







Rule Name & Severity | Last Updated | Author | Types, Tactics & Capabilities | |
|---|---|---|---|---|
PayPal invoice abuse | 1d ago Feb 11th, 2026 | Sublime Security | /feeds/core/detection-rules/paypal-invoice-abuse-0ff7a0d4 | |
Reconnaissance: Empty subject with mismatched reply-to from new sender | 6d ago Feb 6th, 2026 | Sublime Security | /feeds/core/detection-rules/reconnaissance-empty-subject-with-mismatched-reply-to-from-new-sender-12f4bd45 | |
Canva infrastructure abuse | 6d ago Feb 6th, 2026 | Sublime Security | /feeds/core/detection-rules/canva-infrastructure-abuse-b69fdb5c | |
Credential phishing: Generic document sharing | 7d ago Feb 5th, 2026 | Sublime Security | /feeds/core/detection-rules/credential-phishing-generic-document-sharing-9f0e1d2c | |
Attachment: Legal themed message or PDF with suspicious indicators | 7d ago Feb 5th, 2026 | Sublime Security | /feeds/core/detection-rules/attachment-legal-themed-message-or-pdf-with-suspicious-indicators-19133301 | |
Attachment: PDF contains W9 or invoice YARA signatures | 8d ago Feb 4th, 2026 | Sublime Security | /feeds/core/detection-rules/attachment-pdf-contains-w9-or-invoice-yara-signatures-9a8e8a98 | |
Suspicious display name: Gmail sender with engaging languages | 9d ago Feb 3rd, 2026 | Sublime Security | /feeds/core/detection-rules/suspicious-display-name-gmail-sender-with-engaging-languages-82ca0ff1 | |
Impersonation: Executive using numbered local part | 13d ago Jan 30th, 2026 | Sublime Security | /feeds/core/detection-rules/impersonation-executive-using-numbered-local-part-8e005a22 | |
VIP impersonation with w2 request | 14d ago Jan 29th, 2026 | Sublime Security | /feeds/core/detection-rules/vip-impersonation-with-w2-request-e7e73fad | |
Brand impersonation: Aramco | 15d ago Jan 28th, 2026 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-aramco-96e87699 | |
Reconnaissance: Hotel booking reply-to redirect | 16d ago Jan 27th, 2026 | Sublime Security | /feeds/core/detection-rules/reconnaissance-hotel-booking-reply-to-redirect-08c36035 | |
Reconnaissance: Short generic greeting message | 16d ago Jan 27th, 2026 | Sublime Security | /feeds/core/detection-rules/reconnaissance-short-generic-greeting-message-c67dedab | |
Attachment: Fake lawyer & sports agent identities | 17d ago Jan 26th, 2026 | Sublime Security | /feeds/core/detection-rules/attachment-fake-lawyer-and-sports-agent-identities-7d3a2478 | |
Attachment: ICS file with meeting prefix | 17d ago Jan 26th, 2026 | Sublime Security | /feeds/core/detection-rules/attachment-ics-file-with-meeting-prefix-383a5810 | |
Headers: Fake in-reply-to with wildcard sender and missing thread context | 20d ago Jan 23rd, 2026 | Sublime Security | /feeds/core/detection-rules/headers-fake-in-reply-to-with-wildcard-sender-and-missing-thread-context-89da670a | |
Service abuse: Adobe legitimate domain with document approval language | 20d ago Jan 23rd, 2026 | Sublime Security | /feeds/core/detection-rules/service-abuse-adobe-legitimate-domain-with-document-approval-language-237f4da4 | |
BEC/Fraud: Romance scam | 21d ago Jan 22nd, 2026 | Sublime Security | /feeds/core/detection-rules/becfraud-romance-scam-0243cdaa | |
Brand impersonation: AuthentiSign | 22d ago Jan 21st, 2026 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-authentisign-445a8c8b | |
Attachment: Invoice and W-9 PDFs with suspicious creators | 22d ago Jan 21st, 2026 | Sublime Security | /feeds/core/detection-rules/attachment-invoice-and-w-9-pdfs-with-suspicious-creators-305d6e32 | |
Link: Self-sent message with quarterly document review request | 22d ago Jan 21st, 2026 | Sublime Security | /feeds/core/detection-rules/link-self-sent-message-with-quarterly-document-review-request-3c42cec6 |