• Sublime Core Feed

Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Jan 23rd, 2026
Feed Source
Detection Method is
Rule Name & Severity
Author
Last Updated
Labels
Link: SharePoint filename matches org name
Sublime Security
3mo ago
Sep 26th, 2025
/feeds/core/detection-rules/link-sharepoint-filename-matches-org-name-cb954726
Link: Spam website with evasion indicators
Sublime Security
1mo ago
Nov 25th, 2025
/feeds/core/detection-rules/link-spam-website-with-evasion-indicators-08bcd353
Link: Suspicious SharePoint document name
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-suspicious-sharepoint-document-name-f95fee6e
Link: Suspicious URL with recipient targeting and special characters
Sublime Security
2d ago
Jan 22nd, 2026
/feeds/core/detection-rules/link-suspicious-url-with-recipient-targeting-and-special-characters-e808be3a
Link to auto-downloaded file with Google Drive branding
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-to-auto-downloaded-file-with-google-drive-branding-4b5343be
Link to Google Apps Script macro via comment tagging
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-to-google-apps-script-macro-via-comment-tagging-66fecd30
Link: Tycoon2FA phishing kit (non-exhaustive)
Sublime Security
20h ago
Jan 23rd, 2026
/feeds/core/detection-rules/link-tycoon2fa-phishing-kit-non-exhaustive-a070d4e2
Link: Uncommon SharePoint document type with sender's display name
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-uncommon-sharepoint-document-type-with-senders-display-name-02d290b2
Link: URL scheme obfuscation via split HTML anchors
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-url-scheme-obfuscation-via-split-html-anchors-10375948
Link: Webflow link from unsolicited sender
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-webflow-link-from-unsolicited-sender-d4f3b8cf
Link: Zoho form link from unsolicited sender
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-zoho-form-link-from-unsolicited-sender-eb04a9f2
Low reputation link to auto-downloaded HTML file with smuggling indicators
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/low-reputation-link-to-auto-downloaded-html-file-with-smuggling-indicators-339676c6
Mass campaign: Cross Site Scripting (XSS) attempt
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/mass-campaign-cross-site-scripting-xss-attempt-6cbb7124
Microsoft device code phishing
@ajpc500
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/microsoft-device-code-phishing-61f3ae67
Non-RFC compliant calendar files from unsolicited sender
Sublime Security
3mo ago
Oct 1st, 2025
/feeds/core/detection-rules/non-rfc-compliant-calendar-files-from-unsolicited-sender-9859f100
Notion suspicious file share
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/notion-suspicious-file-share-f7307929
Open redirect: Cartoon Network
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/open-redirect-cartoon-network-7435e057
Open redirect: giving.lluh.org
Sublime Security
8mo ago
May 23rd, 2025
/feeds/core/detection-rules/open-redirect-givinglluhorg-a2bf1099
Open redirect (go2.aspx) leading to Microsoft credential phishing
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/open-redirect-go2aspx-leading-to-microsoft-credential-phishing-51667096
Open Redirect: Google domain with /url path and suspicious indicators
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/open-redirect-google-domain-with-url-path-and-suspicious-indicators-fc5adf74
Open redirect: Klaviyo
Sublime Security
2y ago
May 14th, 2024
/feeds/core/detection-rules/open-redirect-klaviyo-ce5a370a
Open redirect: marketing.edinburghairport.com
Sublime Security
8mo ago
May 23rd, 2025
/feeds/core/detection-rules/open-redirect-marketingedinburghairportcom-33a47565
Open redirect: next2.io
Sublime Security
8mo ago
May 23rd, 2025
/feeds/core/detection-rules/open-redirect-next2io-5085c422
Open redirect: people.anuneo.com
Sublime Security
8mo ago
May 23rd, 2025
/feeds/core/detection-rules/open-redirect-peopleanuneocom-2ae83b73
Open redirect: slubnaglowie.pl
Sublime Security
8mo ago
May 23rd, 2025
/feeds/core/detection-rules/open-redirect-slubnaglowiepl-2ec356d0
Open redirect: typedrawers.com
Sublime Security
8mo ago
May 23rd, 2025
/feeds/core/detection-rules/open-redirect-typedrawerscom-158d9e95
Outlook hyperlink bypass: left-to-right mark (LRM) in base HTML tag
Sublime Security
1mo ago
Dec 10th, 2025
/feeds/core/detection-rules/outlook-hyperlink-bypass-left-to-right-mark-lrm-in-base-html-tag-160cc681
PayPal invoice abuse
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/paypal-invoice-abuse-0ff7a0d4
PDF attachment with Google (AE) redirecting to a php or zip file
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/pdf-attachment-with-google-ae-redirecting-to-a-php-or-zip-file-57ae513f
PhaaS: Impact Solutions (Impact Vector Suite)
Sublime Security
5h ago
Jan 23rd, 2026
/feeds/core/detection-rules/phaas-impact-solutions-impact-vector-suite-4d197faf
Potential prompt injection attack in body HTML
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/potential-prompt-injection-attack-in-body-html-5fb24736
QR Code with suspicious indicators
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/qr-code-with-suspicious-indicators-04f5c34f
Reconnaissance: All recipients cc/bcc'd or undisclosed
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/reconnaissance-all-recipients-ccbccd-or-undisclosed-420f60d3
Reconnaissance: Email address harvesting attempt
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/reconnaissance-email-address-harvesting-attempt-bb31efbc
Reconnaissance: Large unknown recipient list
Sublime Security
2mo ago
Nov 24th, 2025
/feeds/core/detection-rules/reconnaissance-large-unknown-recipient-list-24783a28
Reconnaissance: Short generic greeting message
Sublime Security
1mo ago
Dec 2nd, 2025
/feeds/core/detection-rules/reconnaissance-short-generic-greeting-message-c67dedab
Recruitee Infrastructure Abuse
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/recruitee-infrastructure-abuse-31cab83d
Request for Quote or Purchase (RFQ|RFP) with HTML smuggling attachment
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/request-for-quote-or-purchase-rfqorrfp-with-html-smuggling-attachment-a47a5755
Request for Quote or Purchase (RFQ|RFP) with suspicious sender or recipient pattern
Sublime Security
9d ago
Jan 15th, 2026
/feeds/core/detection-rules/request-for-quote-or-purchase-rfqorrfp-with-suspicious-sender-or-recipient-pattern-2ac0d329
Salesforce infrastructure abuse
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/salesforce-infrastructure-abuse-78a77c70
Scam: Piano giveaway
Sublime Security
1mo ago
Dec 11th, 2025
/feeds/core/detection-rules/scam-piano-giveaway-1a91a203
Self-sent fake PDF attachment with misleading link
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/self-sent-fake-pdf-attachment-with-misleading-link-8a285d2e
Sendgrid voicemail phish
Sublime Security
2mo ago
Nov 24th, 2025
/feeds/core/detection-rules/sendgrid-voicemail-phish-21cad89c
Service abuse: Adobe legitimate domain with document approval language
Sublime Security
23h ago
Jan 23rd, 2026
/feeds/core/detection-rules/service-abuse-adobe-legitimate-domain-with-document-approval-language-237f4da4
Service abuse: AppSheet infrastructure with suspicious indicators
Sublime Security
3mo ago
Oct 6th, 2025
/feeds/core/detection-rules/service-abuse-appsheet-infrastructure-with-suspicious-indicators-5937646a
Service Abuse: Box file sharing with credential phishing intent
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/service-abuse-box-file-sharing-with-credential-phishing-intent-5bd0cb25
Service abuse: Callback phishing via Microsoft Teams invite
Sublime Security
1mo ago
Dec 12th, 2025
/feeds/core/detection-rules/service-abuse-callback-phishing-via-microsoft-teams-invite-13e35e5f
Service abuse: Cisco secure email service with financial request
Sublime Security
3mo ago
Oct 1st, 2025
/feeds/core/detection-rules/service-abuse-cisco-secure-email-service-with-financial-request-43a6daa8
Service abuse: DocSend share from an unsolicited reply-to address
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/service-abuse-docsend-share-from-an-unsolicited-reply-to-address-b377e64c
Service abuse: DocSend share from newly registered domain
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/service-abuse-docsend-share-from-newly-registered-domain-3bc152f2