• Sublime Core Feed

Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Jan 23rd, 2026
Feed Source
Detection Method is
Rule Name & Severity
Author
Last Updated
Labels
Adobe branded PDF file linking to a password-protected file from untrusted sender
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/adobe-branded-pdf-file-linking-to-a-password-protected-file-from-untrusted-sender-5ea75469
Attachment: 7z Archive Containing RAR File
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/attachment-7z-archive-containing-rar-file-1a629bb4
Attachment: Any HTML file (unsolicited)
Sublime Security
2mo ago
Nov 3rd, 2025
/feeds/core/detection-rules/attachment-any-html-file-unsolicited-ef36763f
Attachment: Any HTML file within archive (unsolicited)
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/attachment-any-html-file-within-archive-unsolicited-6a67c02c
Attachment: Any .sap file (unsolicited)
Sublime Security
2mo ago
Oct 27th, 2025
/feeds/core/detection-rules/attachment-any-sap-file-unsolicited-220ed3de
Attachment: Archive containing disallowed file type
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/attachment-archive-containing-disallowed-file-type-3859e3e7
Attachment: Archive containing HTML file with file scheme link
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/attachment-archive-containing-html-file-with-file-scheme-link-edf6d0d9
Attachment: Archive contains DLL-loading macro
Sublime Security
3y ago
Dec 28th, 2023
/feeds/core/detection-rules/attachment-archive-contains-dll-loading-macro-3a193f5f
Attachment: Archive with embedded CHM file
Sublime Security
3y ago
Aug 21st, 2023
/feeds/core/detection-rules/attachment-archive-with-embedded-chm-file-5280e94d
Attachment: Archive with embedded EXE file
Sublime Security
2y ago
Feb 27th, 2024
/feeds/core/detection-rules/attachment-archive-with-embedded-exe-file-e2b0ad86
Attachment: Archive with pdf, txt and wsf files
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/attachment-archive-with-pdf-txt-and-wsf-files-16b2e239
Attachment: Base64 encoded bash command in filename
@vector_sec
4mo ago
Sep 5th, 2025
/feeds/core/detection-rules/attachment-base64-encoded-bash-command-in-filename-819f69c8
Attachment: Calendar file with invisible Unicode characters
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/attachment-calendar-file-with-invisible-unicode-characters-050fceac
Attachment: Calendar invite from recently registered domain
Sublime Security
4mo ago
Sep 25th, 2025
/feeds/core/detection-rules/attachment-calendar-invite-from-recently-registered-domain-d801521c
Attachment: Callback phishing solicitation via pdf file
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/attachment-callback-phishing-solicitation-via-pdf-file-ac33f097
Attachment: Callback phishing solicitation via text-based file
Sublime Security
4mo ago
Sep 22nd, 2025
/feeds/core/detection-rules/attachment-callback-phishing-solicitation-via-text-based-file-ca39c83a
Attachment: Compensation review lure with QR code
Sublime Security
1mo ago
Dec 10th, 2025
/feeds/core/detection-rules/attachment-compensation-review-lure-with-qr-code-9fd8185c
Attachment: Credit card application with WhatsApp contact
Sublime Security
2mo ago
Nov 20th, 2025
/feeds/core/detection-rules/attachment-credit-card-application-with-whatsapp-contact-95b08315
Attachment: .csproj with suspicious commands
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/attachment-csproj-with-suspicious-commands-fe45b81d
Attachment: CVE-2021-40444 - MSHTML Remote Code Execution Vulnerability
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/attachment-cve-2021-40444-mshtml-remote-code-execution-vulnerability-8cefcf7f
Attachment: CVE-2023-21716 - Microsoft Office Remote Code Execution Vulnerability
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/attachment-cve-2023-21716-microsoft-office-remote-code-execution-vulnerability-23714cca
Attachment: CVE-2025-24071 - Microsoft Windows File Explorer Spoofing Vulnerability
Sublime Security
10mo ago
Mar 21st, 2025
/feeds/core/detection-rules/attachment-cve-2025-24071-microsoft-windows-file-explorer-spoofing-vulnerability-2e69fa0b
Attachment: Decoy PDF author (Julie P.)
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/attachment-decoy-pdf-author-julie-p-4324213a
Attachment: DocuSign impersonation via PDF linking to new domain
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/attachment-docusign-impersonation-via-pdf-linking-to-new-domain-f0c96282
Attachment: DOCX with hyperlink targeting recipient address
Sublime Security
1mo ago
Dec 17th, 2025
/feeds/core/detection-rules/attachment-docx-with-hyperlink-targeting-recipient-address-9ec8fa49
Attachment: Double base64-encoded zip file in HTML smuggling attachment
@ajpc500
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/attachment-double-base64-encoded-zip-file-in-html-smuggling-attachment-61ebb07b
Attachment: Dropbox image lure with no Dropbox domains in links
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/attachment-dropbox-image-lure-with-no-dropbox-domains-in-links-500eee2d
Attachment: EICAR string present
@ajpc500
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/attachment-eicar-string-present-592e2319
Attachment: Embedded Javascript in SVG file
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/attachment-embedded-javascript-in-svg-file-f70293bc
Attachment: Embedded VBScript in MHT file (unsolicited)
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/attachment-embedded-vbscript-in-mht-file-unsolicited-b30353a6
Attachment: EML containing a base64 encoded script
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/attachment-eml-containing-a-base64-encoded-script-fc3d9445
Attachment: EML file contains HTML attachment with login portal indicators
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/attachment-eml-file-contains-html-attachment-with-login-portal-indicators-6e4df158
Attachment: EML file with HTML attachment (unsolicited)
Sublime Security
5mo ago
Aug 20th, 2025
/feeds/core/detection-rules/attachment-eml-file-with-html-attachment-unsolicited-c24fd191
Attachment: EML file with IPFS links
Sublime Security
2mo ago
Nov 4th, 2025
/feeds/core/detection-rules/attachment-eml-file-with-ipfs-links-1fe9d7e7
Attachment: EML with embedded Javascript in SVG file
Sublime Security
5mo ago
Aug 8th, 2025
/feeds/core/detection-rules/attachment-eml-with-embedded-javascript-in-svg-file-dfafb78f
Attachment: EML with Encrypted ZIP
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/attachment-eml-with-encrypted-zip-6897a8f7
Attachment: EML with link to credential phishing page
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/attachment-eml-with-link-to-credential-phishing-page-1df41cca
Attachment: EML with SharePoint files shared from GoDaddy federated tenants
Sublime Security
4mo ago
Sep 23rd, 2025
/feeds/core/detection-rules/attachment-eml-with-sharepoint-files-shared-from-godaddy-federated-tenants-02c1f590
Attachment: EML with Sharepoint link likely unrelated to sender
Sublime Security
4mo ago
Sep 23rd, 2025
/feeds/core/detection-rules/attachment-eml-with-sharepoint-link-likely-unrelated-to-sender-0a4fd31b
Attachment: EML with suspicious indicators
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/attachment-eml-with-suspicious-indicators-deb5d08d
Attachment: Emotet heavily padded doc in zip file
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/attachment-emotet-heavily-padded-doc-in-zip-file-9a5332ed
Attachment: Encrypted Microsoft Office file (unsolicited)
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/attachment-encrypted-microsoft-office-file-unsolicited-1e47e953
Attachment: Encrypted PDF with credential theft body
Sublime Security
1mo ago
Dec 1st, 2025
/feeds/core/detection-rules/attachment-encrypted-pdf-with-credential-theft-body-c9596c9a
Attachment: Encrypted zip file with payment-related lure
Sublime Security
1mo ago
Nov 25th, 2025
/feeds/core/detection-rules/attachment-encrypted-zip-file-with-payment-related-lure-5d1eb7af
Attachment: Excel file with suspicious template identifier
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/attachment-excel-file-with-suspicious-template-identifier-40f84b4b
Attachment: Excel Web Query File (IQY)
@jkcoote
3y ago
Aug 21st, 2023
/feeds/core/detection-rules/attachment-excel-web-query-file-iqy-510412b5
Attachment: Fake attachment image lure
Sublime Security
4mo ago
Sep 22nd, 2025
/feeds/core/detection-rules/attachment-fake-attachment-image-lure-96b8b285
Attachment: Fake scan-to-email
Sublime Security
4mo ago
Sep 22nd, 2025
/feeds/core/detection-rules/attachment-fake-scan-to-email-ea850cc1
Attachment: Fake secure message and suspicious indicators
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/attachment-fake-secure-message-and-suspicious-indicators-20a34d94
Attachment: Fake Slack installer
Sublime Security
3y ago
Nov 29th, 2023
/feeds/core/detection-rules/attachment-fake-slack-installer-cded2d2f