Tactic or Technique: Spoofing

Spoofing is when attackers falsify sender information to make a message look like it came from someone you trust by forging a real email address.
Messages like this often impersonate executives, IT support, or vendors and can lead to stolen credentials, wire fraud, or malware infections. When the source looks trustworthy, you're more likely to follow instructions, click a link, or open a file without hesitation.
Spoofing is especially effective when email authentication protocols like SPF, DKIM, and DMARC aren’t properly enforced. Without those protections, it becomes much easier for attackers to get past both technical filters and human judgment.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Service Abuse: Nifty.com with impersonation
14d ago
Dec 19th, 2025
Sublime Security
/feeds/core/detection-rules/service-abuse-niftycom-with-impersonation-370cfdac
Extortion / sextortion (untrusted sender)
14d ago
Dec 19th, 2025
Sublime Security
/feeds/core/detection-rules/extortion-sextortion-untrusted-sender-265913eb
Brand impersonation: State Farm
16d ago
Dec 17th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-state-farm-bcf7eba0
Brand impersonation: DocuSign
23d ago
Dec 10th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-docusign-4d29235c
Body: Embedded email headers indicative of thread hijacking/abuse
1mo ago
Dec 1st, 2025
Sublime Security
/feeds/core/detection-rules/body-embedded-email-headers-indicative-of-thread-hijackingabuse-6e8eeebb
VIP Impersonation via Google Group relay with suspicious indicators
1mo ago
Nov 12th, 2025
Sublime Security
/feeds/core/detection-rules/vip-impersonation-via-google-group-relay-with-suspicious-indicators-57f9cd3b
Brand impersonation: Survey request with credential theft indicators
1mo ago
Nov 8th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-survey-request-with-credential-theft-indicators-ea1c0e09
Headers: Outlook Express mailer
1mo ago
Nov 6th, 2025
Sublime Security
/feeds/core/detection-rules/headers-outlook-express-mailer-b7a698de
Vendor impersonation: Thread hijacking with typosquat domain
1mo ago
Nov 4th, 2025
Sublime Security
/feeds/core/detection-rules/vendor-impersonation-thread-hijacking-with-typosquat-domain-9c2f38ed
Attachment: ICS calendar with embedded file from internal sender with SPF failure
2mo ago
Oct 22nd, 2025
Sublime Security
/feeds/core/detection-rules/attachment-ics-calendar-with-embedded-file-from-internal-sender-with-spf-failure-d9ce9db8
Headers: System account impersonation with empty sender address
3mo ago
Oct 1st, 2025
Sublime Security
/feeds/core/detection-rules/headers-system-account-impersonation-with-empty-sender-address-887f7953
Brand impersonation: Navan
3mo ago
Sep 22nd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-navan-3573e9a8
VIP local_part impersonation from unsolicited sender
4mo ago
Aug 12th, 2025
Sublime Security
/feeds/core/detection-rules/vip-localpart-impersonation-from-unsolicited-sender-74035fdc
DocuSign impersonation via spoofed Intuit sender
5mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/docusign-impersonation-via-spoofed-intuit-sender-d437710b
Extortion / sextortion in attachment from untrusted sender
5mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/extortion-sextortion-in-attachment-from-untrusted-sender-3cb8d32c
Impersonation: SharePoint reply header anomaly
5mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/impersonation-sharepoint-reply-header-anomaly-78875848
Spoofable internal domain with suspicious signals
5mo ago
Jul 23rd, 2025
Sublime Security
/feeds/core/detection-rules/spoofable-internal-domain-with-suspicious-signals-40089d69
Business Email Compromise (BEC) attempt from unsolicited sender
5mo ago
Jul 16th, 2025
Sublime Security
/feeds/core/detection-rules/business-email-compromise-bec-attempt-from-unsolicited-sender-57eccc45
Cyrillic vowel substitution in subject or display name from unknown sender
5mo ago
Jul 16th, 2025
Sublime Security
/feeds/core/detection-rules/cyrillic-vowel-substitution-in-subject-or-display-name-from-unknown-sender-74bc0b0c
VIP impersonation: Fake thread with display name match, email mismatch
2y ago
Jul 29th, 2024
Sublime Security
/feeds/core/detection-rules/vip-impersonation-fake-thread-with-display-name-match-email-mismatch-11cc3e28