Detection Method: URL analysis

URL analysis scans links in emails, attachments, or embedded content to find malicious destinations aimed at stealing your credentials, delivering malware, or launching other types of attacks. This method looks at key factors like the structure of the URL, redirection paths, domain reputation, and what the link shows when clicked.
URL analysis can help you detect:
  • Phishing sites pretending to be trusted login pages
  • Malicious domains hidden through URL shorteners or redirects
  • Login forms on suspicious or newly registered domains
  • Brand impersonation using slight domain tweaks (typosquatting or homograph attacks)
  • Suspicious URLs with weird characters or unusual patterns
For example, attackers often use redirect chains to hide their final destination from security scanners. With URL analysis, we can follow these redirects to reveal the true destination and assess the potential threat.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Service abuse: Behance document sharing with suspicious language
3d ago
Mar 27th, 2026
Sublime Security
Attachment: PDF bid/proposal lure with credential theft indicators
3d ago
Mar 27th, 2026
Sublime Security
Brand impersonation: Robinhood
4d ago
Mar 26th, 2026
Sublime Security
Link: Non-standard port 8443 in display URL
4d ago
Mar 26th, 2026
Sublime Security
Credential phishing: Fake card notification with tracking lure
6d ago
Mar 24th, 2026
Sublime Security
Link: Financial account issue with suspicious indicators
6d ago
Mar 24th, 2026
Sublime Security
Cloud storage impersonation with credential theft indicators
7d ago
Mar 23rd, 2026
Sublime Security
Spam: Fake dating profile notification
10d ago
Mar 20th, 2026
Sublime Security
Link: Free file hosting with undisclosed recipients
11d ago
Mar 19th, 2026
Sublime Security
Service abuse: Substack credential theft with confusable characters and branded button redirects
11d ago
Mar 19th, 2026
Sublime Security
Attachment: PDF with a suspicious string and single URL
13d ago
Mar 17th, 2026
Sublime Security
Link: IPv4-mapped IPv6 address obfuscation
13d ago
Mar 17th, 2026
Sublime Security
Attachment: PDF proposal with credential theft indicators
13d ago
Mar 17th, 2026
Sublime Security
Link: Obfuscation via userinfo with suspicious indicators
17d ago
Mar 13th, 2026
Sublime Security
Link: Microsoft device code authentication with suspicious indicators
18d ago
Mar 12th, 2026
Sublime Security
Service abuse: Google Firebase sender address with suspicious content
18d ago
Mar 12th, 2026
Sublime Security
Service abuse: Google OAuth with suspicious redirect destination
18d ago
Mar 12th, 2026
Sublime Security
Link: Unsolicited email contains link to page containing Tycoon URI structure
20d ago
Mar 10th, 2026
Sublime Security
Link: Commonly Abused Web Service redirecting to ZIP file
20d ago
Mar 10th, 2026
Sublime Security
Link: Unsolicited email contains link leading to Tycoon URL structure
20d ago
Mar 10th, 2026
Sublime Security