Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Sep 9th, 2026
Feed Source
Detection Method is
Rule Name & Severity
Author
Last Updated
Labels
Attachment: PDF with fake invoice using suspicious font sizing
Sublime Security
3mo ago
Jun 9th, 2026
Attachment: PDF with link to DMG file download
Sublime Security
8mo ago
Jan 12th, 2026
Attachment: PDF with link to zip containing a wsf file
Sublime Security
8mo ago
Jan 12th, 2026
Attachment: PDF with Microsoft Purview message impersonation
Sublime Security
10mo ago
Nov 10th, 2025
Attachment: PDF with password in filename matching body text
Sublime Security
6mo ago
Feb 19th, 2026
Attachment: PDF with personal Microsoft OneNote URL
Sublime Security
9mo ago
Dec 4th, 2025
Attachment: PDF with QR code containing recipient-specific credential theft content
Sublime Security
3mo ago
Jun 10th, 2026
Attachment: PDF with secure document acknowledgment prompt
Sublime Security
1mo ago
Jul 17th, 2026
Attachment: PDF with suspicious document view lure
Sublime Security
1mo ago
Jul 14th, 2026
Attachment: PDF with suspicious internal object reference identifier
Sublime Security
2mo ago
Jun 29th, 2026
Attachment: PDF with suspicious link and action-oriented language
Sublime Security
23d ago
Aug 18th, 2026
Attachment: PDF with View RFP Document lure with external link
Sublime Security
14d ago
Aug 27th, 2026
Attachment: PDF with W-9 form indicators
Sublime Security
2mo ago
Jun 26th, 2026
Attachment: RFP/RFQ impersonating government entities
Sublime Security
2y ago
Jan 30th, 2024
Attachment: Romance scam with image lure and advance-fee or suspicious link indicators
Sublime Security
2mo ago
Jul 1st, 2026
Attachment: Self-sender PDF with minimal content and view prompt
Sublime Security
6mo ago
Feb 12th, 2026
Attachment: Suspicious employee policy update document lure
Sublime Security
8mo ago
Dec 26th, 2025
Attachment: Suspicious PDF created with headless browser
Sublime Security
2mo ago
Jul 1st, 2026
Attachment: SVG file execution
Sublime Security
1y ago
Aug 8th, 2025
Attachment: SVG file with HTML entity encoded href attributes
Sublime Security
3mo ago
May 20th, 2026
Attachment: SVG file with hyperlinks and cursor styling
Sublime Security
3mo ago
May 20th, 2026
Attachment: Targeted DOCX with personalized recipient acknowledgement lure
Sublime Security
1mo ago
Aug 4th, 2026
Attachment: USDA bid invitation impersonation
Sublime Security
1y ago
Aug 5th, 2025
Attachment: Web files with suspicious comments
Sublime Security
1y ago
Aug 8th, 2025
BEC: Employee impersonation with subject manipulation
Sublime Security
7mo ago
Jan 16th, 2026
BEC: Executive coaching vendor impersonation
Sublime Security
2mo ago
Jul 1st, 2026
BEC: Financial fraud from newly registered sender domain
Sublime Security
2mo ago
Jun 25th, 2026
BEC/Fraud: Fake investment outreach from suspicious TLD
Sublime Security
30d ago
Aug 11th, 2026
BEC/Fraud: Generic scam attempt to undisclosed recipients
Sublime Security
1mo ago
Jul 27th, 2026
BEC/Fraud: Job scam fake thread or plaintext pivot to freemail
Sublime Security
3mo ago
Jun 5th, 2026
BEC/Fraud: Penpal scam
Sublime Security
1mo ago
Jul 27th, 2026
BEC/Fraud: Reply-chain manipulation with urgent keywords and self-reply
Sublime Security
6mo ago
Mar 11th, 2026
BEC/Fraud: Romance scam
Sublime Security
6mo ago
Mar 9th, 2026
BEC/Fraud: Scam lure with freemail pivot
Sublime Security
4mo ago
Apr 30th, 2026
BEC/Fraud: Self-addressed reply with unrelated link in ongoing thread
Sublime Security
15d ago
Aug 26th, 2026
BEC/Fraud: Student loan callback phishing
Sublime Security
4mo ago
May 4th, 2026
BEC/Fraud: Unsolicited business acquisition offer
Sublime Security
2mo ago
Jul 6th, 2026
BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns
Sublime Security
4mo ago
Apr 17th, 2026
BEC: Tax document request
Sublime Security
1mo ago
Aug 6th, 2026
BEC: Wealth management lure from newly registered domain
Sublime Security
2d ago
Sep 8th, 2026
BEC with unusual reply-to or return-path mismatch
Sublime Security
3mo ago
Jun 5th, 2026
Benefits enrollment impersonation
Sublime Security
3mo ago
Jun 5th, 2026
Body: CSS clamp() font obfuscation
Sublime Security
9d ago
Sep 1st, 2026
Body: CSS Hidden text via clip-path
Sublime Security
1mo ago
Aug 5th, 2026
Body: CSS Hidden text via table-column
Sublime Security
7d ago
Sep 3rd, 2026
Body: CVE-2026-42897 Exchange OWA stored XSS
Sublime Security
10h ago
Sep 9th, 2026
Body: Embedded email headers indicative of thread hijacking/abuse
Sublime Security
9mo ago
Dec 1st, 2025
Body: Fake secure email portal with HTML obfuscation
Sublime Security
2mo ago
Jun 18th, 2026
Body HTML: Comment with 24-character hex token
Sublime Security
9d ago
Sep 1st, 2026
Body: HTML whitespace stuffing with short initial message
Sublime Security
13d ago
Aug 28th, 2026