Rule Name & Severity | Last Updated | Author | Types, Tactics & Capabilities | |
|---|---|---|---|---|
Service abuse: Formester with suspicious link behavior | 14d ago Dec 19th, 2025 | Sublime Security | /feeds/core/detection-rules/service-abuse-formester-with-suspicious-link-behavior-e4b74fd4 | |
Credential phishing content and link (untrusted sender) | 16d ago Dec 17th, 2025 | Sublime Security | /feeds/core/detection-rules/credential-phishing-content-and-link-untrusted-sender-f0c95bb7 | |
Link: Microsoft Dynamics 365 form phishing | 28d ago Dec 5th, 2025 | Sublime Security | /feeds/core/detection-rules/link-microsoft-dynamics-365-form-phishing-f72b9085 | |
Link: HR impersonation with suspicious domain indicators and credential theft | 30d ago Dec 3rd, 2025 | Sublime Security | /feeds/core/detection-rules/link-hr-impersonation-with-suspicious-domain-indicators-and-credential-theft-f31f8831 | |
Link: Cryptocurrency fraud with suspicious links | 1mo ago Dec 1st, 2025 | Sublime Security | /feeds/core/detection-rules/link-cryptocurrency-fraud-with-suspicious-links-d0da37ce | |
Link: Spam website with evasion indicators | 1mo ago Nov 25th, 2025 | Sublime Security | /feeds/core/detection-rules/link-spam-website-with-evasion-indicators-08bcd353 | |
Brand impersonation: DocuSign branded attachment lure with no DocuSign links | 2mo ago Oct 22nd, 2025 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-docusign-branded-attachment-lure-with-no-docusign-links-814a5694 | |
Google Accelerated Mobile Pages (AMP) abuse | 3mo ago Sep 22nd, 2025 | Sublime Security | /feeds/core/detection-rules/google-accelerated-mobile-pages-amp-abuse-46907029 | |
Attachment: QR code with credential phishing indicators | 3mo ago Sep 4th, 2025 | Sublime Security | /feeds/core/detection-rules/attachment-qr-code-with-credential-phishing-indicators-9f1681e1 | |
Link: Multistage landing - FreshDesk knowledge base abuse | 4mo ago Aug 21st, 2025 | Sublime Security | /feeds/core/detection-rules/link-multistage-landing-freshdesk-knowledge-base-abuse-edd6acf7 | |
Link: Multistage landing - Trello board abuse | 4mo ago Aug 20th, 2025 | Sublime Security | /feeds/core/detection-rules/link-multistage-landing-trello-board-abuse-14a5b23a | |
Link: Adobe share with suspicious indicators | 5mo ago Aug 5th, 2025 | Sublime Security | /feeds/core/detection-rules/link-adobe-share-with-suspicious-indicators-b33cae80 | |
Suspicious recipients pattern with no Compauth pass and suspicious content | 5mo ago Aug 5th, 2025 | Sublime Security | /feeds/core/detection-rules/suspicious-recipients-pattern-with-no-compauth-pass-and-suspicious-content-34fb65f6 | |
Link: Multistage landing - Scribd document | 5mo ago Aug 5th, 2025 | Sublime Security | /feeds/core/detection-rules/link-multistage-landing-scribd-document-afa9807d | |
Link: Multistage landing - Ludus presentation | 5mo ago Aug 5th, 2025 | Sublime Security | /feeds/core/detection-rules/link-multistage-landing-ludus-presentation-a8b3c311 | |
Issuu document with suspicious embedded link | 5mo ago Aug 5th, 2025 | Sublime Security | /feeds/core/detection-rules/issuu-document-with-suspicious-embedded-link-0d73f43d | |
Link: Figma design deck with credential theft language | 5mo ago Aug 5th, 2025 | Sublime Security | /feeds/core/detection-rules/link-figma-design-deck-with-credential-theft-language-87601924 | |
Link: chatbot.page platform abuse | 5mo ago Aug 5th, 2025 | Sublime Security | /feeds/core/detection-rules/link-chatbotpage-platform-abuse-bfd6a076 | |
Link: Credential phishing link with undisclosed recipients | 5mo ago Aug 5th, 2025 | Sublime Security | /feeds/core/detection-rules/link-credential-phishing-link-with-undisclosed-recipients-06fc155e | |
Attachment: EML with link to credential phishing page | 5mo ago Jul 16th, 2025 | Sublime Security | /feeds/core/detection-rules/attachment-eml-with-link-to-credential-phishing-page-1df41cca |