Rule Name & Severity | Author | Last Updated | Labels | |
|---|---|---|---|---|
Attachment: Adobe image lure in body or attachment with suspicious link | Sublime Security | 18d ago Jan 5th, 2026 | /feeds/core/detection-rules/attachment-adobe-image-lure-in-body-or-attachment-with-suspicious-link-1d7add81 | |
Attachment: Callback phishing solicitation via image file | @vector_sec | 11d ago Jan 12th, 2026 | /feeds/core/detection-rules/attachment-callback-phishing-solicitation-via-image-file-60acbb36 | |
Attachment: Fake attachment image lure | Sublime Security | 4mo ago Sep 22nd, 2025 | /feeds/core/detection-rules/attachment-fake-attachment-image-lure-96b8b285 | |
Attachment: Fake scan-to-email | Sublime Security | 4mo ago Sep 22nd, 2025 | /feeds/core/detection-rules/attachment-fake-scan-to-email-ea850cc1 | |
Attachment: Fake secure message and suspicious indicators | Sublime Security | 11d ago Jan 12th, 2026 | /feeds/core/detection-rules/attachment-fake-secure-message-and-suspicious-indicators-20a34d94 | |
Attachment: Microsoft impersonation via PDF with link and suspicious language | Sublime Security | 6mo ago Jul 16th, 2025 | /feeds/core/detection-rules/attachment-microsoft-impersonation-via-pdf-with-link-and-suspicious-language-70d41c7f | |
Attachment: QR code link with base64-encoded recipient address | Sublime Security | 11d ago Jan 12th, 2026 | /feeds/core/detection-rules/attachment-qr-code-link-with-base64-encoded-recipient-address-927a0c1a | |
Attachment: QR code with userinfo portion | Sublime Security | 11d ago Jan 12th, 2026 | /feeds/core/detection-rules/attachment-qr-code-with-userinfo-portion-9d62cc5c | |
Attachment: SVG files with evasion elements | Sublime Security | 5mo ago Aug 8th, 2025 | /feeds/core/detection-rules/attachment-svg-files-with-evasion-elements-5d2dbb60 | |
Brand impersonation: Coinbase with suspicious links | Sublime Security | 4mo ago Sep 22nd, 2025 | /feeds/core/detection-rules/brand-impersonation-coinbase-with-suspicious-links-b61e2f8e | |
Brand impersonation: DocuSign with embedded QR code | Sublime Security | 3mo ago Oct 17th, 2025 | /feeds/core/detection-rules/brand-impersonation-docusign-with-embedded-qr-code-f5cde463 | |
Brand impersonation: Fake Fax | Sublime Security | 2d ago Jan 21st, 2026 | /feeds/core/detection-rules/brand-impersonation-fake-fax-2a96b90a | |
Brand impersonation: Microsoft Planner with suspicious link | Sublime Security | 11d ago Jan 12th, 2026 | /feeds/core/detection-rules/brand-impersonation-microsoft-planner-with-suspicious-link-ea363c08 | |
Brand impersonation: Microsoft with low reputation links | Sublime Security | 11d ago Jan 12th, 2026 | /feeds/core/detection-rules/brand-impersonation-microsoft-with-low-reputation-links-b59201b6 | |
Brand impersonation: USPS | Sublime Security | 3d ago Jan 20th, 2026 | /feeds/core/detection-rules/brand-impersonation-usps-28b9130a | |
Cloud storage impersonation with credential theft indicators | Sublime Security | 4mo ago Sep 22nd, 2025 | /feeds/core/detection-rules/cloud-storage-impersonation-with-credential-theft-indicators-4c20f72c | |
Credential phishing: Hyper-linked image leading to free file host | Sublime Security | 5mo ago Aug 5th, 2025 | /feeds/core/detection-rules/credential-phishing-hyper-linked-image-leading-to-free-file-host-f5cb1eca | |
Credential phishing: Image as content, short or no body contents | Sublime Security | 11d ago Jan 12th, 2026 | /feeds/core/detection-rules/credential-phishing-image-as-content-short-or-no-body-contents-01313f38 | |
Credential theft: Gophish abuse with hidden tracking image | Sublime Security | 2mo ago Nov 5th, 2025 | /feeds/core/detection-rules/credential-theft-gophish-abuse-with-hidden-tracking-image-59915ceb | |
Image as content with a link to an open redirect (unsolicited) | Sublime Security | 11d ago Jan 12th, 2026 | /feeds/core/detection-rules/image-as-content-with-a-link-to-an-open-redirect-unsolicited-f5cec36b | |
Inline image as message with attachment or link | Sublime Security | 6mo ago Jul 16th, 2025 | /feeds/core/detection-rules/inline-image-as-message-with-attachment-or-link-823d7107 | |
Invoicera infrastructure abuse | Sublime Security | 2y ago Mar 7th, 2024 | /feeds/core/detection-rules/invoicera-infrastructure-abuse-1e56f310 | |
PHP Mailer with common phishing attachments | @vector_sec | 3y ago Aug 21st, 2023 | /feeds/core/detection-rules/php-mailer-with-common-phishing-attachments-07e03563 | |
Spam: BlackBaud infrastructure abuse | Sublime Security | 2y ago Jan 17th, 2024 | /feeds/core/detection-rules/spam-blackbaud-infrastructure-abuse-3db46591 | |
Spam: Image as content with hidden HTML element | Sublime Security | 51m ago Jan 23rd, 2026 | /feeds/core/detection-rules/spam-image-as-content-with-hidden-html-element-5de8861f | |
Spam: Item giveaway spam template | Sublime Security | 5mo ago Aug 5th, 2025 | /feeds/core/detection-rules/spam-item-giveaway-spam-template-06a5f93b | |
Spam: Mastercard promotional content with image-based body | Sublime Security | 2mo ago Nov 5th, 2025 | /feeds/core/detection-rules/spam-mastercard-promotional-content-with-image-based-body-5f2cb559 |