Rule Name & Severity | Last Updated | Author | Types, Tactics & Capabilities | |
|---|---|---|---|---|
Service abuse: Formester with suspicious link behavior | 14d ago Dec 19th, 2025 | Sublime Security | /feeds/core/detection-rules/service-abuse-formester-with-suspicious-link-behavior-e4b74fd4 | |
Brand impersonation: Google Drive fake file share | 14d ago Dec 19th, 2025 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-google-drive-fake-file-share-b424a941 | |
Credential phishing content and link (untrusted sender) | 16d ago Dec 17th, 2025 | Sublime Security | /feeds/core/detection-rules/credential-phishing-content-and-link-untrusted-sender-f0c95bb7 | |
Attachment: Adobe image lure in body or attachment with suspicious link | 21d ago Dec 12th, 2025 | Sublime Security | /feeds/core/detection-rules/attachment-adobe-image-lure-in-body-or-attachment-with-suspicious-link-1d7add81 | |
QR Code with suspicious indicators | 21d ago Dec 12th, 2025 | Sublime Security | /feeds/core/detection-rules/qr-code-with-suspicious-indicators-04f5c34f | |
Brand impersonation: Sharepoint fake file share | 23d ago Dec 10th, 2025 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-sharepoint-fake-file-share-ff8b296b | |
Brand impersonation: Microsoft with low reputation links | 23d ago Dec 10th, 2025 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-microsoft-with-low-reputation-links-b59201b6 | |
Link: HR impersonation with suspicious domain indicators and credential theft | 30d ago Dec 3rd, 2025 | Sublime Security | /feeds/core/detection-rules/link-hr-impersonation-with-suspicious-domain-indicators-and-credential-theft-f31f8831 | |
Link: QR code in EML attachment with credential phishing indicators | 1mo ago Dec 2nd, 2025 | Sublime Security | /feeds/core/detection-rules/link-qr-code-in-eml-attachment-with-credential-phishing-indicators-9908ed3a | |
Suspicious invoice reference with missing or image-only attachments | 1mo ago Dec 2nd, 2025 | Sublime Security | /feeds/core/detection-rules/suspicious-invoice-reference-with-missing-or-image-only-attachments-466c1680 | |
Compensation review with QR code in attached EML | 1mo ago Nov 26th, 2025 | Sublime Security | /feeds/core/detection-rules/compensation-review-with-qr-code-in-attached-eml-98a2f03c | |
Brand impersonation: Sharepoint | 1mo ago Nov 24th, 2025 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-sharepoint-284b1b70 | |
Brand impersonation: Adobe with suspicious language and link | 1mo ago Nov 24th, 2025 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-adobe-with-suspicious-language-and-link-32cc8bf1 | |
Credential phishing: DocuSign embedded image lure with no DocuSign domains in links | 1mo ago Nov 18th, 2025 | Sublime Security | /feeds/core/detection-rules/credential-phishing-docusign-embedded-image-lure-with-no-docusign-domains-in-links-dfe8715e | |
Brand impersonation: Capital One | 1mo ago Nov 17th, 2025 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-capital-one-d53848e4 | |
Brand impersonation: Quickbooks | 1mo ago Nov 14th, 2025 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-quickbooks-4fd791d1 | |
Brand impersonation: Fake Fax | 1mo ago Nov 13th, 2025 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-fake-fax-2a96b90a | |
Brand impersonation: SharePoint PDF attachment with credential theft language | 1mo ago Nov 7th, 2025 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-sharepoint-pdf-attachment-with-credential-theft-language-ae3756fa | |
Brand impersonation: USPS | 1mo ago Nov 5th, 2025 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-usps-28b9130a | |
Spam: Mastercard promotional content with image-based body | 1mo ago Nov 5th, 2025 | Sublime Security | /feeds/core/detection-rules/spam-mastercard-promotional-content-with-image-based-body-5f2cb559 |