Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Apr 24th, 2026
Feed Source
Detection Method is
Rule Name & Severity
Author
Last Updated
Labels
Attachment: ICS calendar file with QR code containing recipient email address
Sublime Security
4d ago
Apr 20th, 2026
Attachment: ICS calendar file with recipient address in UID field
Sublime Security
4d ago
Apr 20th, 2026
Attachment: ICS calendar with embedded file from internal sender with SPF failure
Sublime Security
6mo ago
Oct 22nd, 2025
Attachment: ICS file with AWS Lambda URL
Sublime Security
23d ago
Apr 1st, 2026
Attachment: ICS file with excessive custom properties
Sublime Security
1mo ago
Mar 17th, 2026
Attachment: ICS file with links to newly registered domains
Sublime Security
4d ago
Apr 20th, 2026
Attachment: ICS file with meeting prefix
Sublime Security
2mo ago
Jan 26th, 2026
Attachment: ICS file with non-Gregorian calendar scale
Sublime Security
5mo ago
Nov 4th, 2025
Attachment: ICS with embedded document
Sublime Security
7mo ago
Sep 22nd, 2025
Attachment: ICS with embedded Javascript in SVG file
Sublime Security
2mo ago
Jan 29th, 2026
Attachment: ICS with employee policy review lure
Sublime Security
1mo ago
Mar 16th, 2026
Attachment: Invoice and W-9 PDFs with suspicious creators
Sublime Security
3mo ago
Jan 21st, 2026
Attachment: JavaScript file with suspicious base64-encoded executable
Sublime Security
2y ago
Apr 1st, 2024
Attachment: Legal themed message or PDF with suspicious indicators
Sublime Security
21d ago
Apr 3rd, 2026
Attachment: Link file with UNC path
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: Link to Doubleclick.net open redirect
Sublime Security
8mo ago
Aug 5th, 2025
Attachment: LNK file
@ajpc500
3y ago
Aug 21st, 2023
Attachment: LNK with embedded content
@ajpc500
3mo ago
Jan 12th, 2026
Attachment: Macro files containing MHT content
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: Macro with suspected use of COM ShellBrowserWindow object for process creation
@ajpc500
3mo ago
Jan 12th, 2026
Attachment: Malformed OLE file
Sublime Security
2y ago
Nov 25th, 2024
Attachment: Malicious OneNote commands
@Kyle_Parrish_
3mo ago
Jan 12th, 2026
Attachment: Microsoft 365 credential phishing
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: Microsoft impersonation via PDF with link and suspicious language
Sublime Security
9mo ago
Jul 16th, 2025
Attachment: MSI installer file
@ajpc500
8mo ago
Aug 5th, 2025
Attachment: MS Office or RTF file with Shell.Explorer.1 com object with embedded LNK
Sublime Security
2mo ago
Jan 28th, 2026
Attachment: Office document loads remote document template
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: Office document with VSTO add-in
@vector_sec
3mo ago
Jan 12th, 2026
Attachment: Office file contains OLE relationship to credential phishing page
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: Office file with credential phishing URLs
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: Office file with document sharing and browser instruction lures
Sublime Security
2mo ago
Jan 29th, 2026
Attachment: Office file with suspicious function calls or downloaded file path
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: Password-protected PDF with fake document indicators
Sublime Security
3mo ago
Jan 21st, 2026
Attachment: PDF bid/proposal lure with credential theft indicators
Sublime Security
28d ago
Mar 27th, 2026
Attachment: PDF contains W9 or invoice YARA signatures
Sublime Security
1mo ago
Mar 18th, 2026
Attachment: PDF file with link to fake Bitcoin exchange
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: PDF file with low reputation links to suspicious filetypes (unsolicited)
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: PDF file with low reputation link to ZIP file (unsolicited)
Michael Tingle
3mo ago
Jan 12th, 2026
Attachment: PDF generated with wkhtmltopdf tool and default title
Sublime Security
4mo ago
Dec 19th, 2025
Attachment: PDF Object Hash - Encrypted PDFs with fake payment notification
Sublime Security
1mo ago
Mar 2nd, 2026
Attachment: PDF proposal with credential theft indicators
Sublime Security
1mo ago
Mar 17th, 2026
Attachment: PDF with a suspicious string and single URL
Sublime Security
14d ago
Apr 10th, 2026
Attachment: PDF with credential theft language and invalid reply-to domain
Sublime Security
14d ago
Apr 10th, 2026
Attachment: PDF with credential theft language and link to a free subdomain (unsolicited)
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: PDF with CVE-2026-34621 lures
Sublime Security
2d ago
Apr 22nd, 2026
Attachment: PDF with JSFck obfuscation
Sublime Security
2d ago
Apr 22nd, 2026
Attachment: PDF with link to DMG file download
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: PDF with link to zip containing a wsf file
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: PDF with Microsoft Purview message impersonation
Sublime Security
5mo ago
Nov 10th, 2025
Attachment: PDF with multistage landing - ClickUp abuse
Sublime Security
1mo ago
Feb 27th, 2026