







Rule Name & Severity | Last Updated | Author | Types, Tactics & Capabilities | |
|---|---|---|---|---|
VIP Impersonation via Google Group relay with suspicious indicators | 3h ago Nov 12th, 2025 | Sublime Security | /feeds/core/detection-rules/vip-impersonation-via-google-group-relay-with-suspicious-indicators-57f9cd3b | |
BEC/Fraud: Job scam fake thread or plaintext pivot to freemail | 3h ago Nov 12th, 2025 | Sublime Security | /feeds/core/detection-rules/becfraud-job-scam-fake-thread-or-plaintext-pivot-to-freemail-ce21c151 | |
VIP impersonation with charitable donation fraud | 3h ago Nov 12th, 2025 | Sublime Security | /feeds/core/detection-rules/vip-impersonation-with-charitable-donation-fraud-35a56b8e | |
Service Abuse: ExactTarget with suspicious sender indicators | 4d ago Nov 8th, 2025 | Sublime Security | /feeds/core/detection-rules/service-abuse-exacttarget-with-suspicious-sender-indicators-6154f197 | |
Brand impersonation: SendGrid | 5d ago Nov 7th, 2025 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-sendgrid-d800124f | |
Headers: Outlook Express mailer | 6d ago Nov 6th, 2025 | Sublime Security | /feeds/core/detection-rules/headers-outlook-express-mailer-b7a698de | |
Vendor impersonation: Thread hijacking with typosquat domain | 8d ago Nov 4th, 2025 | Sublime Security | /feeds/core/detection-rules/vendor-impersonation-thread-hijacking-with-typosquat-domain-9c2f38ed | |
Credential phishing: Generic document sharing | 9d ago Nov 3rd, 2025 | Sublime Security | /feeds/core/detection-rules/credential-phishing-generic-document-sharing-9f0e1d2c | |
Spam/fraud: Predatory journal/research paper request | 9d ago Nov 3rd, 2025 | Sublime Security | /feeds/core/detection-rules/spamfraud-predatory-journalresearch-paper-request-263ca56b | |
Job scam (unsolicited sender) | 9d ago Nov 3rd, 2025 | Sublime Security | /feeds/core/detection-rules/job-scam-unsolicited-sender-a37dc32d | |
Advance Fee Fraud (AFF) from freemail provider or suspicious TLD | 9d ago Nov 3rd, 2025 | Sublime Security | /feeds/core/detection-rules/advance-fee-fraud-aff-from-freemail-provider-or-suspicious-tld-6a5af373 | |
Link: File sharing impersonation with suspicious language and sending patterns | 12d ago Oct 31st, 2025 | Sublime Security | /feeds/core/detection-rules/link-file-sharing-impersonation-with-suspicious-language-and-sending-patterns-d3363041 | |
Service abuse: SendThisFile with credential theft and financial language | 16d ago Oct 27th, 2025 | Sublime Security | /feeds/core/detection-rules/service-abuse-sendthisfile-with-credential-theft-and-financial-language-c1ebf25b | |
Brand impersonation: Internal Revenue Service | 26d ago Oct 17th, 2025 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-internal-revenue-service-3c63f8e9 | |
HTML: Bidirectional (BIDI) HTML override with right to left obfuscation | 26d ago Oct 17th, 2025 | Sublime Security | /feeds/core/detection-rules/html-bidirectional-bidi-html-override-with-right-to-left-obfuscation-f93940d2 | |
Link: Apple App Store malicious ad manager themed apps from free email provider | 26d ago Oct 17th, 2025 | Sublime Security | /feeds/core/detection-rules/link-apple-app-store-malicious-ad-manager-themed-apps-from-free-email-provider-9ce402c6 | |
Service abuse: Google classroom solicitation | 26d ago Oct 17th, 2025 | Sublime Security | /feeds/core/detection-rules/service-abuse-google-classroom-solicitation-e9c39e92 | |
Impersonation: Social Security Administration (SSA) | 29d ago Oct 14th, 2025 | Sublime Security | /feeds/core/detection-rules/impersonation-social-security-administration-ssa-6196767e | |
Business Email Compromise: Request For Mobile Number Via Reply Thread Hijacking | 1mo ago Oct 10th, 2025 | Sublime Security | /feeds/core/detection-rules/business-email-compromise-request-for-mobile-number-via-reply-thread-hijacking-0282f346 | |
Brand impersonation: Aquent | 1mo ago Oct 9th, 2025 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-aquent-5074459c |