Detection Method: Sender analysis

Sender analysis helps you assess whether an email is coming from a legitimate sender. By combining machine learning and rules-based logic, this method evaluates sender profiles, looking at things like authentication results, past behavior, and patterns from previous messages.
Sender analysis can help you detect:
  • Impersonation attempts using fake email addresses or domains
  • Suspicious senders with authentication issues (e.g., SPF, DKIM, DMARC failures)
  • Unusual behavior based on historical patterns, like frequent urgent requests
  • Senders linked to known phishing or malware campaigns
  • Changes in sender behavior that could indicate a compromised account
For example, an attacker might try to impersonate a trusted vendor or executive. The email address or domain might look real, but sender analysis can catch issues like failed authentication checks or past suspicious activity, helping you spot these threats before they do damage.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Observed IOC: Malicious sender email addresses
3d ago
Jun 19th, 2026
Sublime Security
Observed IOC: Malicious sender domains
3d ago
Jun 19th, 2026
Sublime Security
Service abuse: DocSend share from an unsolicited reply-to address
4d ago
Jun 18th, 2026
Sublime Security
Body: Fake secure email portal with HTML obfuscation
4d ago
Jun 18th, 2026
Sublime Security
Employee impersonation: Payroll fraud
4d ago
Jun 18th, 2026
Sublime Security
Brand impersonation: Cloud services with credential theft intent
4d ago
Jun 18th, 2026
Sublime Security
Service abuse: Google Firebase sender address with suspicious content
4d ago
Jun 18th, 2026
Sublime Security
Credential phishing: Fake storage alerts (unsolicited)
4d ago
Jun 18th, 2026
Sublime Security
Brand impersonation: Bids & Tenders
5d ago
Jun 17th, 2026
Sublime Security
Service abuse: Outlook Groups with Google Sites link and evasion tag
5d ago
Jun 17th, 2026
Sublime Security
Brand impersonation: Microsoft
5d ago
Jun 17th, 2026
@amitchell516
Evasion: Hidden content divs from freemail sender
5d ago
Jun 17th, 2026
Sublime Security
Brand impersonation: Quickbooks
5d ago
Jun 17th, 2026
Sublime Security
Attachment: Encrypted PDF with credential theft body
5d ago
Jun 17th, 2026
Sublime Security
Brand impersonation: Fake Fax
5d ago
Jun 17th, 2026
Sublime Security
Fake thread with suspicious indicators
5d ago
Jun 17th, 2026
Sublime Security
Reconnaissance: Short generic greeting message
5d ago
Jun 17th, 2026
Sublime Security
Brand impersonation: Survey request with credential theft indicators
5d ago
Jun 17th, 2026
Sublime Security
Self-impersonation: Sender matches recipient with bolded name and suspicious link
6d ago
Jun 16th, 2026
Sublime Security
Fake Zoom meeting invite with suspicious link
6d ago
Jun 16th, 2026
Sublime Security