Detection Method: Sender analysis

Sender analysis helps you assess whether an email is coming from a legitimate sender. By combining machine learning and rules-based logic, this method evaluates sender profiles, looking at things like authentication results, past behavior, and patterns from previous messages.
Sender analysis can help you detect:
  • Impersonation attempts using fake email addresses or domains
  • Suspicious senders with authentication issues (e.g., SPF, DKIM, DMARC failures)
  • Unusual behavior based on historical patterns, like frequent urgent requests
  • Senders linked to known phishing or malware campaigns
  • Changes in sender behavior that could indicate a compromised account
For example, an attacker might try to impersonate a trusted vendor or executive. The email address or domain might look real, but sender analysis can catch issues like failed authentication checks or past suspicious activity, helping you spot these threats before they do damage.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Observed IOC: Malicious sender email addresses
1d ago
May 29th, 2026
Sublime Security
Reconnaissance: Short generic greeting message
1d ago
May 29th, 2026
Sublime Security
Credential phishing: Engaging language and other indicators (untrusted sender)
1d ago
May 29th, 2026
Sublime Security
Spam: Website errors solicitation
1d ago
May 29th, 2026
Sublime Security
Brand impersonation: Meta and subsidiaries
1d ago
May 29th, 2026
Sublime Security
Impersonation Link: Cloud branding service with credential theft language
1d ago
May 29th, 2026
Sublime Security
Credential phishing: Suspicious e-sign agreement document notification
1d ago
May 29th, 2026
Sublime Security
Service Abuse: HelloSign share with suspicious sender or document name
2d ago
May 28th, 2026
Sublime Security
Impersonation: Employee using fabricated identity in initial contact
2d ago
May 28th, 2026
Sublime Security
Business Email Compromise: Request for mobile number via reply thread hijacking
2d ago
May 28th, 2026
Sublime Security
Credential phishing: Fake storage alerts (unsolicited)
2d ago
May 28th, 2026
Sublime Security
Brand impersonation: Figma with malicious document access overlay
3d ago
May 27th, 2026
Sublime Security
Observed IOC: Malicious sender domains
3d ago
May 27th, 2026
Sublime Security
Service abuse: Square marketing with suspicious QR code
4d ago
May 26th, 2026
Sublime Security
Brand impersonation: DHL
4d ago
May 26th, 2026
Sublime Security
Brand Impersonation: Procore
4d ago
May 26th, 2026
Sublime Security
Brand impersonation: Dashlane
4d ago
May 26th, 2026
Sublime Security
Business Email Compromise (BEC) with request for mobile number
4d ago
May 26th, 2026
Sublime Security
Service abuse: Amazon invitation with suspected callback phishing
8d ago
May 22nd, 2026
Sublime Security
Credential phishing: Generic document sharing
8d ago
May 22nd, 2026
Sublime Security