Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Sep 9th, 2026
Feed Source
Detection Method is
Rule Name & Severity
Author
Last Updated
Labels
Link to auto-download of a suspicious file type (unsolicited)
Sublime Security
8mo ago
Jan 12th, 2026
MalwareBazaar: Malicious attachment hash in archive (trusted reporters)
Sublime Security
4mo ago
Apr 29th, 2026
Malware: Pikabot delivery via URL auto-download
Sublime Security
2y ago
Apr 25th, 2024
Non-RFC compliant calendar files from unsolicited sender
Sublime Security
4mo ago
Apr 28th, 2026
QR code to auto-download of a suspicious file type (unsolicited)
Sublime Security
10mo ago
Oct 17th, 2025