Detection Method: URL analysis

URL analysis scans links in emails, attachments, or embedded content to find malicious destinations aimed at stealing your credentials, delivering malware, or launching other types of attacks. This method looks at key factors like the structure of the URL, redirection paths, domain reputation, and what the link shows when clicked.
URL analysis can help you detect:
  • Phishing sites pretending to be trusted login pages
  • Malicious domains hidden through URL shorteners or redirects
  • Login forms on suspicious or newly registered domains
  • Brand impersonation using slight domain tweaks (typosquatting or homograph attacks)
  • Suspicious URLs with weird characters or unusual patterns
For example, attackers often use redirect chains to hide their final destination from security scanners. With URL analysis, we can follow these redirects to reveal the true destination and assess the potential threat.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Cloud storage impersonation with credential theft indicators
20h ago
Mar 13th, 2026
Sublime Security
Link: Obfuscation via userinfo with suspicious indicators
21h ago
Mar 13th, 2026
Sublime Security
Link: Microsoft device code authentication with suspicious indicators
2d ago
Mar 12th, 2026
Sublime Security
Service abuse: Google Firebase sender address with suspicious content
2d ago
Mar 12th, 2026
Sublime Security
Service abuse: Google OAuth with suspicious redirect destination
2d ago
Mar 12th, 2026
Sublime Security
Link: Unsolicited email contains link to page containing Tycoon URI structure
4d ago
Mar 10th, 2026
Sublime Security
Link: Commonly Abused Web Service redirecting to ZIP file
4d ago
Mar 10th, 2026
Sublime Security
Link: Unsolicited email contains link leading to Tycoon URL structure
4d ago
Mar 10th, 2026
Sublime Security
Service abuse: File sharing impersonation with external SharePoint links
5d ago
Mar 9th, 2026
Sublime Security
Link: Mixed case HTTPS protocol
5d ago
Mar 9th, 2026
Sublime Security
Service abuse: Monday.com infrastructure with phishing intent
5d ago
Mar 9th, 2026
Sublime Security
Request for Quote or Purchase (RFQ|RFP) with suspicious sender or recipient pattern
5d ago
Mar 9th, 2026
Sublime Security
Credential phishing: Blue button styled link with file-sharing template artifacts
5d ago
Mar 9th, 2026
Sublime Security
Link: Google Drawings link from new sender
5d ago
Mar 9th, 2026
Sublime Security
Link: Blogspot hosting explicit romance content
5d ago
Mar 9th, 2026
Sublime Security
Service abuse: Vimeo with external plain-text links in message
8d ago
Mar 6th, 2026
Sublime Security
Attachment: PDF with suspicious link and action-oriented language
8d ago
Mar 6th, 2026
Sublime Security
Brand impersonation: Zoom via lookalike domain
8d ago
Mar 6th, 2026
Sublime Security
Service abuse: Nylas tracking subdomain with suspicious content
8d ago
Mar 6th, 2026
Sublime Security
Link: Apple App Store link to apps impersonating AI adveristing
9d ago
Mar 5th, 2026
Sublime Security