Rule Name & Severity | Last Updated | Author | Types, Tactics & Capabilities | |
|---|---|---|---|---|
Extortion / sextortion (untrusted sender) | 22h ago Jan 22nd, 2026 | Sublime Security | /feeds/core/detection-rules/extortion-sextortion-untrusted-sender-265913eb | |
Vendor impersonation: Thread hijacking with typosquat domain | 11d ago Jan 12th, 2026 | Sublime Security | /feeds/core/detection-rules/vendor-impersonation-thread-hijacking-with-typosquat-domain-9c2f38ed | |
VIP impersonation: Fake thread with display name match, email mismatch | 11d ago Jan 12th, 2026 | Sublime Security | /feeds/core/detection-rules/vip-impersonation-fake-thread-with-display-name-match-email-mismatch-11cc3e28 | |
SPF temp error | 11d ago Jan 12th, 2026 | Sublime Security | /feeds/core/detection-rules/spf-temp-error-2df7e839 | |
Brand impersonation: DocuSign | 11d ago Jan 12th, 2026 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-docusign-4d29235c | |
Impersonation: SharePoint reply header anomaly | 11d ago Jan 12th, 2026 | Sublime Security | /feeds/core/detection-rules/impersonation-sharepoint-reply-header-anomaly-78875848 | |
Headers: System account impersonation with empty sender address | 11d ago Jan 12th, 2026 | Sublime Security | /feeds/core/detection-rules/headers-system-account-impersonation-with-empty-sender-address-887f7953 | |
Service Abuse: Nifty.com with impersonation | 11d ago Jan 12th, 2026 | Sublime Security | /feeds/core/detection-rules/service-abuse-niftycom-with-impersonation-370cfdac | |
Brand impersonation: State Farm | 1mo ago Dec 17th, 2025 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-state-farm-bcf7eba0 | |
Body: Embedded email headers indicative of thread hijacking/abuse | 1mo ago Dec 1st, 2025 | Sublime Security | /feeds/core/detection-rules/body-embedded-email-headers-indicative-of-thread-hijackingabuse-6e8eeebb | |
VIP Impersonation via Google Group relay with suspicious indicators | 2mo ago Nov 12th, 2025 | Sublime Security | /feeds/core/detection-rules/vip-impersonation-via-google-group-relay-with-suspicious-indicators-57f9cd3b | |
Brand impersonation: Survey request with credential theft indicators | 2mo ago Nov 8th, 2025 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-survey-request-with-credential-theft-indicators-ea1c0e09 | |
Headers: Outlook Express mailer | 2mo ago Nov 6th, 2025 | Sublime Security | /feeds/core/detection-rules/headers-outlook-express-mailer-b7a698de | |
Attachment: ICS calendar with embedded file from internal sender with SPF failure | 3mo ago Oct 22nd, 2025 | Sublime Security | /feeds/core/detection-rules/attachment-ics-calendar-with-embedded-file-from-internal-sender-with-spf-failure-d9ce9db8 | |
Brand impersonation: Navan | 4mo ago Sep 22nd, 2025 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-navan-3573e9a8 | |
VIP local_part impersonation from unsolicited sender | 5mo ago Aug 12th, 2025 | Sublime Security | /feeds/core/detection-rules/vip-localpart-impersonation-from-unsolicited-sender-74035fdc | |
DocuSign impersonation via spoofed Intuit sender | 5mo ago Aug 5th, 2025 | Sublime Security | /feeds/core/detection-rules/docusign-impersonation-via-spoofed-intuit-sender-d437710b | |
Extortion / sextortion in attachment from untrusted sender | 5mo ago Aug 5th, 2025 | Sublime Security | /feeds/core/detection-rules/extortion-sextortion-in-attachment-from-untrusted-sender-3cb8d32c | |
Spoofable internal domain with suspicious signals | 6mo ago Jul 23rd, 2025 | Sublime Security | /feeds/core/detection-rules/spoofable-internal-domain-with-suspicious-signals-40089d69 | |
Business Email Compromise (BEC) attempt from unsolicited sender | 6mo ago Jul 16th, 2025 | Sublime Security | /feeds/core/detection-rules/business-email-compromise-bec-attempt-from-unsolicited-sender-57eccc45 |