• Sublime Core Feed

Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Apr 3rd, 2026
Feed Source
Attack Type is
Rule Name & Severity
Author
Last Updated
Labels
Attachment: Calendar invite from recently registered domain
Sublime Security
6mo ago
Sep 25th, 2025
Attachment: Callback phishing solicitation via image file
@vector_sec
2mo ago
Jan 12th, 2026
Attachment: Callback phishing solicitation via pdf file
Sublime Security
8mo ago
Aug 5th, 2025
Attachment: Callback phishing solicitation via text-based file
Sublime Security
6mo ago
Sep 22nd, 2025
Attachment: PDF generated with wkhtmltopdf tool and default title
Sublime Security
3mo ago
Dec 19th, 2025
BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns
Sublime Security
2mo ago
Jan 12th, 2026
Body: PayApp transaction reference pattern
Sublime Security
8d ago
Mar 27th, 2026
Brand impersonation: AliExpress
Sublime Security
8mo ago
Aug 5th, 2025
Brand impersonation: GitHub with callback scam indicators
Sublime Security
24d ago
Mar 11th, 2026
Brand impersonation: McAfee
Sublime Security
24d ago
Mar 11th, 2026
Brand impersonation: Quickbooks
Sublime Security
2mo ago
Jan 15th, 2026
Brand impersonation: QuickBooks notification from Intuit themed company name
Sublime Security
2mo ago
Jan 12th, 2026
Brand impersonation: SiriusXM
Sublime Security
8mo ago
Aug 5th, 2025
Brand impersonation: Vanguard
Sublime Security
6mo ago
Sep 22nd, 2025
Brand impersonation: WeTransfer
Sublime Security
8mo ago
Aug 5th, 2025
Callback phishing: AOL senders with suspicious HTML template or PDF attachment
Sublime Security
2mo ago
Jan 12th, 2026
Callback phishing: Branded invoice from sender/reply-to domain less than 30 days old
Sublime Security
5mo ago
Oct 17th, 2025
Callback phishing in body or attachment (untrusted sender)
Sublime Security
8d ago
Mar 27th, 2026
Callback phishing: Social Security Administration fraud
Sublime Security
2mo ago
Jan 12th, 2026
Callback phishing solicitation in message body
Sublime Security
5mo ago
Oct 17th, 2025
Callback phishing: SumUp infrastructure abuse
Sublime Security
7mo ago
Sep 5th, 2025
Callback phishing via Adobe Sign comment
Sublime Security
2mo ago
Jan 12th, 2026
Callback phishing via calendar invite
Sublime Security
2mo ago
Jan 22nd, 2026
Callback phishing via DocuSign comment
Sublime Security
2mo ago
Jan 12th, 2026
Callback phishing via e-signature service
Sublime Security
2mo ago
Jan 12th, 2026
Callback phishing via extensionless rfc822 attachment
Sublime Security
2mo ago
Jan 12th, 2026
Callback phishing via Google Group abuse
Sublime Security
8mo ago
Jul 16th, 2025
Callback phishing via Google Meet
Sublime Security
2mo ago
Jan 12th, 2026
Callback phishing via Intuit service abuse
Sublime Security
2mo ago
Jan 12th, 2026
Callback phishing via Microsoft comment
Sublime Security
9d ago
Mar 26th, 2026
Callback Phishing via Signable E-Signature Request
Sublime Security
2mo ago
Jan 12th, 2026
Callback phishing via SignFree e-signature request
Sublime Security
2mo ago
Jan 12th, 2026
Callback phishing via Xodo Sign comment
Sublime Security
2mo ago
Jan 12th, 2026
Callback phishing via Yammer comment
Sublime Security
2mo ago
Jan 12th, 2026
Callback phishing via Zelle Service Abuse
Sublime Security
2mo ago
Jan 12th, 2026
Callback phishing via Zoho service abuse
Sublime Security
2mo ago
Jan 12th, 2026
Callback Phishing via Zoom comment
Sublime Security
1mo ago
Feb 11th, 2026
Callback scam: Impersonation via TimeTrade infrastructure
Sublime Security
7mo ago
Aug 20th, 2025
Canva infrastructure abuse
Sublime Security
1mo ago
Feb 6th, 2026
Display Name Emoji with Financial Symbols
Sublime Security
2mo ago
Jan 12th, 2026
Encrypted Microsoft Office files from untrusted sender
Sublime Security
8mo ago
Aug 5th, 2025
Generic service abuse from newly registered domain
Sublime Security
8mo ago
Aug 5th, 2025
Inbound message from popular service via newly observed distribution list
Sublime Security
8mo ago
Aug 5th, 2025
Link: Direct POWR.io Form Builder with suspicious patterns
Sublime Security
8mo ago
Aug 5th, 2025
Link: /index.php enclosed in three asterisks
Sublime Security
2mo ago
Jan 12th, 2026
Link: Invoice or receipt from freemail sender with customer service number
@vector_sec
2mo ago
Jan 12th, 2026
Link: Jensi file preview link from unsolicited sender
Sublime Security
2mo ago
Jan 12th, 2026
Link: Webflow link from unsolicited sender
Sublime Security
8mo ago
Aug 5th, 2025
Link: Zoho form link from unsolicited sender
Sublime Security
8mo ago
Aug 5th, 2025
Message traversed multiple onmicrosoft.com tenants
Sublime Security
2mo ago
Jan 12th, 2026