Detection Method: URL analysis

URL analysis scans links in emails, attachments, or embedded content to find malicious destinations aimed at stealing your credentials, delivering malware, or launching other types of attacks. This method looks at key factors like the structure of the URL, redirection paths, domain reputation, and what the link shows when clicked.
URL analysis can help you detect:
  • Phishing sites pretending to be trusted login pages
  • Malicious domains hidden through URL shorteners or redirects
  • Login forms on suspicious or newly registered domains
  • Brand impersonation using slight domain tweaks (typosquatting or homograph attacks)
  • Suspicious URLs with weird characters or unusual patterns
For example, attackers often use redirect chains to hide their final destination from security scanners. With URL analysis, we can follow these redirects to reveal the true destination and assess the potential threat.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Suspicious message with unscannable Cloudflare link
2h ago
Aug 12th, 2026
Sublime Security
URL with Unicode U+2044 (⁄) or U+2215 (∕) characters
23h ago
Aug 11th, 2026
@delivr_to
Brand impersonation: Social Security Administration
1d ago
Aug 11th, 2026
Sublime Security
New link domain (<=10d) from untrusted sender
2d ago
Aug 10th, 2026
Sublime Security
Link: URL shortener chaining to workers.dev redirect
2d ago
Aug 10th, 2026
Sublime Security
Brand impersonation: Google Meet with malicious link
5d ago
Aug 7th, 2026
Sublime Security
Link: URL using underscore-dot substitution in display text
5d ago
Aug 7th, 2026
Sublime Security
Credential phishing: Generic document sharing
5d ago
Aug 7th, 2026
Sublime Security
Link: Numeric IP obfuscation in URL
6d ago
Aug 6th, 2026
Sublime Security
Brand impersonation: SoFi
6d ago
Aug 6th, 2026
Sublime Security
Credential phishing content and link (untrusted sender)
6d ago
Aug 6th, 2026
Sublime Security
Spam: Fake photo share
6d ago
Aug 6th, 2026
Sublime Security
Brand impersonation: Cloud services with credential theft intent
6d ago
Aug 6th, 2026
Sublime Security
Service abuse: Evernote link
7d ago
Aug 5th, 2026
Sublime Security
Link: Mismatched free file host links with document lure
7d ago
Aug 5th, 2026
Sublime Security
Link: Suspicious recipient with timeout redirect
8d ago
Aug 4th, 2026
Sublime Security
Service abuse: Cognito Forms with short body from unknown sender
8d ago
Aug 4th, 2026
Sublime Security
Link: Unformatted template with literal placeholder in mailto link
9d ago
Aug 3rd, 2026
Sublime Security
Brand impersonation: Robinhood
9d ago
Aug 3rd, 2026
Sublime Security
Credential phishing: Suspicious e-sign agreement document notification
9d ago
Aug 3rd, 2026
Sublime Security