Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Jun 8th, 2026
Feed Source
Detection Method is
Rule Name & Severity
Author
Last Updated
Labels
Attachment: PDF with a suspicious string and single URL
Sublime Security
4d ago
Jun 4th, 2026
Attachment: PDF with blurry lure image
Sublime Security
3d ago
Jun 5th, 2026
Attachment: PDF with credential theft language and invalid reply-to domain
Sublime Security
1mo ago
Apr 10th, 2026
Attachment: PDF with credential theft language and link to a free subdomain (unsolicited)
Sublime Security
4mo ago
Jan 12th, 2026
Attachment: PDF with CVE-2026-34621 lures
Sublime Security
1mo ago
Apr 22nd, 2026
Attachment: PDF with eCheckRun lures
Sublime Security
3d ago
Jun 5th, 2026
Attachment: PDF with JSFck obfuscation
Sublime Security
1mo ago
Apr 22nd, 2026
Attachment: PDF with link to DMG file download
Sublime Security
4mo ago
Jan 12th, 2026
Attachment: PDF with link to zip containing a wsf file
Sublime Security
4mo ago
Jan 12th, 2026
Attachment: PDF with Microsoft Purview message impersonation
Sublime Security
7mo ago
Nov 10th, 2025
Attachment: PDF with multistage landing - ClickUp abuse
Sublime Security
3mo ago
Feb 27th, 2026
Attachment: PDF with password in filename matching body text
Sublime Security
3mo ago
Feb 19th, 2026
Attachment: PDF with personal Microsoft OneNote URL
Sublime Security
6mo ago
Dec 4th, 2025
Attachment: PDF with recipient email in link
Sublime Security
3mo ago
Mar 3rd, 2026
Attachment: PDF with ReportLab library and default metadata
Sublime Security
3mo ago
Feb 27th, 2026
Attachment: PDF With SAI Global ISO9001 Logo
Sublime Security
1mo ago
Apr 15th, 2026
Attachment: PDF with specific author metadata
Sublime Security
7d ago
Jun 1st, 2026
Attachment: PDF with split QR code
Sublime Security
1mo ago
Apr 15th, 2026
Attachment: PDF with suspicious HeadlessChrome metadata
Sublime Security
1mo ago
May 1st, 2026
Attachment: PDF with suspicious language and redirect to suspicious file type
Sublime Security
4mo ago
Jan 12th, 2026
Attachment: PDF with suspicious link and action-oriented language
Sublime Security
21d ago
May 18th, 2026
Attachment: PDF with suspicious view document characteristics
Sublime Security
1mo ago
Apr 23rd, 2026
Attachment: Potential sandbox evasion in Office file
@ajpc500
4mo ago
Jan 12th, 2026
Attachment: PowerPoint with suspicious hyperlink
Sublime Security
4mo ago
Jan 12th, 2026
Attachment: PowerShell content
@ajpc500
10mo ago
Aug 5th, 2025
Attachment: QR code link with base64-encoded recipient address
Sublime Security
1mo ago
Apr 29th, 2026
Attachment: QR code with encoded recipient targeting and redirect indicators
Sublime Security
4mo ago
Jan 30th, 2026
Attachment: QR code with recipient targeting and special characters
Sublime Security
3mo ago
Feb 21st, 2026
Attachment: QR code with suspicious URL patterns in EML file
Sublime Security
3mo ago
Feb 21st, 2026
Attachment: QR code with userinfo portion
Sublime Security
1mo ago
Apr 30th, 2026
Attachment: RDP connection file
@ajpc500
10mo ago
Aug 5th, 2025
Attachment: RFC822 containing suspicious file sharing language with links from untrusted sender
Sublime Security
7mo ago
Nov 4th, 2025
Attachment: RFP/RFQ impersonating government entities
Sublime Security
2y ago
Jan 30th, 2024
Attachment: RTF file with suspicious link
Sublime Security
10mo ago
Jul 23rd, 2025
Attachment: RTF with embedded content
@amitchell516
2y ago
Feb 26th, 2024
Attachment: Self-sender PDF with minimal content and view prompt
Sublime Security
3mo ago
Feb 12th, 2026
Attachment: SFX archive containing commands
Sublime Security
4mo ago
Jan 12th, 2026
Attachment: Small text file with link containing recipient email address
Sublime Security
25d ago
May 14th, 2026
Attachment: Soda PDF producer with encryption themes
Sublime Security
10mo ago
Aug 5th, 2025
Attachment soliciting user to enable macros
Sublime Security
4mo ago
Jan 12th, 2026
Attachment: Suspicious employee policy update document lure
Sublime Security
5mo ago
Dec 26th, 2025
Attachment: Suspicious PDF created with headless browser
Sublime Security
1mo ago
May 7th, 2026
Attachment: SVG file execution
Sublime Security
10mo ago
Aug 8th, 2025
Attachment: SVG files with evasion elements
Sublime Security
1mo ago
May 8th, 2026
Attachment: SVG file with HTML entity encoded href attributes
Sublime Security
19d ago
May 20th, 2026
Attachment: SVG file with hyperlinks and cursor styling
Sublime Security
19d ago
May 20th, 2026
Attachment: TAR file with RAR type
Sublime Security
1mo ago
Apr 24th, 2026
Attachment: Uncommon compressed file
Sublime Security
4mo ago
Jan 12th, 2026
Attachment: USDA bid invitation impersonation
Sublime Security
10mo ago
Aug 5th, 2025
Attachment: Web files with suspicious comments
Sublime Security
10mo ago
Aug 8th, 2025