Rule Name & Severity | Author | Last Updated | Labels | |
|---|---|---|---|---|
Adobe branded PDF file linking to a password-protected file from untrusted sender | Sublime Security | 3mo ago Jul 16th, 2025 | /feeds/core/detection-rules/adobe-branded-pdf-file-linking-to-a-password-protected-file-from-untrusted-sender-5ea75469 | |
Attachment: Adobe image lure in body or attachment with suspicious link | Sublime Security | 1mo ago Sep 22nd, 2025 | /feeds/core/detection-rules/attachment-adobe-image-lure-in-body-or-attachment-with-suspicious-link-1d7add81 | |
Attachment: Decoy PDF author (Julie P.) | Sublime Security | 3mo ago Aug 5th, 2025 | /feeds/core/detection-rules/attachment-decoy-pdf-author-julie-p-4324213a | |
Attachment: DocuSign impersonation via PDF linking to new domain | Sublime Security | 3mo ago Aug 5th, 2025 | /feeds/core/detection-rules/attachment-docusign-impersonation-via-pdf-linking-to-new-domain-f0c96282 | |
Attachment: Dropbox image lure with no Dropbox domains in links | Sublime Security | 3mo ago Jul 16th, 2025 | /feeds/core/detection-rules/attachment-dropbox-image-lure-with-no-dropbox-domains-in-links-500eee2d | |
Attachment: EML with SharePoint files shared from GoDaddy federated tenants | Sublime Security | 1mo ago Sep 23rd, 2025 | /feeds/core/detection-rules/attachment-eml-with-sharepoint-files-shared-from-godaddy-federated-tenants-02c1f590 | |
Attachment: EML with Sharepoint link likely unrelated to sender | Sublime Security | 1mo ago Sep 23rd, 2025 | /feeds/core/detection-rules/attachment-eml-with-sharepoint-link-likely-unrelated-to-sender-0a4fd31b | |
Attachment: Fake secure message and suspicious indicators | Sublime Security | 3mo ago Jul 16th, 2025 | /feeds/core/detection-rules/attachment-fake-secure-message-and-suspicious-indicators-20a34d94 | |
Attachment: Fake Slack installer | Sublime Security | 2y ago Nov 29th, 2023 | /feeds/core/detection-rules/attachment-fake-slack-installer-cded2d2f | |
Attachment: Fake Zoom installer | Sublime Security | 2y ago Nov 29th, 2023 | /feeds/core/detection-rules/attachment-fake-zoom-installer-840a12a6 | |
Attachment: HTML smuggling Microsoft sign in | Sublime Security | 3mo ago Aug 5th, 2025 | /feeds/core/detection-rules/attachment-html-smuggling-microsoft-sign-in-878d6385 | |
Attachment: HTML with emoji-to-character map | Sublime Security | 3mo ago Aug 5th, 2025 | /feeds/core/detection-rules/attachment-html-with-emoji-to-character-map-3119d086 | |
Attachment: Microsoft 365 credential phishing | Sublime Security | 3mo ago Aug 5th, 2025 | /feeds/core/detection-rules/attachment-microsoft-365-credential-phishing-edce0229 | |
Attachment: Microsoft impersonation via PDF with link and suspicious language | Sublime Security | 3mo ago Jul 16th, 2025 | /feeds/core/detection-rules/attachment-microsoft-impersonation-via-pdf-with-link-and-suspicious-language-70d41c7f | |
Attachment: PDF file with link to fake Bitcoin exchange | Sublime Security | 3mo ago Aug 5th, 2025 | /feeds/core/detection-rules/attachment-pdf-file-with-link-to-fake-bitcoin-exchange-47601cb7 | |
Attachment: PDF with Microsoft Purview message impersonation | Sublime Security | 2d ago Nov 10th, 2025 | /feeds/core/detection-rules/attachment-pdf-with-microsoft-purview-message-impersonation-571d4964 | |
Attachment: RFP/RFQ impersonating government entities | Sublime Security | 1y ago Jan 30th, 2024 | /feeds/core/detection-rules/attachment-rfprfq-impersonating-government-entities-3b73e3b3 | |
Attachment: USDA bid invitation impersonation | Sublime Security | 3mo ago Aug 5th, 2025 | /feeds/core/detection-rules/attachment-usda-bid-invitation-impersonation-34eb9493 | |
BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns | Sublime Security | 3mo ago Aug 5th, 2025 | /feeds/core/detection-rules/becfraud-urgent-language-and-suspicious-sendinginfrastructure-patterns-ba8a79e0 | |
Brand impersonation: Adobe (QR code) | Sublime Security | 1mo ago Oct 3rd, 2025 | /feeds/core/detection-rules/brand-impersonation-adobe-qr-code-2fc36c6d | |
Brand impersonation: Adobe with suspicious language and link | Sublime Security | 26d ago Oct 17th, 2025 | /feeds/core/detection-rules/brand-impersonation-adobe-with-suspicious-language-and-link-32cc8bf1 | |
Brand impersonation: ADP | Sublime Security | 1y ago Jan 9th, 2024 | /feeds/core/detection-rules/brand-impersonation-adp-bb9cf46b | |
Brand impersonation: AliExpress | Sublime Security | 3mo ago Aug 5th, 2025 | /feeds/core/detection-rules/brand-impersonation-aliexpress-b14703d8 | |
Brand impersonation: Amazon | Sublime Security | 8d ago Nov 4th, 2025 | /feeds/core/detection-rules/brand-impersonation-amazon-13fc967d | |
Brand impersonation: Amazon Web Services (AWS) | Sublime Security | 1mo ago Oct 10th, 2025 | /feeds/core/detection-rules/brand-impersonation-amazon-web-services-aws-31de94e0 | |
Brand impersonation: Amazon with suspicious attachment | Sublime Security | 3mo ago Jul 16th, 2025 | /feeds/core/detection-rules/brand-impersonation-amazon-with-suspicious-attachment-5751dcb9 | |
Brand impersonation: American Express (AMEX) | Sublime Security | 4mo ago Jul 10th, 2025 | /feeds/core/detection-rules/brand-impersonation-american-express-amex-992a9fa9 | |
Brand impersonation: Apple | Sublime Security | 2y ago Aug 21st, 2023 | /feeds/core/detection-rules/brand-impersonation-apple-0b17f2c2 | |
Brand impersonation: Aquent | Sublime Security | 1mo ago Oct 9th, 2025 | /feeds/core/detection-rules/brand-impersonation-aquent-5074459c | |
Brand impersonation: Aramco | Sublime Security | 1mo ago Sep 15th, 2025 | /feeds/core/detection-rules/brand-impersonation-aramco-96e87699 | |
Brand impersonation: Bank of America | Sublime Security | 1y ago Jun 14th, 2024 | /feeds/core/detection-rules/brand-impersonation-bank-of-america-d2fc6ea1 | |
Brand impersonation: Barracuda Networks | Sublime Security | 1mo ago Sep 26th, 2025 | /feeds/core/detection-rules/brand-impersonation-barracuda-networks-583fd5eb | |
Brand impersonation: Binance | Sublime Security | 2mo ago Sep 3rd, 2025 | /feeds/core/detection-rules/brand-impersonation-binance-c3302a76 | |
Brand impersonation: Blockchain[.]com | Sublime Security | 1y ago Apr 23rd, 2024 | /feeds/core/detection-rules/brand-impersonation-blockchaincom-0d85e555 | |
Brand impersonation: Booking.com | Sublime Security | 9d ago Nov 3rd, 2025 | /feeds/core/detection-rules/brand-impersonation-bookingcom-d1d8882f | |
Brand impersonation: Box file sharing service | Sublime Security | 1mo ago Sep 23rd, 2025 | /feeds/core/detection-rules/brand-impersonation-box-file-sharing-service-03da310c | |
Brand impersonation: Capital One | Sublime Security | 1mo ago Oct 3rd, 2025 | /feeds/core/detection-rules/brand-impersonation-capital-one-d53848e4 | |
Brand impersonation: Charles Schwab | Sublime Security | 2mo ago Sep 3rd, 2025 | /feeds/core/detection-rules/brand-impersonation-charles-schwab-7abde595 | |
Brand impersonation: Chase Bank | Sublime Security | 1mo ago Sep 22nd, 2025 | /feeds/core/detection-rules/brand-impersonation-chase-bank-c680f1e7 | |
Brand impersonation: Chase bank with credential phishing indicators | Sublime Security | 1mo ago Sep 22nd, 2025 | /feeds/core/detection-rules/brand-impersonation-chase-bank-with-credential-phishing-indicators-d9577856 | |
Brand impersonation: Coinbase | Sublime Security | 8d ago Nov 4th, 2025 | /feeds/core/detection-rules/brand-impersonation-coinbase-3dca757a | |
Brand impersonation: Coinbase with suspicious links | Sublime Security | 1mo ago Sep 22nd, 2025 | /feeds/core/detection-rules/brand-impersonation-coinbase-with-suspicious-links-b61e2f8e | |
Brand impersonation: Dashlane | Sublime Security | 3mo ago Jul 16th, 2025 | /feeds/core/detection-rules/brand-impersonation-dashlane-9e400937 | |
Brand impersonation: DHL | Sublime Security | 26d ago Oct 17th, 2025 | /feeds/core/detection-rules/brand-impersonation-dhl-be4b4ae0 | |
Brand impersonation: DigitalOcean | Sublime Security | 1mo ago Sep 18th, 2025 | /feeds/core/detection-rules/brand-impersonation-digitalocean-7f2f0e97 | |
Brand impersonation: Discord notification | Sublime Security | 20d ago Oct 23rd, 2025 | /feeds/core/detection-rules/brand-impersonation-discord-notification-97007826 | |
Brand Impersonation: Disney | Sublime Security | 1mo ago Sep 22nd, 2025 | /feeds/core/detection-rules/brand-impersonation-disney-bf90b8fb | |
Brand impersonation: DocSend | Sublime Security | 3mo ago Aug 5th, 2025 | /feeds/core/detection-rules/brand-impersonation-docsend-cd9a3f7a | |
Brand impersonation: DocuSign | Sublime Security | 5mo ago May 21st, 2025 | /feeds/core/detection-rules/brand-impersonation-docusign-4d29235c | |
Brand impersonation: DocuSign branded attachment lure with no DocuSign links | Sublime Security | 21d ago Oct 22nd, 2025 | /feeds/core/detection-rules/brand-impersonation-docusign-branded-attachment-lure-with-no-docusign-links-814a5694 |