• Sublime Core Feed

Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Mar 9th, 2026
Feed Source
Detection Method is
Rule Name & Severity
Author
Last Updated
Labels
Service abuse: Payoneer callback scam
Sublime Security
1mo ago
Jan 12th, 2026
/feeds/core/detection-rules/service-abuse-payoneer-callback-scam-b7fb174c
Service abuse: QuickBooks notification from new domain
Sublime Security
1mo ago
Jan 12th, 2026
/feeds/core/detection-rules/service-abuse-quickbooks-notification-from-new-domain-c4f46473
Service abuse: QuickBooks notification with suspicious comments
Sublime Security
1mo ago
Jan 12th, 2026
/feeds/core/detection-rules/service-abuse-quickbooks-notification-with-suspicious-comments-a23d0950
Service abuse: Random Google Firebase sender address with suspicious content
Sublime Security
1mo ago
Jan 12th, 2026
/feeds/core/detection-rules/service-abuse-random-google-firebase-sender-address-with-suspicious-content-9f8899a9
Service abuse: Recruiting with suspicious language patterns from legitimate platforms
Sublime Security
5mo ago
Oct 7th, 2025
/feeds/core/detection-rules/service-abuse-recruiting-with-suspicious-language-patterns-from-legitimate-platforms-29e12696
Service abuse: Sendgrid credential theft with personalized request targeting single recipient
Sublime Security
1mo ago
Jan 12th, 2026
/feeds/core/detection-rules/service-abuse-sendgrid-credential-theft-with-personalized-request-targeting-single-recipient-b9680da1
Service abuse: SendGrid-formatted link with actor-controlled fragment
Sublime Security
3mo ago
Nov 24th, 2025
/feeds/core/detection-rules/service-abuse-sendgrid-formatted-link-with-actor-controlled-fragment-cb511fe9
Service abuse: SendThisFile with credential theft and financial language
Sublime Security
4mo ago
Oct 27th, 2025
/feeds/core/detection-rules/service-abuse-sendthisfile-with-credential-theft-and-financial-language-c1ebf25b
Service abuse: SurveyMonkey survey from newly registered domain
Sublime Security
1mo ago
Jan 12th, 2026
/feeds/core/detection-rules/service-abuse-surveymonkey-survey-from-newly-registered-domain-50a85fa7
Service abuse: Task management message sent via SendGrid
Sublime Security
5mo ago
Oct 6th, 2025
/feeds/core/detection-rules/service-abuse-task-management-message-sent-via-sendgrid-568a63f5
Service abuse: Trello board invitation with VIP impersonation
Sublime Security
1mo ago
Feb 3rd, 2026
/feeds/core/detection-rules/service-abuse-trello-board-invitation-with-vip-impersonation-fedfc94b
Service abuse: Vimeo with external plain-text links in message
Sublime Security
4d ago
Mar 6th, 2026
/feeds/core/detection-rules/service-abuse-vimeo-with-external-plain-text-links-in-message-ba94ae6b
Service abuse: WeTransfer callback scam
Sublime Security
1mo ago
Jan 30th, 2026
/feeds/core/detection-rules/service-abuse-wetransfer-callback-scam-c60c8650
Sharepoint file share with suspicious recipients pattern
Sublime Security
2y ago
Mar 27th, 2024
/feeds/core/detection-rules/sharepoint-file-share-with-suspicious-recipients-pattern-998a0826
Sharepoint online with external recipients and external display name
@vector_sec
3y ago
Aug 17th, 2023
/feeds/core/detection-rules/sharepoint-online-with-external-recipients-and-external-display-name-5579bb4b
SharePoint OTP for filename matching org name
Sublime Security
1mo ago
Jan 12th, 2026
/feeds/core/detection-rules/sharepoint-otp-for-filename-matching-org-name-89911cbd
Shopify infrastructure abuse
Sublime Security
2y ago
Nov 13th, 2024
/feeds/core/detection-rules/shopify-infrastructure-abuse-844ff164
Spam: Attendee list solicitation
Sublime Security
6mo ago
Aug 29th, 2025
/feeds/core/detection-rules/spam-attendee-list-solicitation-69715b62
Spam: BlackBaud infrastructure abuse
Sublime Security
2y ago
Jan 17th, 2024
/feeds/core/detection-rules/spam-blackbaud-infrastructure-abuse-3db46591
Spam: Campaign with excessive display-text and keywords found
Sublime Security
1mo ago
Jan 12th, 2026
/feeds/core/detection-rules/spam-campaign-with-excessive-display-text-and-keywords-found-140e46a1
Spam: Campaign with excessive space/char obfuscation and free file hosted link
Sublime Security
1mo ago
Jan 12th, 2026
/feeds/core/detection-rules/spam-campaign-with-excessive-spacechar-obfuscation-and-free-file-hosted-link-122bc0ca
Spam: Commonly observed formatting of unauthorized free giveaways
Sublime Security
1mo ago
Jan 14th, 2026
/feeds/core/detection-rules/spam-commonly-observed-formatting-of-unauthorized-free-giveaways-8bc49fa3
Spam: Cryptocurrency airdrop/giveaway
Sublime Security
4mo ago
Oct 16th, 2025
/feeds/core/detection-rules/spam-cryptocurrency-airdropgiveaway-80a2e2fd
Spam: Default Microsoft Exchange Online sender domain (onmicrosoft.com)
Sublime Security
1mo ago
Jan 12th, 2026
/feeds/core/detection-rules/spam-default-microsoft-exchange-online-sender-domain-onmicrosoftcom-3f2a64ce
Spam: Fake dating profile notification
Sublime Security
3mo ago
Dec 3rd, 2025
/feeds/core/detection-rules/spam-fake-dating-profile-notification-0f33fea2
Spam: Fake photo share
Sublime Security
4mo ago
Nov 8th, 2025
/feeds/core/detection-rules/spam-fake-photo-share-eb086f7d
Spam/fraud: Predatory journal/research paper request
Sublime Security
4mo ago
Nov 3rd, 2025
/feeds/core/detection-rules/spamfraud-predatory-journalresearch-paper-request-263ca56b
Spam: Ghostwriting services scam with manipulative language
Sublime Security
4mo ago
Oct 17th, 2025
/feeds/core/detection-rules/spam-ghostwriting-services-scam-with-manipulative-language-b747c3ea
Spam: Item giveaway spam template
Sublime Security
7mo ago
Aug 5th, 2025
/feeds/core/detection-rules/spam-item-giveaway-spam-template-06a5f93b
Spam: Mastercard promotional content with image-based body
Sublime Security
4mo ago
Nov 5th, 2025
/feeds/core/detection-rules/spam-mastercard-promotional-content-with-image-based-body-5f2cb559
Spam: New job cold outreach from unsolicited sender
Sublime Security
5mo ago
Sep 29th, 2025
/feeds/core/detection-rules/spam-new-job-cold-outreach-from-unsolicited-sender-ec39b789
Spam: New link domain (<=10d) and emojis
Sublime Security
7mo ago
Jul 16th, 2025
/feeds/core/detection-rules/spam-new-link-domain-less10d-and-emojis-33677993
Spam: Personalized subject and greetings via Salesforce Marketing Cloud
Sublime Security
4mo ago
Nov 3rd, 2025
/feeds/core/detection-rules/spam-personalized-subject-and-greetings-via-salesforce-marketing-cloud-c77f127f
Spam: Sendersrv.com with financial communications and unsubscribe language
Sublime Security
14d ago
Feb 24th, 2026
/feeds/core/detection-rules/spam-sendersrvcom-with-financial-communications-and-unsubscribe-language-69570820
Spam: Sexually explicit Google Drive share
Sublime Security
7mo ago
Aug 5th, 2025
/feeds/core/detection-rules/spam-sexually-explicit-google-drive-share-3f951c06
Spam: Sexually explicit Google group invitation
Sublime Security
3mo ago
Nov 12th, 2025
/feeds/core/detection-rules/spam-sexually-explicit-google-group-invitation-4e0bec29
Spam: Sexually explicit Looker Studio report
Sublime Security
5mo ago
Oct 2nd, 2025
/feeds/core/detection-rules/spam-sexually-explicit-looker-studio-report-f1e649cd
Spam: Single recipient duplicated in cc
Sublime Security
1mo ago
Jan 12th, 2026
/feeds/core/detection-rules/spam-single-recipient-duplicated-in-cc-387cacc9
Spam: SMTP & Proxy Communications in Email Body
Sublime Security
3mo ago
Dec 2nd, 2025
/feeds/core/detection-rules/spam-smtp-and-proxy-communications-in-email-body-2bdc6a3b
Spam: Unsolicited malformed PDF
Sublime Security
7mo ago
Jul 16th, 2025
/feeds/core/detection-rules/spam-unsolicited-malformed-pdf-f0c50031
Spam: URL shortener with short body content and emojis
Sublime Security
1mo ago
Jan 12th, 2026
/feeds/core/detection-rules/spam-url-shortener-with-short-body-content-and-emojis-b7797e4c
Spam: Website errors solicitation
Sublime Security
2mo ago
Dec 11th, 2025
/feeds/core/detection-rules/spam-website-errors-solicitation-122ea794
Spoofable internal domain with suspicious signals
Sublime Security
7mo ago
Jul 23rd, 2025
/feeds/core/detection-rules/spoofable-internal-domain-with-suspicious-signals-40089d69
Subject and sender display name contains matching long alphanumeric string
Sublime Security
1mo ago
Jan 12th, 2026
/feeds/core/detection-rules/subject-and-sender-display-name-contains-matching-long-alphanumeric-string-a8a0c831
Subject: Suspicious bracketed reference
Sublime Security
1mo ago
Jan 12th, 2026
/feeds/core/detection-rules/subject-suspicious-bracketed-reference-663dbce4
Suspected cross-site scripting (XSS) found in subject
Sublime Security
6mo ago
Sep 4th, 2025
/feeds/core/detection-rules/suspected-cross-site-scripting-xss-found-in-subject-8a946cfa
Suspected lookalike domain with suspicious language
Sublime Security
1mo ago
Jan 12th, 2026
/feeds/core/detection-rules/suspected-lookalike-domain-with-suspicious-language-3674ced0
Suspected WordPress abuse with cross-site scripting (XSS) indicators
Sublime Security
7mo ago
Aug 5th, 2025
/feeds/core/detection-rules/suspected-wordpress-abuse-with-cross-site-scripting-xss-indicators-9c21225b
Suspicious attachment with unscannable Cloudflare link
Sublime Security
1mo ago
Jan 12th, 2026
/feeds/core/detection-rules/suspicious-attachment-with-unscannable-cloudflare-link-00f92b6f
Suspicious DocuSign share from new domain
Sublime Security
7mo ago
Aug 5th, 2025
/feeds/core/detection-rules/suspicious-docusign-share-from-new-domain-d430a1f3