Detection Method: URL analysis

URL analysis scans links in emails, attachments, or embedded content to find malicious destinations aimed at stealing your credentials, delivering malware, or launching other types of attacks. This method looks at key factors like the structure of the URL, redirection paths, domain reputation, and what the link shows when clicked.
URL analysis can help you detect:
  • Phishing sites pretending to be trusted login pages
  • Malicious domains hidden through URL shorteners or redirects
  • Login forms on suspicious or newly registered domains
  • Brand impersonation using slight domain tweaks (typosquatting or homograph attacks)
  • Suspicious URLs with weird characters or unusual patterns
For example, attackers often use redirect chains to hide their final destination from security scanners. With URL analysis, we can follow these redirects to reveal the true destination and assess the potential threat.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Link: Numeric IP obfuscation in URL
13h ago
Aug 6th, 2026
Sublime Security
Brand impersonation: SoFi
13h ago
Aug 6th, 2026
Sublime Security
URL with Unicode U+2044 (⁄) or U+2215 (∕) characters
13h ago
Aug 6th, 2026
@delivr_to
Credential phishing content and link (untrusted sender)
22h ago
Aug 6th, 2026
Sublime Security
Spam: Fake photo share
22h ago
Aug 6th, 2026
Sublime Security
Brand impersonation: Cloud services with credential theft intent
23h ago
Aug 6th, 2026
Sublime Security
Service abuse: Evernote link
2d ago
Aug 5th, 2026
Sublime Security
Link: Mismatched free file host links with document lure
2d ago
Aug 5th, 2026
Sublime Security
Link: Suspicious recipient with timeout redirect
3d ago
Aug 4th, 2026
Sublime Security
Service abuse: Cognito Forms with short body from unknown sender
3d ago
Aug 4th, 2026
Sublime Security
Link: Unformatted template with literal placeholder in mailto link
4d ago
Aug 3rd, 2026
Sublime Security
Credential phishing: Suspicious e-sign agreement document notification
4d ago
Aug 3rd, 2026
Sublime Security
Link: Unicode character obfuscation in display name with base64-encoded URL fragment
4d ago
Aug 3rd, 2026
Sublime Security
Brand impersonation: Robinhood
4d ago
Aug 3rd, 2026
Sublime Security
Service abuse: Adobe share containing newly observed email address domain
7d ago
Jul 31st, 2026
Sublime Security
Service abuse: Adobe message from newly registered domain
7d ago
Jul 31st, 2026
Sublime Security
Body: CSS clamp() font obfuscation with IP-based links
9d ago
Jul 29th, 2026
Sublime Security
Link: QuickBooks image lure with suspicious link
9d ago
Jul 29th, 2026
Sublime Security
Attachment: EML with Sharepoint link likely unrelated to sender
9d ago
Jul 29th, 2026
Sublime Security
Low reputation link to auto-downloaded HTML file with smuggling indicators
9d ago
Jul 29th, 2026
Sublime Security