1,325 Sublime MQL rules across 8 message sections, grouped by which of 28 message attributes they read.
The Sublime Message Data Model has no fixed external surface, so this is a distribution of the corpus across the message attributes the rules read, not a coverage gap report: every catalogued attribute is touched by at least one rule.Sender (790) Recipients (202) Mailbox (13) Subject (431) Headers (574) Body (996) Attachments (392) Type (1320) Body 996 rules, 7 attributes body 550 rules Abuse: Cloudflare Workers Hosted EvilTokens Domain Structure mql, high Abuse: Robinhood injected content mql, medium Advance Fee Fraud (AFF) from freemail provider or suspicious TLD mql, medium Attachment: Adobe image lure in body or attachment with suspicious link mql, medium Attachment: Callback phishing solicitation via text-based file mql, medium Attachment: Cold outreach with invitation subject and not attachment mql, high Attachment: Dropbox image lure with no Dropbox domains in links mql, medium Attachment: Encrypted PDF with credential theft body mql, medium Attachment: Encrypted PDF with credential theft language in EML mql, medium Attachment: Fake secure message and suspicious indicators mql, medium Attachment: Identity Confirmation With Document Unlock Code mql, medium Attachment: Link to Doubleclick.net open redirect mql, medium Attachment: Microsoft 365 credential phishing mql, high Attachment: PDF bid/proposal lure with credential theft indicators mql, medium Attachment: Romance scam with image lure and advance-fee or suspicious link indicators mql, medium BEC/Fraud: Job scam fake thread or plaintext pivot to freemail mql, medium BEC/Fraud: Reply-chain manipulation with urgent keywords and self-reply mql, medium BEC/Fraud: Romance scam mql, medium BEC/Fraud: Scam lure with freemail pivot mql, low Body HTML: Comment with 24-character hex token mql, low Body HTML: Recipient SLD in HTML class mql, medium Body: CSS clamp() font obfuscation with IP-based links mql, medium Body: CSS Hidden text via clip-path mql, medium Body: Embedded email headers indicative of thread hijacking/abuse mql, medium Body: Fake secure email portal with HTML obfuscation mql, high Body: Suspicious table template fingerprint mql, medium Brand impersonation: Adobe Sign with suspicious indicators mql, high Brand impersonation: Adobe with suspicious language and link mql, high Brand impersonation: AliExpress mql, medium Brand impersonation: Aramco mql, medium +520 more current_thread 642 rules Advance Fee Fraud (AFF) from freemail provider or suspicious TLD mql, medium Attachment: Adobe image lure in body or attachment with suspicious link mql, medium Attachment: Calendar file with invisible Unicode characters mql, high Attachment: Calendar invite with Google redirect and invoice request mql, medium Attachment: Callback phishing solicitation via pdf file mql, high Attachment: Callback phishing solicitation via text-based file mql, medium Attachment: Cold outreach with invitation subject and not attachment mql, high Attachment: Compensation review lure with QR code mql, high Attachment: Compensation-themed DOCX with QR code credential theft mql, high Attachment: Credit card application with WhatsApp contact mql, medium Attachment: EML containing a base64 encoded script mql, high Attachment: EML with link to credential phishing page mql, high Attachment: EML with suspicious indicators mql, medium Attachment: Employment contract update with suspicious file naming mql, high Attachment: Encrypted PDF with credential theft body mql, medium Attachment: Encrypted zip file with payment-related lure mql, medium Attachment: Fake scan-to-email mql, medium Attachment: Fake secure message and suspicious indicators mql, medium Attachment: Fake voicemail via PDF mql, medium Attachment: Fictitious invoice using LinkedIn's address mql, medium Attachment: Identity Confirmation With Document Unlock Code mql, medium Attachment: Legal themed message or PDF with suspicious indicators mql, medium Attachment: PDF bid/proposal lure with credential theft indicators mql, medium Attachment: PDF file with low reputation link to ZIP file (unsolicited) mql, medium Attachment: PDF file with low reputation links to suspicious filetypes (unsolicited) mql, medium Attachment: PDF with credential theft language and link to a free subdomain (unsolicited) mql, medium Attachment: PDF with password in filename matching body text mql, medium Attachment: PDF with suspicious HeadlessChrome metadata mql, medium Attachment: QR code link with base64-encoded recipient address mql, high Attachment: QR code with credential phishing indicators mql, medium +612 more html 130 rules Advance Fee Fraud (AFF) from freemail provider or suspicious TLD mql, medium Anthropic Magic String in HTML mql, low Attachment: Adobe image lure in body or attachment with suspicious link mql, medium Attachment: Callback phishing solicitation via pdf file mql, high Attachment: EML file contains HTML attachment with login portal indicators mql, high Attachment: EML file with HTML attachment (unsolicited) mql, medium Attachment: EML with link to credential phishing page mql, high Attachment: EML with Sharepoint link likely unrelated to sender mql, medium Attachment: EML with suspicious indicators mql, medium Attachment: Fake attachment image lure mql, medium BEC/Fraud: Job scam fake thread or plaintext pivot to freemail mql, medium BEC/Fraud: Student loan callback phishing mql, medium Body HTML: Comment with 24-character hex token mql, low Body: CSS clamp() font obfuscation with IP-based links mql, medium Body: CSS zero-value calc() obfuscation mql, medium Body: Embedded email headers indicative of thread hijacking/abuse mql, medium Body: Fake secure email portal with HTML obfuscation mql, high Body: HTML whitespace stuffing with short initial message mql, medium Body: Invisible Unicode obfuscation student loan callback phishing mql, medium Body: Yellow highlighted text markers mql, low Brand impersonation: Adobe Sign with suspicious indicators mql, high Brand impersonation: Capital One mql, high Brand impersonation: Cloud services with credential theft intent mql, medium Brand impersonation: DocuSign mql, high Brand impersonation: Evite mql, medium Brand impersonation: Fake DocuSign HTML table not linking to DocuSign domains mql, medium Brand impersonation: Fake Fax mql, medium Brand impersonation: File sharing notification with template artifacts mql, low Brand impersonation: Google Drive fake file share mql, medium Brand impersonation: Google using Microsoft Forms mql, high +100 more ips (collection) 1 rule links (collection) 444 rules Abuse: Cloudflare Workers Hosted EvilTokens Domain Structure mql, high Advance Fee Fraud (AFF) from freemail provider or suspicious TLD mql, medium Attachment: Adobe image lure in body or attachment with suspicious link mql, medium Attachment: Callback phishing solicitation via text-based file mql, medium Attachment: Dropbox image lure with no Dropbox domains in links mql, medium Attachment: Fake secure message and suspicious indicators mql, medium Attachment: Microsoft 365 credential phishing mql, high Attachment: PDF bid/proposal lure with credential theft indicators mql, medium Attachment: Romance scam with image lure and advance-fee or suspicious link indicators mql, medium BEC/Fraud: Job scam fake thread or plaintext pivot to freemail mql, medium BEC/Fraud: Romance scam mql, medium BEC/Fraud: Scam lure with freemail pivot mql, low Body: CSS clamp() font obfuscation with IP-based links mql, medium Body: Fake secure email portal with HTML obfuscation mql, high Brand impersonation: Adobe Sign with suspicious indicators mql, high Brand impersonation: Adobe with suspicious language and link mql, high Brand impersonation: AliExpress mql, medium Brand impersonation: Aramco mql, medium Brand impersonation: Blockchain.com mql, medium Brand impersonation: Booking.com mql, medium Brand impersonation: Capital One mql, high Brand impersonation: Chase bank with credential phishing indicators mql, medium Brand impersonation: Cloud services with credential theft intent mql, medium Brand impersonation: Coinbase with suspicious links mql, medium Brand impersonation: DocuSign mql, high Brand impersonation: DocuSign branded attachment lure with no DocuSign links mql, high Brand impersonation: DoorDash mql, medium Brand impersonation: Dropbox mql, medium Brand impersonation: Enbridge mql, medium Brand impersonation: Evite mql, medium +414 more plain 34 rules Anthropic Magic String in HTML mql, low Attachment: Callback phishing solicitation via pdf file mql, high Attachment: Legal themed message or PDF with suspicious indicators mql, medium BEC/Fraud: Unsolicited business acquisition offer mql, medium Body: Embedded email headers indicative of thread hijacking/abuse mql, medium Brand impersonation: Google Drive fake file share mql, medium Brand impersonation: Microsoft with low reputation links mql, medium Brand impersonation: Sharepoint mql, high Brand impersonation: Sharepoint fake file share mql, medium Brand impersonation: Wells Fargo mql, high Fake message thread - Untrusted sender with a mismatched freemail reply-to address mql, medium Fake thread with suspicious indicators mql, medium HTML smuggling with atob in message body mql, high Impersonation: Fake Gmail attachment mql, high Impersonation: SharePoint reply header anomaly mql, medium Impersonation: Suspected supplier impersonation with suspicious content mql, high Link to Google Apps Script macro via comment tagging mql, medium Link: Remittance payment request with timeline template mql, medium Link: Secure SharePoint file share from new or unusual sender mql, low Link: Zoho form link from unsolicited sender mql, medium Malformed URL prefix mql, high Reconnaissance: Empty message from uncommon sender mql, low Reconnaissance: Fake real estate inquiry with empty body mql, medium Service abuse: Google Firebase sender address with suspicious content mql, low Spam: Attendee list solicitation mql, low Spam: Fake photo share mql, low Spam: New link domain (<=10d) and emojis mql, medium Spam: URL shortener with short body content and emojis mql, low Suspicious invoice reference with missing or image-only attachments mql, high URL with Unicode U+2044 (⁄) or U+2215 (∕) characters mql, low +4 more previous_threads (collection) 23 rules Attachment: Encrypted PDF with credential theft body mql, medium BEC/Fraud: Reply-chain manipulation with urgent keywords and self-reply mql, medium Brand impersonation: Adobe Sign with suspicious indicators mql, high Brand impersonation: Google Drive fake file share mql, medium Business Email Compromise: Request for mobile number via reply thread hijacking mql, medium Credential phishing: 'Secure message' and engaging language mql, medium Fake thread with suspicious indicators mql, medium Impersonation: IT Department mailbox storage alert mql, medium Job scam with specific salary pattern mql, low Link: Free file hosting with undisclosed recipients mql, medium Spam: Attendee list solicitation mql, low Spam: Personalized subject and greetings via Salesforce Marketing Cloud mql, low Spam: Website errors solicitation mql, low Vendor impersonation: Thread hijacking with typosquat domain mql, high VIP impersonation: Fabricated thread history with fake VIP recipients mql, high VIP impersonation: Fake forwarded indicator with VIP recipient impersonation mql, high VIP impersonation: Fake thread with VIPs missing email metadata mql, high VIP impersonation: Invoice fraud with mobile device sign-off mql, high VIP impersonation: Payment handoff with VIP display name authored fake threads mql, high VIP Impersonation: VIP handoff with fake forwarded invoice thread mql, high VIP impersonation: VIP name within a delimited subject with fake previous threads mql, high VIP impersonation: VIP payment redirect handoff via fake threads mql, high VIP impersonation: VIP recipient of previous thread with HTML generator mql, high