Rule Name & Severity | Last Updated | Author | Types, Tactics & Capabilities | |
|---|---|---|---|---|
Impersonation: Internal corporate services | 3d ago Jan 20th, 2026 | Sublime Security | /feeds/core/detection-rules/impersonation-internal-corporate-services-3cd04f33 | |
BEC: Employee impersonation with subject manipulation | 7d ago Jan 16th, 2026 | Sublime Security | /feeds/core/detection-rules/bec-employee-impersonation-with-subject-manipulation-9adfc77b | |
Sharepoint link likely unrelated to sender | 11d ago Jan 12th, 2026 | Sublime Security | /feeds/core/detection-rules/sharepoint-link-likely-unrelated-to-sender-6870f489 | |
Suspicious attachment with unscannable Cloudflare link | 11d ago Jan 12th, 2026 | Sublime Security | /feeds/core/detection-rules/suspicious-attachment-with-unscannable-cloudflare-link-00f92b6f | |
Attachment with VBA macros from employee impersonation (unsolicited) | 11d ago Jan 12th, 2026 | Sublime Security | /feeds/core/detection-rules/attachment-with-vba-macros-from-employee-impersonation-unsolicited-9b262123 | |
Benefits enrollment impersonation | 11d ago Jan 12th, 2026 | Sublime Security | /feeds/core/detection-rules/benefits-enrollment-impersonation-5a6eb5a8 | |
Employee impersonation with urgent request (untrusted sender) | 11d ago Jan 12th, 2026 | Sublime Security | /feeds/core/detection-rules/employee-impersonation-with-urgent-request-untrusted-sender-1ce9a146 | |
Service Abuse: Box file sharing with credential phishing intent | 11d ago Jan 12th, 2026 | Sublime Security | /feeds/core/detection-rules/service-abuse-box-file-sharing-with-credential-phishing-intent-5bd0cb25 | |
Headers: System account impersonation with empty sender address | 11d ago Jan 12th, 2026 | Sublime Security | /feeds/core/detection-rules/headers-system-account-impersonation-with-empty-sender-address-887f7953 | |
Xero invoice abuse | 1mo ago Dec 17th, 2025 | Sublime Security | /feeds/core/detection-rules/xero-invoice-abuse-6538c600 | |
Credential phishing: Generic document sharing | 1mo ago Dec 8th, 2025 | Sublime Security | /feeds/core/detection-rules/credential-phishing-generic-document-sharing-9f0e1d2c | |
Suspicious request for financial information | 1mo ago Dec 6th, 2025 | Sublime Security | /feeds/core/detection-rules/suspicious-request-for-financial-information-4ebdaa4d | |
Link: HR impersonation with suspicious domain indicators and credential theft | 1mo ago Dec 3rd, 2025 | Sublime Security | /feeds/core/detection-rules/link-hr-impersonation-with-suspicious-domain-indicators-and-credential-theft-f31f8831 | |
VIP impersonation with charitable donation fraud | 2mo ago Nov 12th, 2025 | Sublime Security | /feeds/core/detection-rules/vip-impersonation-with-charitable-donation-fraud-35a56b8e | |
VIP Impersonation via Google Group relay with suspicious indicators | 2mo ago Nov 12th, 2025 | Sublime Security | /feeds/core/detection-rules/vip-impersonation-via-google-group-relay-with-suspicious-indicators-57f9cd3b | |
Link: SharePoint filename matches org name | 3mo ago Sep 26th, 2025 | Sublime Security | /feeds/core/detection-rules/link-sharepoint-filename-matches-org-name-cb954726 | |
Canva infrastructure abuse | 4mo ago Sep 5th, 2025 | Sublime Security | /feeds/core/detection-rules/canva-infrastructure-abuse-b69fdb5c | |
Employee impersonation: Payroll fraud | 5mo ago Aug 5th, 2025 | Sublime Security | /feeds/core/detection-rules/employee-impersonation-payroll-fraud-2beb7d85 | |
Impersonation: Human Resources with link or attachment and engaging language | 6mo ago Jul 16th, 2025 | Sublime Security | /feeds/core/detection-rules/impersonation-human-resources-with-link-or-attachment-and-engaging-language-8c95a6a8 |