Rule Name & Severity | Author | Last Updated | Labels | |
|---|---|---|---|---|
Attachment: Callback phishing solicitation via pdf file | Sublime Security | 5mo ago Aug 5th, 2025 | /feeds/core/detection-rules/attachment-callback-phishing-solicitation-via-pdf-file-ac33f097 | |
Attachment: Legal themed message or PDF with suspicious indicators | Sublime Security | 1mo ago Dec 1st, 2025 | /feeds/core/detection-rules/attachment-legal-themed-message-or-pdf-with-suspicious-indicators-19133301 | |
Body: Embedded email headers indicative of thread hijacking/abuse | Sublime Security | 1mo ago Dec 1st, 2025 | /feeds/core/detection-rules/body-embedded-email-headers-indicative-of-thread-hijackingabuse-6e8eeebb | |
Brand impersonation: Google Drive fake file share | Sublime Security | 18d ago Dec 19th, 2025 | /feeds/core/detection-rules/brand-impersonation-google-drive-fake-file-share-b424a941 | |
Brand impersonation: Microsoft with low reputation links | Sublime Security | 27d ago Dec 10th, 2025 | /feeds/core/detection-rules/brand-impersonation-microsoft-with-low-reputation-links-b59201b6 | |
Brand impersonation: Sharepoint fake file share | Sublime Security | 27d ago Dec 10th, 2025 | /feeds/core/detection-rules/brand-impersonation-sharepoint-fake-file-share-ff8b296b | |
Brand impersonation: Wells Fargo | Sublime Security | 11mo ago Jan 15th, 2025 | /feeds/core/detection-rules/brand-impersonation-wells-fargo-02d7301f | |
Fake message thread - Untrusted sender with a mismatched freemail reply-to address | Sublime Security | 5mo ago Aug 5th, 2025 | /feeds/core/detection-rules/fake-message-thread-untrusted-sender-with-a-mismatched-freemail-reply-to-address-ca64e819 | |
Fake thread with suspicious indicators | Sublime Security | 28d ago Dec 9th, 2025 | /feeds/core/detection-rules/fake-thread-with-suspicious-indicators-c2e18a57 | |
HTML smuggling with atob in message body | Sublime Security | 3y ago Aug 17th, 2023 | /feeds/core/detection-rules/html-smuggling-with-atob-in-message-body-0f86851f | |
Impersonation: Fake Gmail attachment | Sublime Security | 5mo ago Aug 5th, 2025 | /feeds/core/detection-rules/impersonation-fake-gmail-attachment-0f5a4e14 | |
Impersonation: SharePoint reply header anomaly | Sublime Security | 5mo ago Aug 5th, 2025 | /feeds/core/detection-rules/impersonation-sharepoint-reply-header-anomaly-78875848 | |
Impersonation: Suspected supplier impersonation with suspicious content | Sublime Security | 11mo ago Feb 3rd, 2025 | /feeds/core/detection-rules/impersonation-suspected-supplier-impersonation-with-suspicious-content-63d8b1ce | |
Link: Secure SharePoint file share from new or unusual sender | Sublime Security | 4mo ago Sep 5th, 2025 | /feeds/core/detection-rules/link-secure-sharepoint-file-share-from-new-or-unusual-sender-74ed3020 | |
Link to Google Apps Script macro via comment tagging | Sublime Security | 5mo ago Aug 5th, 2025 | /feeds/core/detection-rules/link-to-google-apps-script-macro-via-comment-tagging-66fecd30 | |
Link: Zoho form link from unsolicited sender | Sublime Security | 5mo ago Aug 5th, 2025 | /feeds/core/detection-rules/link-zoho-form-link-from-unsolicited-sender-eb04a9f2 | |
Malformed URL prefix | Sublime Security | 4mo ago Sep 4th, 2025 | /feeds/core/detection-rules/malformed-url-prefix-4e659d28 | |
Service abuse: Random Google Firebase sender address with suspicious content | Sublime Security | 1mo ago Nov 26th, 2025 | /feeds/core/detection-rules/service-abuse-random-google-firebase-sender-address-with-suspicious-content-9f8899a9 | |
Spam: Attendee list solicitation | Sublime Security | 4mo ago Aug 29th, 2025 | /feeds/core/detection-rules/spam-attendee-list-solicitation-69715b62 | |
Spam: Fake photo share | Sublime Security | 1mo ago Nov 8th, 2025 | /feeds/core/detection-rules/spam-fake-photo-share-eb086f7d | |
Spam: New link domain (<=10d) and emojis | Sublime Security | 5mo ago Jul 16th, 2025 | /feeds/core/detection-rules/spam-new-link-domain-less10d-and-emojis-33677993 | |
Spam: URL shortener with short body content and emojis | Sublime Security | 5mo ago Jul 23rd, 2025 | /feeds/core/detection-rules/spam-url-shortener-with-short-body-content-and-emojis-b7797e4c | |
Suspicious invoice reference with missing or image-only attachments | Sublime Security | 1mo ago Dec 2nd, 2025 | /feeds/core/detection-rules/suspicious-invoice-reference-with-missing-or-image-only-attachments-466c1680 | |
URL with Unicode U+2044 (⁄) or U+2215 (∕) characters | @delivr_to | 2y ago Feb 23rd, 2024 | /feeds/core/detection-rules/url-with-unicode-u2044-or-u2215-characters-12069f5b | |
VIP impersonation: Fake thread with display name match, email mismatch | Sublime Security | 2y ago Jul 29th, 2024 | /feeds/core/detection-rules/vip-impersonation-fake-thread-with-display-name-match-email-mismatch-11cc3e28 | |
VIP impersonation with charitable donation fraud | Sublime Security | 1mo ago Nov 12th, 2025 | /feeds/core/detection-rules/vip-impersonation-with-charitable-donation-fraud-35a56b8e |