Rule Name & Severity | Last Updated | Author | Types, Tactics & Capabilities | |
|---|---|---|---|---|
VIP Impersonation via Google Group relay with suspicious indicators | 2h ago Nov 12th, 2025 | Sublime Security | /feeds/core/detection-rules/vip-impersonation-via-google-group-relay-with-suspicious-indicators-57f9cd3b | |
Brand impersonation: Survey request with credential theft indicators | 4d ago Nov 8th, 2025 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-survey-request-with-credential-theft-indicators-ea1c0e09 | |
Headers: Outlook Express mailer | 6d ago Nov 6th, 2025 | Sublime Security | /feeds/core/detection-rules/headers-outlook-express-mailer-b7a698de | |
Service Abuse: Nifty.com with impersonation | 7d ago Nov 5th, 2025 | Sublime Security | /feeds/core/detection-rules/service-abuse-niftycom-with-impersonation-370cfdac | |
Vendor impersonation: Thread hijacking with typosquat domain | 8d ago Nov 4th, 2025 | Sublime Security | /feeds/core/detection-rules/vendor-impersonation-thread-hijacking-with-typosquat-domain-9c2f38ed | |
Extortion / sextortion (untrusted sender) | 12d ago Oct 31st, 2025 | Sublime Security | /feeds/core/detection-rules/extortion-sextortion-untrusted-sender-265913eb | |
Attachment: ICS calendar with embedded file from internal sender with SPF failure | 21d ago Oct 22nd, 2025 | Sublime Security | /feeds/core/detection-rules/attachment-ics-calendar-with-embedded-file-from-internal-sender-with-spf-failure-d9ce9db8 | |
Headers: System account impersonation with empty sender address | 1mo ago Oct 1st, 2025 | Sublime Security | /feeds/core/detection-rules/headers-system-account-impersonation-with-empty-sender-address-887f7953 | |
Brand impersonation: Navan | 1mo ago Sep 22nd, 2025 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-navan-3573e9a8 | |
VIP local_part impersonation from unsolicited sender | 3mo ago Aug 12th, 2025 | Sublime Security | /feeds/core/detection-rules/vip-localpart-impersonation-from-unsolicited-sender-74035fdc | |
Extortion / sextortion in attachment from untrusted sender | 3mo ago Aug 5th, 2025 | Sublime Security | /feeds/core/detection-rules/extortion-sextortion-in-attachment-from-untrusted-sender-3cb8d32c | |
Impersonation: SharePoint reply header anomaly | 3mo ago Aug 5th, 2025 | Sublime Security | /feeds/core/detection-rules/impersonation-sharepoint-reply-header-anomaly-78875848 | |
DocuSign impersonation via spoofed Intuit sender | 3mo ago Aug 5th, 2025 | Sublime Security | /feeds/core/detection-rules/docusign-impersonation-via-spoofed-intuit-sender-d437710b | |
Spoofable internal domain with suspicious signals | 3mo ago Jul 23rd, 2025 | Sublime Security | /feeds/core/detection-rules/spoofable-internal-domain-with-suspicious-signals-40089d69 | |
Cyrillic vowel substitution in subject or display name from unknown sender | 3mo ago Jul 16th, 2025 | Sublime Security | /feeds/core/detection-rules/cyrillic-vowel-substitution-in-subject-or-display-name-from-unknown-sender-74bc0b0c | |
Business Email Compromise (BEC) attempt from unsolicited sender | 3mo ago Jul 16th, 2025 | Sublime Security | /feeds/core/detection-rules/business-email-compromise-bec-attempt-from-unsolicited-sender-57eccc45 | |
Brand impersonation: DocuSign | 5mo ago May 21st, 2025 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-docusign-4d29235c | |
VIP impersonation: Fake thread with display name match, email mismatch | 1y ago Jul 29th, 2024 | Sublime Security | /feeds/core/detection-rules/vip-impersonation-fake-thread-with-display-name-match-email-mismatch-11cc3e28 | |
Brand spoof: Dropbox | 1y ago Apr 23rd, 2024 | Sublime Security | /feeds/core/detection-rules/brand-spoof-dropbox-bd99740a | |
SPF temp error | 2y ago Aug 21st, 2023 | Sublime Security | /feeds/core/detection-rules/spf-temp-error-2df7e839 |