Tactic or Technique: Spoofing

Spoofing is when attackers falsify sender information to make a message look like it came from someone you trust by forging a real email address.
Messages like this often impersonate executives, IT support, or vendors and can lead to stolen credentials, wire fraud, or malware infections. When the source looks trustworthy, you're more likely to follow instructions, click a link, or open a file without hesitation.
Spoofing is especially effective when email authentication protocols like SPF, DKIM, and DMARC aren’t properly enforced. Without those protections, it becomes much easier for attackers to get past both technical filters and human judgment.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
VIP Impersonation via Google Group relay with suspicious indicators
2h ago
Nov 12th, 2025
Sublime Security
/feeds/core/detection-rules/vip-impersonation-via-google-group-relay-with-suspicious-indicators-57f9cd3b
Brand impersonation: Survey request with credential theft indicators
4d ago
Nov 8th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-survey-request-with-credential-theft-indicators-ea1c0e09
Headers: Outlook Express mailer
6d ago
Nov 6th, 2025
Sublime Security
/feeds/core/detection-rules/headers-outlook-express-mailer-b7a698de
Service Abuse: Nifty.com with impersonation
7d ago
Nov 5th, 2025
Sublime Security
/feeds/core/detection-rules/service-abuse-niftycom-with-impersonation-370cfdac
Vendor impersonation: Thread hijacking with typosquat domain
8d ago
Nov 4th, 2025
Sublime Security
/feeds/core/detection-rules/vendor-impersonation-thread-hijacking-with-typosquat-domain-9c2f38ed
Extortion / sextortion (untrusted sender)
12d ago
Oct 31st, 2025
Sublime Security
/feeds/core/detection-rules/extortion-sextortion-untrusted-sender-265913eb
Attachment: ICS calendar with embedded file from internal sender with SPF failure
21d ago
Oct 22nd, 2025
Sublime Security
/feeds/core/detection-rules/attachment-ics-calendar-with-embedded-file-from-internal-sender-with-spf-failure-d9ce9db8
Headers: System account impersonation with empty sender address
1mo ago
Oct 1st, 2025
Sublime Security
/feeds/core/detection-rules/headers-system-account-impersonation-with-empty-sender-address-887f7953
Brand impersonation: Navan
1mo ago
Sep 22nd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-navan-3573e9a8
VIP local_part impersonation from unsolicited sender
3mo ago
Aug 12th, 2025
Sublime Security
/feeds/core/detection-rules/vip-localpart-impersonation-from-unsolicited-sender-74035fdc
Extortion / sextortion in attachment from untrusted sender
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/extortion-sextortion-in-attachment-from-untrusted-sender-3cb8d32c
Impersonation: SharePoint reply header anomaly
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/impersonation-sharepoint-reply-header-anomaly-78875848
DocuSign impersonation via spoofed Intuit sender
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/docusign-impersonation-via-spoofed-intuit-sender-d437710b
Spoofable internal domain with suspicious signals
3mo ago
Jul 23rd, 2025
Sublime Security
/feeds/core/detection-rules/spoofable-internal-domain-with-suspicious-signals-40089d69
Cyrillic vowel substitution in subject or display name from unknown sender
3mo ago
Jul 16th, 2025
Sublime Security
/feeds/core/detection-rules/cyrillic-vowel-substitution-in-subject-or-display-name-from-unknown-sender-74bc0b0c
Business Email Compromise (BEC) attempt from unsolicited sender
3mo ago
Jul 16th, 2025
Sublime Security
/feeds/core/detection-rules/business-email-compromise-bec-attempt-from-unsolicited-sender-57eccc45
Brand impersonation: DocuSign
5mo ago
May 21st, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-docusign-4d29235c
VIP impersonation: Fake thread with display name match, email mismatch
1y ago
Jul 29th, 2024
Sublime Security
/feeds/core/detection-rules/vip-impersonation-fake-thread-with-display-name-match-email-mismatch-11cc3e28
Brand spoof: Dropbox
1y ago
Apr 23rd, 2024
Sublime Security
/feeds/core/detection-rules/brand-spoof-dropbox-bd99740a
SPF temp error
2y ago
Aug 21st, 2023
Sublime Security
/feeds/core/detection-rules/spf-temp-error-2df7e839