Rule Name & Severity | Author | Last Updated | Labels | |
|---|---|---|---|---|
Mismatched links: Free file share with urgent language | Sublime Security | 5mo ago Aug 5th, 2025 | /feeds/core/detection-rules/mismatched-links-free-file-share-with-urgent-language-478334c8 | |
Notion suspicious file share | Sublime Security | 6mo ago Jul 16th, 2025 | /feeds/core/detection-rules/notion-suspicious-file-share-f7307929 | |
Service abuse: Adobe Creative Cloud share from an unsolicited sender address | Sublime Security | 3mo ago Oct 22nd, 2025 | /feeds/core/detection-rules/service-abuse-adobe-creative-cloud-share-from-an-unsolicited-sender-address-47e42ca1 | |
Service abuse: DocSend share from an unsolicited reply-to address | Sublime Security | 5mo ago Aug 5th, 2025 | /feeds/core/detection-rules/service-abuse-docsend-share-from-an-unsolicited-reply-to-address-b377e64c | |
Service abuse: DocSend share from newly registered domain | Sublime Security | 11d ago Jan 12th, 2026 | /feeds/core/detection-rules/service-abuse-docsend-share-from-newly-registered-domain-3bc152f2 | |
Service abuse: DocuSign share from an unsolicited reply-to address | Sublime Security | 11d ago Jan 12th, 2026 | /feeds/core/detection-rules/service-abuse-docusign-share-from-an-unsolicited-reply-to-address-2f12d616 | |
Service abuse: FlipHTML5 with attachment deception and credential theft language | Sublime Security | 11d ago Jan 12th, 2026 | /feeds/core/detection-rules/service-abuse-fliphtml5-with-attachment-deception-and-credential-theft-language-02464799 | |
Service abuse: Formester with suspicious link behavior | Sublime Security | 1mo ago Dec 19th, 2025 | /feeds/core/detection-rules/service-abuse-formester-with-suspicious-link-behavior-e4b74fd4 | |
Service abuse: Google account notification with links to free file host | Sublime Security | 5mo ago Aug 5th, 2025 | /feeds/core/detection-rules/service-abuse-google-account-notification-with-links-to-free-file-host-59786115 | |
Service abuse: Google application integration redirecting to suspicious hosts | Sublime Security | 1mo ago Dec 17th, 2025 | /feeds/core/detection-rules/service-abuse-google-application-integration-redirecting-to-suspicious-hosts-473d3247 | |
Service abuse: Google Drive share from an unsolicited reply-to address | Sublime Security | 5mo ago Aug 5th, 2025 | /feeds/core/detection-rules/service-abuse-google-drive-share-from-an-unsolicited-reply-to-address-4581ec0c | |
Service abuse: Google Drive share from new reply-to domain | Sublime Security | 2mo ago Nov 13th, 2025 | /feeds/core/detection-rules/service-abuse-google-drive-share-from-new-reply-to-domain-c1a2d367 | |
Service abuse: HelloSign from an unsolicited sender address | Sublime Security | 5mo ago Aug 5th, 2025 | /feeds/core/detection-rules/service-abuse-hellosign-from-an-unsolicited-sender-address-68ca0753 | |
Service abuse: SendThisFile with credential theft and financial language | Sublime Security | 2mo ago Oct 27th, 2025 | /feeds/core/detection-rules/service-abuse-sendthisfile-with-credential-theft-and-financial-language-c1ebf25b | |
Service abuse: SurveyMonkey survey from newly registered domain | Sublime Security | 11d ago Jan 12th, 2026 | /feeds/core/detection-rules/service-abuse-surveymonkey-survey-from-newly-registered-domain-50a85fa7 | |
Service abuse: Suspicious Zoom Docs link | Sublime Security | 1mo ago Dec 2nd, 2025 | /feeds/core/detection-rules/service-abuse-suspicious-zoom-docs-link-064b2594 | |
Spam: Campaign with excessive space/char obfuscation and free file hosted link | Sublime Security | 11d ago Jan 12th, 2026 | /feeds/core/detection-rules/spam-campaign-with-excessive-spacechar-obfuscation-and-free-file-hosted-link-122bc0ca | |
Spoofable internal domain with suspicious signals | Sublime Security | 6mo ago Jul 23rd, 2025 | /feeds/core/detection-rules/spoofable-internal-domain-with-suspicious-signals-40089d69 | |
Suspicious DocuSign share from new domain | Sublime Security | 5mo ago Aug 5th, 2025 | /feeds/core/detection-rules/suspicious-docusign-share-from-new-domain-d430a1f3 | |
Suspicious Links to Cloudflare R2 and Edge Services | Sublime Security | 11d ago Jan 12th, 2026 | /feeds/core/detection-rules/suspicious-links-to-cloudflare-r2-and-edge-services-5dd3e5c8 | |
Suspicious SharePoint file sharing | Sublime Security | 5mo ago Aug 5th, 2025 | /feeds/core/detection-rules/suspicious-sharepoint-file-sharing-971c3d9c | |
Zoom Events newsletter abuse | Sublime Security | 11d ago Jan 12th, 2026 | /feeds/core/detection-rules/zoom-events-newsletter-abuse-c8fce846 |