Rule Name & Severity | Author | Last Updated | Labels |
|---|---|---|---|
Link: HR impersonation with suspicious domain indicators and credential theft | Sublime Security | 3mo ago Dec 3rd, 2025 | |
Link: Recipient domain in URL path | Sublime Security | 2mo ago Jan 12th, 2026 | |
Link to a domain with punycode characters | @ajpc500 | 4mo ago Nov 12th, 2025 | |
Lookalike sender domain (untrusted sender) | Sublime Security | 5d ago Mar 25th, 2026 | |
Punycode sender domain | Sublime Security | 3y ago Aug 21st, 2023 | |
Sharepoint link likely unrelated to sender | Sublime Security | 2mo ago Jan 12th, 2026 | |
Spam/fraud: Predatory journal/research paper request | Sublime Security | 4mo ago Nov 3rd, 2025 | |
Suspected lookalike domain with suspicious language | Sublime Security | 2mo ago Jan 12th, 2026 | |
Vendor impersonation: Thread hijacking with typosquat domain | Sublime Security | 2mo ago Jan 12th, 2026 |