Rule Name & Severity | Author | Last Updated | Labels | |
|---|---|---|---|---|
Link: Uncommon SharePoint document type with sender's display name | Sublime Security | 5mo ago Aug 5th, 2025 | /feeds/core/detection-rules/link-uncommon-sharepoint-document-type-with-senders-display-name-02d290b2 | |
Link: URL scheme obfuscation via split HTML anchors | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/link-url-scheme-obfuscation-via-split-html-anchors-10375948 | |
Lookalike sender domain (untrusted sender) | Sublime Security | 6mo ago Jul 16th, 2025 | /feeds/core/detection-rules/lookalike-sender-domain-untrusted-sender-67721993 | |
Low reputation link to auto-downloaded HTML file with smuggling indicators | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/low-reputation-link-to-auto-downloaded-html-file-with-smuggling-indicators-339676c6 | |
Mass campaign: Cross Site Scripting (XSS) attempt | Sublime Security | 6mo ago Jul 16th, 2025 | /feeds/core/detection-rules/mass-campaign-cross-site-scripting-xss-attempt-6cbb7124 | |
Mass campaign: recipient address in subject, body, and link (untrusted sender) | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/mass-campaign-recipient-address-in-subject-body-and-link-untrusted-sender-599dabf5 | |
Microsoft device code phishing | @ajpc500 | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/microsoft-device-code-phishing-61f3ae67 | |
Microsoft infrastructure abuse with suspicious patterns | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/microsoft-infrastructure-abuse-with-suspicious-patterns-cfe8e804 | |
Mismatched links: Free file share with urgent language | Sublime Security | 5mo ago Aug 5th, 2025 | /feeds/core/detection-rules/mismatched-links-free-file-share-with-urgent-language-478334c8 | |
Newly registered sender or reply-to domain with newly registered linked domain | Sublime Security | 5mo ago Aug 5th, 2025 | /feeds/core/detection-rules/newly-registered-sender-or-reply-to-domain-with-newly-registered-linked-domain-e5b6a81f | |
Non-RFC compliant calendar files from unsolicited sender | Sublime Security | 3mo ago Oct 1st, 2025 | /feeds/core/detection-rules/non-rfc-compliant-calendar-files-from-unsolicited-sender-9859f100 | |
Open redirect: City of Calgary | Sublime Security | 8mo ago May 23rd, 2025 | /feeds/core/detection-rules/open-redirect-city-of-calgary-00321858 | |
Open redirect: giving.lluh.org | Sublime Security | 8mo ago May 23rd, 2025 | /feeds/core/detection-rules/open-redirect-givinglluhorg-a2bf1099 | |
Open redirect: Klaviyo | Sublime Security | 2y ago May 14th, 2024 | /feeds/core/detection-rules/open-redirect-klaviyo-ce5a370a | |
Open redirect: marketing.edinburghairport.com | Sublime Security | 8mo ago May 23rd, 2025 | /feeds/core/detection-rules/open-redirect-marketingedinburghairportcom-33a47565 | |
Open redirect: next2.io | Sublime Security | 8mo ago May 23rd, 2025 | /feeds/core/detection-rules/open-redirect-next2io-5085c422 | |
Open redirect: people.anuneo.com | Sublime Security | 8mo ago May 23rd, 2025 | /feeds/core/detection-rules/open-redirect-peopleanuneocom-2ae83b73 | |
Open redirect: queue.swytchbike.com | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/open-redirect-queueswytchbikecom-916003d1 | |
Open redirect: slubnaglowie.pl | Sublime Security | 8mo ago May 23rd, 2025 | /feeds/core/detection-rules/open-redirect-slubnaglowiepl-2ec356d0 | |
Open redirect: typedrawers.com | Sublime Security | 8mo ago May 23rd, 2025 | /feeds/core/detection-rules/open-redirect-typedrawerscom-158d9e95 | |
PayPal invoice abuse | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/paypal-invoice-abuse-0ff7a0d4 | |
Potential prompt injection attack in body HTML | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/potential-prompt-injection-attack-in-body-html-5fb24736 | |
Punycode sender domain | Sublime Security | 3y ago Aug 21st, 2023 | /feeds/core/detection-rules/punycode-sender-domain-bc3d8db5 | |
QR code to auto-download of a suspicious file type (unsolicited) | Sublime Security | 3mo ago Oct 17th, 2025 | /feeds/core/detection-rules/qr-code-to-auto-download-of-a-suspicious-file-type-unsolicited-eed87ea2 | |
QR Code with suspicious indicators | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/qr-code-with-suspicious-indicators-04f5c34f | |
Reconnaissance: Email address harvesting attempt | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/reconnaissance-email-address-harvesting-attempt-bb31efbc | |
Reconnaissance: Short generic greeting message | Sublime Security | 1mo ago Dec 2nd, 2025 | /feeds/core/detection-rules/reconnaissance-short-generic-greeting-message-c67dedab | |
Recruitee Infrastructure Abuse | Sublime Security | 6mo ago Jul 16th, 2025 | /feeds/core/detection-rules/recruitee-infrastructure-abuse-31cab83d | |
Salesforce infrastructure abuse | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/salesforce-infrastructure-abuse-78a77c70 | |
Self-sent fake PDF attachment with misleading link | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/self-sent-fake-pdf-attachment-with-misleading-link-8a285d2e | |
Sendgrid voicemail phish | Sublime Security | 2mo ago Nov 24th, 2025 | /feeds/core/detection-rules/sendgrid-voicemail-phish-21cad89c | |
Service abuse: Adobe Creative Cloud share from an unsolicited sender address | Sublime Security | 3mo ago Oct 22nd, 2025 | /feeds/core/detection-rules/service-abuse-adobe-creative-cloud-share-from-an-unsolicited-sender-address-47e42ca1 | |
Service abuse: Adobe legitimate domain with document approval language | Sublime Security | 1d ago Jan 23rd, 2026 | /feeds/core/detection-rules/service-abuse-adobe-legitimate-domain-with-document-approval-language-237f4da4 | |
Service abuse: Adobe Sign notification from an unsolicited reply-to address | Sublime Security | 5mo ago Aug 5th, 2025 | /feeds/core/detection-rules/service-abuse-adobe-sign-notification-from-an-unsolicited-reply-to-address-d00893ba | |
Service abuse: AppSheet infrastructure with suspicious indicators | Sublime Security | 3mo ago Oct 6th, 2025 | /feeds/core/detection-rules/service-abuse-appsheet-infrastructure-with-suspicious-indicators-5937646a | |
Service Abuse: Box file sharing with credential phishing intent | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/service-abuse-box-file-sharing-with-credential-phishing-intent-5bd0cb25 | |
Service abuse: Callback phishing via Microsoft Teams invite | Sublime Security | 1mo ago Dec 12th, 2025 | /feeds/core/detection-rules/service-abuse-callback-phishing-via-microsoft-teams-invite-13e35e5f | |
Service abuse: Cisco secure email service with financial request | Sublime Security | 3mo ago Oct 1st, 2025 | /feeds/core/detection-rules/service-abuse-cisco-secure-email-service-with-financial-request-43a6daa8 | |
Service abuse: DocSend share from an unsolicited reply-to address | Sublime Security | 5mo ago Aug 5th, 2025 | /feeds/core/detection-rules/service-abuse-docsend-share-from-an-unsolicited-reply-to-address-b377e64c | |
Service abuse: DocSend share from newly registered domain | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/service-abuse-docsend-share-from-newly-registered-domain-3bc152f2 | |
Service abuse: DocuSign notification with suspicious sender or document name | Sublime Security | 5mo ago Aug 5th, 2025 | /feeds/core/detection-rules/service-abuse-docusign-notification-with-suspicious-sender-or-document-name-5e4707cd | |
Service abuse: DocuSign share from an unsolicited reply-to address | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/service-abuse-docusign-share-from-an-unsolicited-reply-to-address-2f12d616 | |
Service abuse: Dropbox share from an unsolicited reply-to address | Sublime Security | 5mo ago Aug 5th, 2025 | /feeds/core/detection-rules/service-abuse-dropbox-share-from-an-unsolicited-reply-to-address-50a1499f | |
Service abuse: Dropbox share from new domain | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/service-abuse-dropbox-share-from-new-domain-0e664bd9 | |
Service abuse: Dropbox share with suspicious sender or document name | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/service-abuse-dropbox-share-with-suspicious-sender-or-document-name-27007c9f | |
Service Abuse: ExactTarget with suspicious sender indicators | Sublime Security | 2mo ago Nov 8th, 2025 | /feeds/core/detection-rules/service-abuse-exacttarget-with-suspicious-sender-indicators-6154f197 | |
Service abuse: Facebook business with action required subject | Sublime Security | 2mo ago Nov 17th, 2025 | /feeds/core/detection-rules/service-abuse-facebook-business-with-action-required-subject-64297d2f | |
Service abuse: FlipHTML5 with attachment deception and credential theft language | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/service-abuse-fliphtml5-with-attachment-deception-and-credential-theft-language-02464799 | |
Service abuse: Formester with suspicious link behavior | Sublime Security | 1mo ago Dec 19th, 2025 | /feeds/core/detection-rules/service-abuse-formester-with-suspicious-link-behavior-e4b74fd4 | |
Service abuse: GetAccept callback scam content | Sublime Security | 8d ago Jan 16th, 2026 | /feeds/core/detection-rules/service-abuse-getaccept-callback-scam-content-7ec2f70b |