Detection Method: URL analysis

URL analysis scans links in emails, attachments, or embedded content to find malicious destinations aimed at stealing your credentials, delivering malware, or launching other types of attacks. This method looks at key factors like the structure of the URL, redirection paths, domain reputation, and what the link shows when clicked.
URL analysis can help you detect:
  • Phishing sites pretending to be trusted login pages
  • Malicious domains hidden through URL shorteners or redirects
  • Login forms on suspicious or newly registered domains
  • Brand impersonation using slight domain tweaks (typosquatting or homograph attacks)
  • Suspicious URLs with weird characters or unusual patterns
For example, attackers often use redirect chains to hide their final destination from security scanners. With URL analysis, we can follow these redirects to reveal the true destination and assess the potential threat.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Brand impersonation: Robinhood
19m ago
Aug 27th, 2026
Sublime Security
Attachment: ICS invite meeting lure
1h ago
Aug 27th, 2026
Sublime Security
Link: Microsoft protected message with suspicious recipient patterns
2h ago
Aug 27th, 2026
Sublime Security
Brand impersonation: Microsoft with low reputation links
4h ago
Aug 27th, 2026
Sublime Security
Body: CSS clamp() font obfuscation with suspicious URL
20h ago
Aug 26th, 2026
Sublime Security
Attachment: PDF Grant Payment lure with embedded link
21h ago
Aug 26th, 2026
Sublime Security
BEC/Fraud: Self-addressed reply with unrelated link in ongoing thread
1d ago
Aug 26th, 2026
Sublime Security
ClickFix: Clipboard hijack lure with copy-paste-to-terminal instruction
1d ago
Aug 26th, 2026
Sublime Security
Link: Self-sender with sender org in subject and credential theft indicator
2d ago
Aug 25th, 2026
Sublime Security
Link: Fake RFP/bid reference number lure
2d ago
Aug 25th, 2026
Sublime Security
Attachment: ICS calendar invite with bid/RFP lure and suspicious link
2d ago
Aug 25th, 2026
Sublime Security
Brand impersonation: United States Patent and Trademark Office
2d ago
Aug 25th, 2026
Sublime Security
Link: Google Cloud Storage link with redirect.html in URL
3d ago
Aug 24th, 2026
Sublime Security
Link: Double base64-encoded URL path
3d ago
Aug 24th, 2026
Sublime Security
Attachment: PDF proposal with credential theft indicators
3d ago
Aug 24th, 2026
Sublime Security
Attachment: ICS calendar invite with financial lure and suspicious link
5d ago
Aug 22nd, 2026
Sublime Security
Brand impersonation: Microsoft logo image linking to free file host
6d ago
Aug 21st, 2026
Sublime Security
Evasion: Suspicious TLD link redirecting to Wikipedia
6d ago
Aug 21st, 2026
Sublime Security
Link: Credential phishing with obfuscated JavaScript redirect
6d ago
Aug 21st, 2026
Sublime Security
Link: RTL text reversal with recipient email in URL
7d ago
Aug 20th, 2026
Sublime Security