Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Apr 24th, 2026
Feed Source
Detection Method is
Rule Name & Severity
Author
Last Updated
Labels
Attachment: Adobe image lure in body or attachment with suspicious link
Sublime Security
3mo ago
Jan 5th, 2026
Attachment: Callback phishing solicitation via image file
@vector_sec
3mo ago
Jan 12th, 2026
Attachment: DocuSign impersonation via PDF linking to new domain
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: EML with link to credential phishing page
Sublime Security
9mo ago
Jul 16th, 2025
Attachment: Fake Slack installer
Sublime Security
3y ago
Nov 29th, 2023
Attachment: Fake voicemail via PDF
Sublime Security
10d ago
Apr 14th, 2026
Attachment: Fake Zoom installer
Sublime Security
3y ago
Nov 29th, 2023
Attachment: HTML smuggling - QR Code with suspicious links
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: Microsoft impersonation via PDF with link and suspicious language
Sublime Security
9mo ago
Jul 16th, 2025
Attachment: QR code link with base64-encoded recipient address
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: QR code with credential phishing indicators
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: QR code with recipient targeting and special characters
Sublime Security
2mo ago
Feb 21st, 2026
Brand impersonation: Adobe (QR code)
Sublime Security
4d ago
Apr 20th, 2026
Brand impersonation: Adobe with suspicious language and link
Sublime Security
5mo ago
Nov 24th, 2025
Brand impersonation: Amazon with suspicious attachment
Sublime Security
10d ago
Apr 14th, 2026
Brand impersonation: Box file sharing service
Sublime Security
7mo ago
Sep 23rd, 2025
Brand impersonation: Capital One
Sublime Security
5mo ago
Nov 17th, 2025
Brand impersonation: Chase bank with credential phishing indicators
Sublime Security
3mo ago
Jan 12th, 2026
Brand impersonation: Coinbase with suspicious links
Sublime Security
7mo ago
Sep 22nd, 2025
Brand impersonation: Discord notification
Sublime Security
6mo ago
Oct 23rd, 2025
Brand Impersonation: Disney
Sublime Security
1mo ago
Mar 4th, 2026
Brand impersonation: DocuSign branded attachment lure with no DocuSign links
Sublime Security
6mo ago
Oct 22nd, 2025
Brand impersonation: DocuSign (QR code)
Sublime Security
6mo ago
Oct 15th, 2025
Brand impersonation: DocuSign with embedded QR code
Sublime Security
6mo ago
Oct 17th, 2025
Brand impersonation: Fake Fax
Sublime Security
2mo ago
Feb 5th, 2026
Brand impersonation: File sharing notification with template artifacts
Sublime Security
3mo ago
Jan 23rd, 2026
Brand impersonation: Google Drive fake file share
Sublime Security
4mo ago
Dec 19th, 2025
Brand impersonation: Google fake sign-in warning
Sublime Security
3mo ago
Jan 12th, 2026
Brand Impersonation: Google (QR Code)
Sublime Security
6mo ago
Oct 17th, 2025
Brand impersonation: Gusto
Sublime Security
2mo ago
Feb 18th, 2026
Brand impersonation: Hulu
Sublime Security
3mo ago
Jan 12th, 2026
Brand impersonation: KnowBe4
Sublime Security
2y ago
Nov 25th, 2024
Brand impersonation: Mailchimp
Sublime Security
25d ago
Mar 30th, 2026
Brand impersonation: MetaMask
Sublime Security
7mo ago
Sep 22nd, 2025
Brand impersonation: Microsoft fake sign-in alert
Sublime Security
3mo ago
Jan 12th, 2026
Brand impersonation: Microsoft logo or suspicious language with open redirect
Sublime Security
2y ago
Mar 7th, 2024
Brand impersonation: Microsoft (QR code)
Sublime Security
3mo ago
Jan 12th, 2026
Brand impersonation: Microsoft quarantine release notification in body
Sublime Security
9mo ago
Jul 16th, 2025
Brand impersonation: Microsoft quarantine release notification in image attachment
Sublime Security
9mo ago
Jul 16th, 2025
Brand impersonation: Microsoft with embedded logo and credential theft language
Sublime Security
6mo ago
Oct 17th, 2025
Brand impersonation: Microsoft with low reputation links
Sublime Security
3mo ago
Jan 12th, 2026
Brand impersonation: Okta
Sublime Security
7mo ago
Sep 23rd, 2025
Brand Impersonation: PayPal
Sublime Security
25d ago
Mar 30th, 2026
Brand impersonation: PNC
Sublime Security
6mo ago
Oct 9th, 2025
Brand impersonation: Quickbooks
Sublime Security
3mo ago
Jan 15th, 2026
Brand impersonation: Robert Half
Sublime Security
6mo ago
Oct 1st, 2025
Brand impersonation: Sharepoint
Sublime Security
3mo ago
Jan 10th, 2026
Brand impersonation: Sharepoint fake file share
Sublime Security
3mo ago
Jan 12th, 2026
Brand impersonation: SharePoint PDF attachment with credential theft language
Sublime Security
5mo ago
Nov 7th, 2025
Brand Impersonation: Shein
Sublime Security
6mo ago
Oct 15th, 2025