Rule Name & Severity | Author | Last Updated | Labels | |
|---|---|---|---|---|
Adobe branded PDF file linking to a password-protected file from untrusted sender | Sublime Security | 3mo ago Jul 16th, 2025 | /feeds/core/detection-rules/adobe-branded-pdf-file-linking-to-a-password-protected-file-from-untrusted-sender-5ea75469 | |
Advance Fee Fraud (AFF) from freemail provider or suspicious TLD | Sublime Security | 9d ago Nov 3rd, 2025 | /feeds/core/detection-rules/advance-fee-fraud-aff-from-freemail-provider-or-suspicious-tld-6a5af373 | |
Attachment: Compensation review lure with QR code | Sublime Security | 14d ago Oct 29th, 2025 | /feeds/core/detection-rules/attachment-compensation-review-lure-with-qr-code-9fd8185c | |
Attachment: EML with link to credential phishing page | Sublime Security | 3mo ago Jul 16th, 2025 | /feeds/core/detection-rules/attachment-eml-with-link-to-credential-phishing-page-1df41cca | |
Attachment: Encrypted PDF with credential theft body | Sublime Security | 4d ago Nov 8th, 2025 | /feeds/core/detection-rules/attachment-encrypted-pdf-with-credential-theft-body-c9596c9a | |
Attachment: Fake attachment image lure | Sublime Security | 1mo ago Sep 22nd, 2025 | /feeds/core/detection-rules/attachment-fake-attachment-image-lure-96b8b285 | |
Attachment: Fake scan-to-email | Sublime Security | 1mo ago Sep 22nd, 2025 | /feeds/core/detection-rules/attachment-fake-scan-to-email-ea850cc1 | |
Attachment: Fake secure message and suspicious indicators | Sublime Security | 3mo ago Jul 16th, 2025 | /feeds/core/detection-rules/attachment-fake-secure-message-and-suspicious-indicators-20a34d94 | |
Attachment: Fake Slack installer | Sublime Security | 2y ago Nov 29th, 2023 | /feeds/core/detection-rules/attachment-fake-slack-installer-cded2d2f | |
Attachment: Fake Zoom installer | Sublime Security | 2y ago Nov 29th, 2023 | /feeds/core/detection-rules/attachment-fake-zoom-installer-840a12a6 | |
Attachment: Fictitious invoice using LinkedIn's address | Sublime Security | 2mo ago Sep 3rd, 2025 | /feeds/core/detection-rules/attachment-fictitious-invoice-using-linkedins-address-aeee3d9f | |
Attachment: HTML smuggling - QR Code with suspicious links | Sublime Security | 3mo ago Jul 16th, 2025 | /feeds/core/detection-rules/attachment-html-smuggling-qr-code-with-suspicious-links-010e757d | |
Attachment: Legal themed message with PDF containing suspicious link | Sublime Security | 3mo ago Aug 5th, 2025 | /feeds/core/detection-rules/attachment-legal-themed-message-with-pdf-containing-suspicious-link-19133301 | |
Attachment: Microsoft impersonation via PDF with link and suspicious language | Sublime Security | 3mo ago Jul 16th, 2025 | /feeds/core/detection-rules/attachment-microsoft-impersonation-via-pdf-with-link-and-suspicious-language-70d41c7f | |
Attachment: Office file contains OLE relationship to credential phishing page | Sublime Security | 3mo ago Jul 16th, 2025 | /feeds/core/detection-rules/attachment-office-file-contains-ole-relationship-to-credential-phishing-page-d55793d0 | |
Attachment: PDF file with low reputation link to ZIP file (unsolicited) | Michael Tingle | 3mo ago Jul 16th, 2025 | /feeds/core/detection-rules/attachment-pdf-file-with-low-reputation-link-to-zip-file-unsolicited-d1ee2859 | |
Attachment: PDF with credential theft language and link to a free subdomain (unsolicited) | Sublime Security | 3mo ago Jul 16th, 2025 | /feeds/core/detection-rules/attachment-pdf-with-credential-theft-language-and-link-to-a-free-subdomain-unsolicited-90f4ef4e | |
Attachment: PDF with Microsoft Purview message impersonation | Sublime Security | 2d ago Nov 10th, 2025 | /feeds/core/detection-rules/attachment-pdf-with-microsoft-purview-message-impersonation-571d4964 | |
Attachment: PDF with suspicious language and redirect to suspicious file type | Sublime Security | 1y ago May 22nd, 2024 | /feeds/core/detection-rules/attachment-pdf-with-suspicious-language-and-redirect-to-suspicious-file-type-adda3c3f | |
Attachment: QR code link with base64-encoded recipient address | Sublime Security | 3mo ago Aug 5th, 2025 | /feeds/core/detection-rules/attachment-qr-code-link-with-base64-encoded-recipient-address-927a0c1a | |
Attachment: QR code with credential phishing indicators | Sublime Security | 2mo ago Sep 4th, 2025 | /feeds/core/detection-rules/attachment-qr-code-with-credential-phishing-indicators-9f1681e1 | |
Attachment: RFC822 containing suspicious file sharing language with links from untrusted sender | Sublime Security | 8d ago Nov 4th, 2025 | /feeds/core/detection-rules/attachment-rfc822-containing-suspicious-file-sharing-language-with-links-from-untrusted-sender-d96854d7 | |
Attachment: RFP/RFQ impersonating government entities | Sublime Security | 1y ago Jan 30th, 2024 | /feeds/core/detection-rules/attachment-rfprfq-impersonating-government-entities-3b73e3b3 | |
Attachment: USDA bid invitation impersonation | Sublime Security | 3mo ago Aug 5th, 2025 | /feeds/core/detection-rules/attachment-usda-bid-invitation-impersonation-34eb9493 | |
BEC: Employee impersonation with subject manipulation | Sublime Security | 3mo ago Jul 16th, 2025 | /feeds/core/detection-rules/bec-employee-impersonation-with-subject-manipulation-9adfc77b | |
BEC/Fraud: Generic scam attempt to undisclosed recipients | Sublime Security | 3mo ago Aug 5th, 2025 | /feeds/core/detection-rules/becfraud-generic-scam-attempt-to-undisclosed-recipients-5dac401f | |
BEC/Fraud: Job scam fake thread or plaintext pivot to freemail | Sublime Security | 2h ago Nov 12th, 2025 | /feeds/core/detection-rules/becfraud-job-scam-fake-thread-or-plaintext-pivot-to-freemail-ce21c151 | |
BEC/Fraud: Student loan callback phishing | Sublime Security | 2mo ago Sep 5th, 2025 | /feeds/core/detection-rules/becfraud-student-loan-callback-phishing-a71f82c3 | |
BEC with unusual reply-to or return-path mismatch | Sublime Security | 3mo ago Aug 5th, 2025 | /feeds/core/detection-rules/bec-with-unusual-reply-to-or-return-path-mismatch-83e5e2df | |
Brand impersonation: Amazon Web Services (AWS) | Sublime Security | 1mo ago Oct 10th, 2025 | /feeds/core/detection-rules/brand-impersonation-amazon-web-services-aws-31de94e0 | |
Brand impersonation: Amazon with suspicious attachment | Sublime Security | 3mo ago Jul 16th, 2025 | /feeds/core/detection-rules/brand-impersonation-amazon-with-suspicious-attachment-5751dcb9 | |
Brand impersonation: Aramco | Sublime Security | 1mo ago Sep 15th, 2025 | /feeds/core/detection-rules/brand-impersonation-aramco-96e87699 | |
Brand impersonation: Binance | Sublime Security | 2mo ago Sep 3rd, 2025 | /feeds/core/detection-rules/brand-impersonation-binance-c3302a76 | |
Brand impersonation: Booking.com | Sublime Security | 9d ago Nov 3rd, 2025 | /feeds/core/detection-rules/brand-impersonation-bookingcom-d1d8882f | |
Brand impersonation: Chase bank with credential phishing indicators | Sublime Security | 1mo ago Sep 22nd, 2025 | /feeds/core/detection-rules/brand-impersonation-chase-bank-with-credential-phishing-indicators-d9577856 | |
Brand Impersonation: Disney | Sublime Security | 1mo ago Sep 22nd, 2025 | /feeds/core/detection-rules/brand-impersonation-disney-bf90b8fb | |
Brand impersonation: DocuSign branded attachment lure with no DocuSign links | Sublime Security | 21d ago Oct 22nd, 2025 | /feeds/core/detection-rules/brand-impersonation-docusign-branded-attachment-lure-with-no-docusign-links-814a5694 | |
Brand impersonation: DocuSign PDF attachment with suspicious link | Sublime Security | 21d ago Oct 22nd, 2025 | /feeds/core/detection-rules/brand-impersonation-docusign-pdf-attachment-with-suspicious-link-2601cbb7 | |
Brand impersonation: Exodus | Sublime Security | 3mo ago Aug 5th, 2025 | /feeds/core/detection-rules/brand-impersonation-exodus-40c77ecc | |
Brand impersonation: Interac | Sublime Security | 1y ago Sep 16th, 2024 | /feeds/core/detection-rules/brand-impersonation-interac-50a883dc | |
Brand impersonation: Internal Revenue Service | Sublime Security | 26d ago Oct 17th, 2025 | /feeds/core/detection-rules/brand-impersonation-internal-revenue-service-3c63f8e9 | |
Brand impersonation: Mailchimp | Sublime Security | 1mo ago Sep 22nd, 2025 | /feeds/core/detection-rules/brand-impersonation-mailchimp-48b454c7 | |
Brand impersonation: MetaMask | Sublime Security | 1mo ago Sep 22nd, 2025 | /feeds/core/detection-rules/brand-impersonation-metamask-ddb4c618 | |
Brand impersonation: Microsoft logo or suspicious language with open redirect | Sublime Security | 1y ago Mar 7th, 2024 | /feeds/core/detection-rules/brand-impersonation-microsoft-logo-or-suspicious-language-with-open-redirect-27b8d8d8 | |
Brand impersonation: Microsoft Planner with suspicious link | Sublime Security | 3mo ago Aug 5th, 2025 | /feeds/core/detection-rules/brand-impersonation-microsoft-planner-with-suspicious-link-ea363c08 | |
Brand impersonation: Microsoft quarantine release notification in image attachment | Sublime Security | 3mo ago Jul 16th, 2025 | /feeds/core/detection-rules/brand-impersonation-microsoft-quarantine-release-notification-in-image-attachment-185db6b3 | |
Brand impersonation: Microsoft with embedded logo and credential theft language | Sublime Security | 26d ago Oct 17th, 2025 | /feeds/core/detection-rules/brand-impersonation-microsoft-with-embedded-logo-and-credential-theft-language-3ee9ef3d | |
Brand impersonation: Microsoft with low reputation links | Sublime Security | 4d ago Nov 8th, 2025 | /feeds/core/detection-rules/brand-impersonation-microsoft-with-low-reputation-links-b59201b6 | |
Brand impersonation: Navan | Sublime Security | 1mo ago Sep 22nd, 2025 | /feeds/core/detection-rules/brand-impersonation-navan-3573e9a8 | |
Brand impersonation: SendGrid | Sublime Security | 5d ago Nov 7th, 2025 | /feeds/core/detection-rules/brand-impersonation-sendgrid-d800124f |