Detection Method: URL analysis

URL analysis scans links in emails, attachments, or embedded content to find malicious destinations aimed at stealing your credentials, delivering malware, or launching other types of attacks. This method looks at key factors like the structure of the URL, redirection paths, domain reputation, and what the link shows when clicked.
URL analysis can help you detect:
  • Phishing sites pretending to be trusted login pages
  • Malicious domains hidden through URL shorteners or redirects
  • Login forms on suspicious or newly registered domains
  • Brand impersonation using slight domain tweaks (typosquatting or homograph attacks)
  • Suspicious URLs with weird characters or unusual patterns
For example, attackers often use redirect chains to hide their final destination from security scanners. With URL analysis, we can follow these redirects to reveal the true destination and assess the potential threat.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Open redirect: Quickbase
9m ago
Oct 6th, 2026
Sublime Security
Fake voicemail notification (untrusted sender)
1h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage with echo-tail od= tracking token
4h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage with suspicious URL pattern
4h ago
Oct 6th, 2026
Sublime Security
Attachment: PDF Link With Valueless Base64 Query Parameter
4h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage /index and /unsub link pair
4h ago
Oct 6th, 2026
Sublime Security
Brand impersonation: ConstructConnect
5h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage with suffixed unsubscribe bucket
5h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage with zipper-interleaved tracking token
5h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage with prefixed base64 dash-record fragment
5h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage with base64 go/sub-ID fragment
5h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage with case-striped tracking token in fragment
5h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage with short-path link delivery
5h ago
Oct 6th, 2026
Sublime Security
Link: Malformed subdomain ending in hyphen
5h ago
Oct 6th, 2026
Sublime Security
Link: Observed URL path (lht) with recipient email address
5h ago
Oct 6th, 2026
Sublime Security
Service abuse: Lovable-hosted redirect to external phishing page
6h ago
Oct 6th, 2026
Sublime Security
Attachment: Excel file with hyperlinks to suspicious domains
6h ago
Oct 6th, 2026
Sublime Security
Observed IOC: Malicious domains in body links
6h ago
Oct 6th, 2026
Sublime Security
Link: Possible Intuit link abuse
1d ago
Oct 5th, 2026
Sublime Security
Open redirect: Toradex
1d ago
Oct 5th, 2026
Sublime Security