Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Sep 9th, 2026
Feed Source
Detection Method is
Rule Name & Severity
Author
Last Updated
Labels
Attachment: HTML smuggling with decimal encoding
Sublime Security
8mo ago
Jan 12th, 2026
Attachment: HTML smuggling with embedded base64-encoded ISO
Sublime Security
3y ago
Aug 21st, 2023
Attachment: HTML smuggling with embedded base64 streamed file download
Sublime Security
3y ago
Aug 21st, 2023
Attachment: HTML smuggling with eval and atob
Sublime Security
8mo ago
Jan 12th, 2026
Attachment: HTML smuggling with excessive line break obfuscation
Sublime Security
8mo ago
Jan 12th, 2026
Attachment: HTML smuggling with fromCharCode and other signals
Sublime Security
3y ago
Aug 21st, 2023
Attachment: HTML smuggling with hex strings
@ajpc500
3y ago
Aug 21st, 2023
Attachment: HTML smuggling with high entropy and other signals
Sublime Security
3y ago
Aug 21st, 2023
Attachment: HTML smuggling with raw array buffer
Sublime Security
3y ago
Aug 21st, 2023
Attachment: HTML smuggling with RC4 decryption
Sublime Security
8mo ago
Jan 12th, 2026
Attachment: HTML smuggling with ROT13
@Kyle_Parrish_
8mo ago
Jan 12th, 2026
Attachment: HTML smuggling with setTimeout
Sublime Security
8mo ago
Jan 12th, 2026
Attachment: HTML with hidden body
Sublime Security
8mo ago
Jan 12th, 2026
Attachment: HTML with JavaScript functions for HTTP requests
Sublime Security
1y ago
Aug 5th, 2025
Attachment: ICS calendar file with base64 encoded recipient address in URL parameters
Sublime Security
4mo ago
May 12th, 2026
Attachment: ICS calendar file with QR code containing recipient email address
Sublime Security
4mo ago
Apr 20th, 2026
Attachment: ICS calendar file with recipient address in UID field
Sublime Security
6d ago
Sep 4th, 2026
Attachment: ICS calendar file with suspicious product identifier
Sublime Security
1mo ago
Jul 27th, 2026
Attachment: ICS calendar file with suspicious UID domain
Sublime Security
6d ago
Sep 4th, 2026
Attachment: ICS calendar invite with bid/RFP lure and suspicious link
Sublime Security
2d ago
Sep 8th, 2026
Attachment: ICS calendar invite with financial lure and suspicious link
Sublime Security
10d ago
Aug 31st, 2026
Attachment: ICS calendar invite with photo/file share lure
Sublime Security
6h ago
Sep 9th, 2026
Attachment: ICS file with AWS Lambda URL
Sublime Security
1mo ago
Jul 16th, 2026
Attachment: ICS file with excessive custom properties
Sublime Security
6d ago
Sep 4th, 2026
Attachment: ICS file with non-Gregorian calendar scale
Sublime Security
4mo ago
Apr 28th, 2026
Attachment: ICS invite meeting lure
Sublime Security
14d ago
Aug 27th, 2026
Attachment: ICS voicemail lure with suspicious link
Sublime Security
6h ago
Sep 9th, 2026
Attachment: ICS with employee policy review lure
Sublime Security
4mo ago
Apr 28th, 2026
Attachment: Identity Confirmation With Document Unlock Code
Sublime Security
1mo ago
Jul 28th, 2026
Attachment: Image-only docx/pptx callback phishing
Sublime Security
20d ago
Aug 21st, 2026
Attachment: Invoice and W-9 PDFs with suspicious creators
Sublime Security
16d ago
Aug 25th, 2026
Attachment: Legal themed message or PDF with suspicious indicators
Sublime Security
5mo ago
Apr 3rd, 2026
Attachment: Link to Doubleclick.net open redirect
Sublime Security
4mo ago
Apr 29th, 2026
Attachment: LNK with embedded content
@ajpc500
8mo ago
Jan 12th, 2026
Attachment: Macro with suspected use of COM ShellBrowserWindow object for process creation
@ajpc500
8mo ago
Jan 12th, 2026
Attachment: Malicious OneNote commands
@Kyle_Parrish_
8mo ago
Jan 12th, 2026
Attachment: Malicious zip file matching zipline campaign
Sublime Security
2mo ago
Jun 25th, 2026
Attachment: Microsoft 365 credential phishing
Sublime Security
1mo ago
Jul 27th, 2026
Attachment: Microsoft OAuth credential harvesting via EML with embedded malicious links
Sublime Security
3mo ago
Jun 1st, 2026
Attachment: Office document with VSTO add-in
@vector_sec
8mo ago
Jan 12th, 2026
Attachment: Office file with credential phishing URLs
Sublime Security
8mo ago
Jan 12th, 2026
Attachment: Office file with document sharing and browser instruction lures
Sublime Security
7mo ago
Jan 29th, 2026
Attachment: OLE external relationship containing file scheme link to executable filetype
Sublime Security
9mo ago
Nov 24th, 2025
Attachment: OLE external relationship containing file scheme link to IP address
Sublime Security
8mo ago
Jan 12th, 2026
Attachment: PDF bid/proposal lure with credential theft indicators
Sublime Security
5mo ago
Mar 27th, 2026
Attachment: PDF file with recipient domain and ATT eCheckRun pattern
Sublime Security
2mo ago
Jun 16th, 2026
Attachment: PDF Grant Payment lure with embedded link
Sublime Security
15d ago
Aug 26th, 2026
Attachment: PDF with a suspicious string and single URL
Sublime Security
22d ago
Aug 19th, 2026
Attachment: PDF with bolded passcode
Sublime Security
2d ago
Sep 8th, 2026
Attachment: PDF with credential theft language and invalid reply-to domain
Sublime Security
5mo ago
Apr 10th, 2026