Rule Name & Severity | Author | Last Updated | Labels | |
|---|---|---|---|---|
AnonymousFox indicators | Sublime Security | 6mo ago Aug 5th, 2025 | /feeds/core/detection-rules/anonymousfox-indicators-2506206e | |
Attachment: Adobe image lure in body or attachment with suspicious link | Sublime Security | 1mo ago Jan 5th, 2026 | /feeds/core/detection-rules/attachment-adobe-image-lure-in-body-or-attachment-with-suspicious-link-1d7add81 | |
Attachment: Any HTML file within archive (unsolicited) | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/attachment-any-html-file-within-archive-unsolicited-6a67c02c | |
Attachment: Archive containing HTML file with file scheme link | Sublime Security | 7mo ago Jul 16th, 2025 | /feeds/core/detection-rules/attachment-archive-containing-html-file-with-file-scheme-link-edf6d0d9 | |
Attachment: Calendar file with invisible Unicode characters | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/attachment-calendar-file-with-invisible-unicode-characters-050fceac | |
Attachment: Compensation review lure with QR code | Sublime Security | 2mo ago Dec 10th, 2025 | /feeds/core/detection-rules/attachment-compensation-review-lure-with-qr-code-9fd8185c | |
Attachment: CVE-2025-24071 - Microsoft Windows File Explorer Spoofing Vulnerability | Sublime Security | 11mo ago Mar 21st, 2025 | /feeds/core/detection-rules/attachment-cve-2025-24071-microsoft-windows-file-explorer-spoofing-vulnerability-2e69fa0b | |
Attachment: Decoy PDF author (Julie P.) | Sublime Security | 6mo ago Aug 5th, 2025 | /feeds/core/detection-rules/attachment-decoy-pdf-author-julie-p-4324213a | |
Attachment: DocuSign impersonation via PDF linking to new domain | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/attachment-docusign-impersonation-via-pdf-linking-to-new-domain-f0c96282 | |
Attachment: DOCX with hyperlink targeting recipient address | Sublime Security | 2mo ago Dec 17th, 2025 | /feeds/core/detection-rules/attachment-docx-with-hyperlink-targeting-recipient-address-9ec8fa49 | |
Attachment: Double base64-encoded zip file in HTML smuggling attachment | @ajpc500 | 6mo ago Aug 5th, 2025 | /feeds/core/detection-rules/attachment-double-base64-encoded-zip-file-in-html-smuggling-attachment-61ebb07b | |
Attachment: Dropbox image lure with no Dropbox domains in links | Sublime Security | 7mo ago Jul 16th, 2025 | /feeds/core/detection-rules/attachment-dropbox-image-lure-with-no-dropbox-domains-in-links-500eee2d | |
Attachment: EML containing a base64 encoded script | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/attachment-eml-containing-a-base64-encoded-script-fc3d9445 | |
Attachment: EML file contains HTML attachment with login portal indicators | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/attachment-eml-file-contains-html-attachment-with-login-portal-indicators-6e4df158 | |
Attachment: EML file with HTML attachment (unsolicited) | Sublime Security | 6mo ago Aug 20th, 2025 | /feeds/core/detection-rules/attachment-eml-file-with-html-attachment-unsolicited-c24fd191 | |
Attachment: EML file with IPFS links | Sublime Security | 3mo ago Nov 4th, 2025 | /feeds/core/detection-rules/attachment-eml-file-with-ipfs-links-1fe9d7e7 | |
Attachment: EML with embedded Javascript in SVG file | Sublime Security | 6mo ago Aug 8th, 2025 | /feeds/core/detection-rules/attachment-eml-with-embedded-javascript-in-svg-file-dfafb78f | |
Attachment: EML with link to credential phishing page | Sublime Security | 7mo ago Jul 16th, 2025 | /feeds/core/detection-rules/attachment-eml-with-link-to-credential-phishing-page-1df41cca | |
Attachment: EML with SharePoint files shared from GoDaddy federated tenants | Sublime Security | 4mo ago Sep 23rd, 2025 | /feeds/core/detection-rules/attachment-eml-with-sharepoint-files-shared-from-godaddy-federated-tenants-02c1f590 | |
Attachment: EML with Sharepoint link likely unrelated to sender | Sublime Security | 4mo ago Sep 23rd, 2025 | /feeds/core/detection-rules/attachment-eml-with-sharepoint-link-likely-unrelated-to-sender-0a4fd31b | |
Attachment: EML with suspicious indicators | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/attachment-eml-with-suspicious-indicators-deb5d08d | |
Attachment: Encrypted PDF with credential theft body | Sublime Security | 2mo ago Dec 1st, 2025 | /feeds/core/detection-rules/attachment-encrypted-pdf-with-credential-theft-body-c9596c9a | |
Attachment: Excel file with document sharing lure created by Go Excelize | Sublime Security | 19d ago Jan 29th, 2026 | /feeds/core/detection-rules/attachment-excel-file-with-document-sharing-lure-created-by-go-excelize-dfaf267f | |
Attachment: Excel file with suspicious template identifier | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/attachment-excel-file-with-suspicious-template-identifier-40f84b4b | |
Attachment: Excel Web Query File (IQY) | @jkcoote | 3y ago Aug 21st, 2023 | /feeds/core/detection-rules/attachment-excel-web-query-file-iqy-510412b5 | |
Attachment: Fake attachment image lure | Sublime Security | 4mo ago Sep 22nd, 2025 | /feeds/core/detection-rules/attachment-fake-attachment-image-lure-96b8b285 | |
Attachment: Fake scan-to-email | Sublime Security | 4mo ago Sep 22nd, 2025 | /feeds/core/detection-rules/attachment-fake-scan-to-email-ea850cc1 | |
Attachment: Fake secure message and suspicious indicators | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/attachment-fake-secure-message-and-suspicious-indicators-20a34d94 | |
Attachment: Fake voicemail via PDF | Sublime Security | 6mo ago Aug 5th, 2025 | /feeds/core/detection-rules/attachment-fake-voicemail-via-pdf-d3587209 | |
Attachment: HTML attachment with Javascript location | @vector_sec | 6mo ago Aug 5th, 2025 | /feeds/core/detection-rules/attachment-html-attachment-with-javascript-location-e0611295 | |
Attachment: HTML attachment with login portal indicators | @ajpc500 | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/attachment-html-attachment-with-login-portal-indicators-3aabf4a7 | |
Attachment: HTML file contains exclusively Javascript | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/attachment-html-file-contains-exclusively-javascript-b6d38168 | |
Attachment: HTML file with excessive 'const' declarations and abnormally long timeouts | Sublime Security | 3mo ago Nov 3rd, 2025 | /feeds/core/detection-rules/attachment-html-file-with-excessive-const-declarations-and-abnormally-long-timeouts-66f8a07a | |
Attachment: HTML file with excessive padding and suspicious patterns | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/attachment-html-file-with-excessive-padding-and-suspicious-patterns-0a6aee1e | |
Attachment: HTML file with reference to recipient and suspicious patterns | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/attachment-html-file-with-reference-to-recipient-and-suspicious-patterns-5333493d | |
Attachment: HTML smuggling 'body onload' linking to suspicious destination | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/attachment-html-smuggling-body-onload-linking-to-suspicious-destination-c1e2beed | |
Attachment: HTML smuggling 'body onload' with high entropy and suspicious text | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/attachment-html-smuggling-body-onload-with-high-entropy-and-suspicious-text-329ac12d | |
Attachment: HTML smuggling Microsoft sign in | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/attachment-html-smuggling-microsoft-sign-in-878d6385 | |
Attachment: HTML smuggling - QR Code with suspicious links | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/attachment-html-smuggling-qr-code-with-suspicious-links-010e757d | |
Attachment: HTML smuggling with atob and high entropy | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/attachment-html-smuggling-with-atob-and-high-entropy-03fcac11 | |
Attachment: HTML smuggling with atob and high entropy via calendar invite | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/attachment-html-smuggling-with-atob-and-high-entropy-via-calendar-invite-94d84614 | |
Attachment: HTML smuggling with auto-downloaded file | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/attachment-html-smuggling-with-auto-downloaded-file-abf724f5 | |
Attachment: HTML smuggling with base64 encoded JavaScript function | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/attachment-html-smuggling-with-base64-encoded-javascript-function-4e8a12ec | |
Attachment: HTML smuggling with base64 encoded ZIP file | Sublime Security | 2mo ago Nov 20th, 2025 | /feeds/core/detection-rules/attachment-html-smuggling-with-base64-encoded-zip-file-47e388de | |
Attachment: HTML smuggling with concatenation obfuscation | @vector_sec | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/attachment-html-smuggling-with-concatenation-obfuscation-108ab346 | |
Attachment: HTML smuggling with decimal encoding | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/attachment-html-smuggling-with-decimal-encoding-f99213c4 | |
Attachment: HTML smuggling with embedded base64-encoded ISO | Sublime Security | 3y ago Aug 21st, 2023 | /feeds/core/detection-rules/attachment-html-smuggling-with-embedded-base64-encoded-iso-294ecd2d | |
Attachment: HTML smuggling with eval and atob | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/attachment-html-smuggling-with-eval-and-atob-9f521ca2 | |
Attachment: HTML smuggling with eval and atob via calendar invite | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/attachment-html-smuggling-with-eval-and-atob-via-calendar-invite-597c2edd | |
Attachment: HTML smuggling with excessive line break obfuscation | Sublime Security | 1mo ago Jan 12th, 2026 | /feeds/core/detection-rules/attachment-html-smuggling-with-excessive-line-break-obfuscation-7e901440 |