Rule Name & Severity | Last Updated | Author | Types, Tactics & Capabilities | |
|---|---|---|---|---|
Brand impersonation: DocuSign branded attachment lure with no DocuSign links | 21d ago Oct 22nd, 2025 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-docusign-branded-attachment-lure-with-no-docusign-links-814a5694 | |
Google Accelerated Mobile Pages (AMP) abuse | 1mo ago Sep 22nd, 2025 | Sublime Security | /feeds/core/detection-rules/google-accelerated-mobile-pages-amp-abuse-46907029 | |
Attachment: QR code with credential phishing indicators | 2mo ago Sep 4th, 2025 | Sublime Security | /feeds/core/detection-rules/attachment-qr-code-with-credential-phishing-indicators-9f1681e1 | |
Link: Multistage landing - FreshDesk knowledge base abuse | 2mo ago Aug 21st, 2025 | Sublime Security | /feeds/core/detection-rules/link-multistage-landing-freshdesk-knowledge-base-abuse-edd6acf7 | |
Link: Multistage landing - Trello board abuse | 2mo ago Aug 20th, 2025 | Sublime Security | /feeds/core/detection-rules/link-multistage-landing-trello-board-abuse-14a5b23a | |
Link: Adobe share with suspicious indicators | 3mo ago Aug 5th, 2025 | Sublime Security | /feeds/core/detection-rules/link-adobe-share-with-suspicious-indicators-b33cae80 | |
Suspicious recipients pattern with no Compauth pass and suspicious content | 3mo ago Aug 5th, 2025 | Sublime Security | /feeds/core/detection-rules/suspicious-recipients-pattern-with-no-compauth-pass-and-suspicious-content-34fb65f6 | |
Link: Multistage landing - Scribd document | 3mo ago Aug 5th, 2025 | Sublime Security | /feeds/core/detection-rules/link-multistage-landing-scribd-document-afa9807d | |
Link: Multistage landing - Ludus presentation | 3mo ago Aug 5th, 2025 | Sublime Security | /feeds/core/detection-rules/link-multistage-landing-ludus-presentation-a8b3c311 | |
Issuu document with suspicious embedded link | 3mo ago Aug 5th, 2025 | Sublime Security | /feeds/core/detection-rules/issuu-document-with-suspicious-embedded-link-0d73f43d | |
Link: Figma design deck with credential theft language | 3mo ago Aug 5th, 2025 | Sublime Security | /feeds/core/detection-rules/link-figma-design-deck-with-credential-theft-language-87601924 | |
Link: chatbot.page platform abuse | 3mo ago Aug 5th, 2025 | Sublime Security | /feeds/core/detection-rules/link-chatbotpage-platform-abuse-bfd6a076 | |
Link: Credential phishing link with undisclosed recipients | 3mo ago Aug 5th, 2025 | Sublime Security | /feeds/core/detection-rules/link-credential-phishing-link-with-undisclosed-recipients-06fc155e | |
Attachment: HTML smuggling - QR Code with suspicious links | 3mo ago Jul 16th, 2025 | Sublime Security | /feeds/core/detection-rules/attachment-html-smuggling-qr-code-with-suspicious-links-010e757d | |
Credential phishing link (unknown sender) | 3mo ago Jul 16th, 2025 | Sublime Security | /feeds/core/detection-rules/credential-phishing-link-unknown-sender-a278012b | |
Free subdomain link with login or captcha (untrusted sender) | 3mo ago Jul 16th, 2025 | Sublime Security | /feeds/core/detection-rules/free-subdomain-link-with-login-or-captcha-untrusted-sender-93288f82 | |
Credential phishing content and link (untrusted sender) | 3mo ago Jul 16th, 2025 | Sublime Security | /feeds/core/detection-rules/credential-phishing-content-and-link-untrusted-sender-f0c95bb7 | |
Link: Microsoft Dynamics 365 form phishing | 3mo ago Jul 16th, 2025 | Sublime Security | /feeds/core/detection-rules/link-microsoft-dynamics-365-form-phishing-f72b9085 | |
Link to auto-downloaded file with Adobe branding | 3mo ago Jul 16th, 2025 | Sublime Security | /feeds/core/detection-rules/link-to-auto-downloaded-file-with-adobe-branding-e826c2cf | |
Link to auto-downloaded file with Google Drive branding | 3mo ago Jul 16th, 2025 | Sublime Security | /feeds/core/detection-rules/link-to-auto-downloaded-file-with-google-drive-branding-4b5343be |