Sublime Security | 4mo ago Aug 5th, 2025 | /feeds/core/detection-rules/suspicious-recipients-pattern-with-no-compauth-pass-and-suspicious-content-34fb65f6 |