Rule Name & Severity | Last Updated | Author | Types, Tactics & Capabilities | |
|---|---|---|---|---|
Brand impersonation: Microsoft Planner with suspicious link | 6d ago Feb 6th, 2026 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-microsoft-planner-with-suspicious-link-ea363c08 | |
Brand impersonation: Fake Fax | 7d ago Feb 5th, 2026 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-fake-fax-2a96b90a | |
Attachment: QR code with encoded recipient targeting and redirect indicators | 13d ago Jan 30th, 2026 | Sublime Security | /feeds/core/detection-rules/attachment-qr-code-with-encoded-recipient-targeting-and-redirect-indicators-5d51e565 | |
Brand impersonation: USPS | 23d ago Jan 20th, 2026 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-usps-28b9130a | |
Credential phishing: Image as content, short or no body contents | 1mo ago Jan 12th, 2026 | Sublime Security | /feeds/core/detection-rules/credential-phishing-image-as-content-short-or-no-body-contents-01313f38 | |
Attachment: Fake secure message and suspicious indicators | 1mo ago Jan 12th, 2026 | Sublime Security | /feeds/core/detection-rules/attachment-fake-secure-message-and-suspicious-indicators-20a34d94 | |
Attachment: QR code link with base64-encoded recipient address | 1mo ago Jan 12th, 2026 | Sublime Security | /feeds/core/detection-rules/attachment-qr-code-link-with-base64-encoded-recipient-address-927a0c1a | |
Image as content with a link to an open redirect (unsolicited) | 1mo ago Jan 12th, 2026 | Sublime Security | /feeds/core/detection-rules/image-as-content-with-a-link-to-an-open-redirect-unsolicited-f5cec36b | |
Brand impersonation: Microsoft with low reputation links | 1mo ago Jan 12th, 2026 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-microsoft-with-low-reputation-links-b59201b6 | |
Attachment: QR code with userinfo portion | 1mo ago Jan 12th, 2026 | Sublime Security | /feeds/core/detection-rules/attachment-qr-code-with-userinfo-portion-9d62cc5c | |
Attachment: Callback phishing solicitation via image file | 1mo ago Jan 12th, 2026 | @vector_sec | /feeds/core/detection-rules/attachment-callback-phishing-solicitation-via-image-file-60acbb36 | |
Attachment: Adobe image lure in body or attachment with suspicious link | 1mo ago Jan 5th, 2026 | Sublime Security | /feeds/core/detection-rules/attachment-adobe-image-lure-in-body-or-attachment-with-suspicious-link-1d7add81 | |
Credential theft: Gophish abuse with hidden tracking image | 3mo ago Nov 5th, 2025 | Sublime Security | /feeds/core/detection-rules/credential-theft-gophish-abuse-with-hidden-tracking-image-59915ceb | |
Spam: Mastercard promotional content with image-based body | 3mo ago Nov 5th, 2025 | Sublime Security | /feeds/core/detection-rules/spam-mastercard-promotional-content-with-image-based-body-5f2cb559 | |
Brand impersonation: DocuSign with embedded QR code | 3mo ago Oct 17th, 2025 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-docusign-with-embedded-qr-code-f5cde463 | |
Attachment: Fake scan-to-email | 4mo ago Sep 22nd, 2025 | Sublime Security | /feeds/core/detection-rules/attachment-fake-scan-to-email-ea850cc1 | |
Brand impersonation: Coinbase with suspicious links | 4mo ago Sep 22nd, 2025 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-coinbase-with-suspicious-links-b61e2f8e | |
Cloud storage impersonation with credential theft indicators | 4mo ago Sep 22nd, 2025 | Sublime Security | /feeds/core/detection-rules/cloud-storage-impersonation-with-credential-theft-indicators-4c20f72c | |
Attachment: Fake attachment image lure | 4mo ago Sep 22nd, 2025 | Sublime Security | /feeds/core/detection-rules/attachment-fake-attachment-image-lure-96b8b285 | |
Attachment: SVG files with evasion elements | 6mo ago Aug 8th, 2025 | Sublime Security | /feeds/core/detection-rules/attachment-svg-files-with-evasion-elements-5d2dbb60 |