Rule Name & Severity | Author | Last Updated | Labels | |
|---|---|---|---|---|
Service abuse: Google account notification with links to free file host | Sublime Security | 5mo ago Aug 5th, 2025 | /feeds/core/detection-rules/service-abuse-google-account-notification-with-links-to-free-file-host-59786115 | |
Service abuse: Google classroom solicitation | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/service-abuse-google-classroom-solicitation-e9c39e92 | |
Service abuse: Google Drive share from an unsolicited reply-to address | Sublime Security | 5mo ago Aug 5th, 2025 | /feeds/core/detection-rules/service-abuse-google-drive-share-from-an-unsolicited-reply-to-address-4581ec0c | |
Service abuse: Google Drive share from new reply-to domain | Sublime Security | 2mo ago Nov 13th, 2025 | /feeds/core/detection-rules/service-abuse-google-drive-share-from-new-reply-to-domain-c1a2d367 | |
Service abuse: HelloSign from an unsolicited sender address | Sublime Security | 5mo ago Aug 5th, 2025 | /feeds/core/detection-rules/service-abuse-hellosign-from-an-unsolicited-sender-address-68ca0753 | |
Service Abuse: HelloSign share with suspicious sender or document name | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/service-abuse-hellosign-share-with-suspicious-sender-or-document-name-464d98f3 | |
Service abuse: Microsoft Power BI callback scam | Sublime Security | 2d ago Jan 22nd, 2026 | /feeds/core/detection-rules/service-abuse-microsoft-power-bi-callback-scam-7a55388e | |
Service abuse: Monday.com infrastructure with phishing intent | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/service-abuse-mondaycom-infrastructure-with-phishing-intent-a346e3b1 | |
Service abuse: Payoneer callback scam | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/service-abuse-payoneer-callback-scam-b7fb174c | |
Service abuse: QuickBooks notification from new domain | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/service-abuse-quickbooks-notification-from-new-domain-c4f46473 | |
Service abuse: QuickBooks notification with suspicious comments | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/service-abuse-quickbooks-notification-with-suspicious-comments-a23d0950 | |
Service abuse: Random Google Firebase sender address with suspicious content | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/service-abuse-random-google-firebase-sender-address-with-suspicious-content-9f8899a9 | |
Service abuse: Recruiting with suspicious language patterns from legitimate platforms | Sublime Security | 3mo ago Oct 7th, 2025 | /feeds/core/detection-rules/service-abuse-recruiting-with-suspicious-language-patterns-from-legitimate-platforms-29e12696 | |
Service abuse: Roomsy with unrelated body content | Sublime Security | 1mo ago Dec 2nd, 2025 | /feeds/core/detection-rules/service-abuse-roomsy-with-unrelated-body-content-18e08a5a | |
Service abuse: Sendgrid credential theft with personalized request targeting single recipient | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/service-abuse-sendgrid-credential-theft-with-personalized-request-targeting-single-recipient-b9680da1 | |
Service abuse: SendGrid-formatted link with actor-controlled fragment | Sublime Security | 2mo ago Nov 24th, 2025 | /feeds/core/detection-rules/service-abuse-sendgrid-formatted-link-with-actor-controlled-fragment-cb511fe9 | |
Service abuse: SendGrid impersonation via Sendgrid from new sender | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/service-abuse-sendgrid-impersonation-via-sendgrid-from-new-sender-aa5d18ca | |
Service abuse: SendThisFile with credential theft and financial language | Sublime Security | 2mo ago Oct 27th, 2025 | /feeds/core/detection-rules/service-abuse-sendthisfile-with-credential-theft-and-financial-language-c1ebf25b | |
Service abuse: SurveyMonkey survey from newly registered domain | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/service-abuse-surveymonkey-survey-from-newly-registered-domain-50a85fa7 | |
Service abuse: Suspicious Zoom Docs link | Sublime Security | 1mo ago Dec 2nd, 2025 | /feeds/core/detection-rules/service-abuse-suspicious-zoom-docs-link-064b2594 | |
Service abuse: Task management message sent via SendGrid | Sublime Security | 3mo ago Oct 6th, 2025 | /feeds/core/detection-rules/service-abuse-task-management-message-sent-via-sendgrid-568a63f5 | |
Service abuse: Trello board invitation with VIP impersonation | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/service-abuse-trello-board-invitation-with-vip-impersonation-fedfc94b | |
Sharepoint link likely unrelated to sender | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/sharepoint-link-likely-unrelated-to-sender-6870f489 | |
SharePoint OTP for filename matching org name | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/sharepoint-otp-for-filename-matching-org-name-89911cbd | |
Shopify infrastructure abuse | Sublime Security | 2y ago Nov 13th, 2024 | /feeds/core/detection-rules/shopify-infrastructure-abuse-844ff164 | |
Spam: BlackBaud infrastructure abuse | Sublime Security | 2y ago Jan 17th, 2024 | /feeds/core/detection-rules/spam-blackbaud-infrastructure-abuse-3db46591 | |
Spam: Commonly observed formatting of unauthorized free giveaways | Sublime Security | 10d ago Jan 14th, 2026 | /feeds/core/detection-rules/spam-commonly-observed-formatting-of-unauthorized-free-giveaways-8bc49fa3 | |
Spam: Cryptocurrency airdrop/giveaway | Sublime Security | 3mo ago Oct 16th, 2025 | /feeds/core/detection-rules/spam-cryptocurrency-airdropgiveaway-80a2e2fd | |
Spam: Default Microsoft Exchange Online sender domain (onmicrosoft.com) | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/spam-default-microsoft-exchange-online-sender-domain-onmicrosoftcom-3f2a64ce | |
Spam: Fake dating profile notification | Sublime Security | 1mo ago Dec 3rd, 2025 | /feeds/core/detection-rules/spam-fake-dating-profile-notification-0f33fea2 | |
Spam: Fake photo share | Sublime Security | 2mo ago Nov 8th, 2025 | /feeds/core/detection-rules/spam-fake-photo-share-eb086f7d | |
Spam: Firebase password reset from suspicious sender | Sublime Security | 1mo ago Dec 2nd, 2025 | /feeds/core/detection-rules/spam-firebase-password-reset-from-suspicious-sender-a2f673a9 | |
Spam/fraud: Predatory journal/research paper request | Sublime Security | 2mo ago Nov 3rd, 2025 | /feeds/core/detection-rules/spamfraud-predatory-journalresearch-paper-request-263ca56b | |
Spam: Ghostwriting services scam with manipulative language | Sublime Security | 3mo ago Oct 17th, 2025 | /feeds/core/detection-rules/spam-ghostwriting-services-scam-with-manipulative-language-b747c3ea | |
Spam: Mastercard promotional content with image-based body | Sublime Security | 2mo ago Nov 5th, 2025 | /feeds/core/detection-rules/spam-mastercard-promotional-content-with-image-based-body-5f2cb559 | |
Spam: Personalized subject and greetings via Salesforce Marketing Cloud | Sublime Security | 2mo ago Nov 3rd, 2025 | /feeds/core/detection-rules/spam-personalized-subject-and-greetings-via-salesforce-marketing-cloud-c77f127f | |
Spam: Sexually explicit Google Drive share | Sublime Security | 5mo ago Aug 5th, 2025 | /feeds/core/detection-rules/spam-sexually-explicit-google-drive-share-3f951c06 | |
Spam: Sexually explicit Google group invitation | Sublime Security | 2mo ago Nov 12th, 2025 | /feeds/core/detection-rules/spam-sexually-explicit-google-group-invitation-4e0bec29 | |
Spam: Sexually explicit Looker Studio report | Sublime Security | 3mo ago Oct 2nd, 2025 | /feeds/core/detection-rules/spam-sexually-explicit-looker-studio-report-f1e649cd | |
Spam: Single recipient duplicated in cc | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/spam-single-recipient-duplicated-in-cc-387cacc9 | |
Spam: Unsolicited WordPress account creation or password reset request | Sublime Security | 2mo ago Nov 24th, 2025 | /feeds/core/detection-rules/spam-unsolicited-wordpress-account-creation-or-password-reset-request-e182b6b2 | |
Spoofable internal domain with suspicious signals | Sublime Security | 6mo ago Jul 23rd, 2025 | /feeds/core/detection-rules/spoofable-internal-domain-with-suspicious-signals-40089d69 | |
Subject and sender display name contains matching long alphanumeric string | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/subject-and-sender-display-name-contains-matching-long-alphanumeric-string-a8a0c831 | |
Suspected lookalike domain with suspicious language | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/suspected-lookalike-domain-with-suspicious-language-3674ced0 | |
Suspected WordPress abuse with cross-site scripting (XSS) indicators | Sublime Security | 5mo ago Aug 5th, 2025 | /feeds/core/detection-rules/suspected-wordpress-abuse-with-cross-site-scripting-xss-indicators-9c21225b | |
Suspicious attachment with unscannable Cloudflare link | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/suspicious-attachment-with-unscannable-cloudflare-link-00f92b6f | |
Suspicious DocuSign share from new domain | Sublime Security | 5mo ago Aug 5th, 2025 | /feeds/core/detection-rules/suspicious-docusign-share-from-new-domain-d430a1f3 | |
Suspicious invoice reference with missing or image-only attachments | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/suspicious-invoice-reference-with-missing-or-image-only-attachments-466c1680 | |
Suspicious link to Looker Studio (lookerstudio.google.com) from a new and unsolicited sender | Sublime Security | 12d ago Jan 12th, 2026 | /feeds/core/detection-rules/suspicious-link-to-looker-studio-lookerstudiogooglecom-from-a-new-and-unsolicited-sender-dbb50cb4 | |
Suspicious mailer received from Gmail servers | Sublime Security | 6mo ago Jul 16th, 2025 | /feeds/core/detection-rules/suspicious-mailer-received-from-gmail-servers-f05f04ee |