Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Jul 25th, 2026
Feed Source
Detection Method is
Rule Name & Severity
Author
Last Updated
Labels
Attachment: PDF contains W9 or invoice YARA signatures
Sublime Security
4mo ago
Mar 18th, 2026
Attachment: PDF file with link to fake Bitcoin exchange
Sublime Security
6mo ago
Jan 12th, 2026
Attachment: PDF file with low reputation links to suspicious filetypes (unsolicited)
Sublime Security
6mo ago
Jan 12th, 2026
Attachment: PDF file with low reputation link to ZIP file (unsolicited)
Michael Tingle
6mo ago
Jan 12th, 2026
Attachment: PDF file with recipient domain and ATT eCheckRun pattern
Sublime Security
1mo ago
Jun 16th, 2026
Attachment: PDF generated with wkhtmltopdf tool and default title
Sublime Security
7mo ago
Dec 19th, 2025
Attachment: PDF Object Hash associated with a fake invoice and a W-9
Sublime Security
24d ago
Jul 2nd, 2026
Attachment: PDF Object Hash associated with fake Canada Revenue Agency documents
Sublime Security
1mo ago
Jun 17th, 2026
Attachment: PDF Object Hash - Encrypted PDFs with fake payment notification
Sublime Security
4mo ago
Mar 2nd, 2026
Attachment: PDF Object Hash with Blue File Icon
Sublime Security
1mo ago
Jun 5th, 2026
Attachment: PDF proposal with credential theft indicators
Sublime Security
4mo ago
Mar 17th, 2026
Attachment: PDF with a suspicious string and single URL
Sublime Security
1mo ago
Jun 17th, 2026
Attachment: PDF with blurry lure image
Sublime Security
1mo ago
Jun 5th, 2026
Attachment: PDF with credential theft language and invalid reply-to domain
Sublime Security
3mo ago
Apr 10th, 2026
Attachment: PDF with credential theft language and link to a free subdomain (unsolicited)
Sublime Security
6mo ago
Jan 12th, 2026
Attachment: PDF with CVE-2026-34621 lures
Sublime Security
3mo ago
Apr 22nd, 2026
Attachment: PDF with eCheckRun lures
Sublime Security
1mo ago
Jun 5th, 2026
Attachment: PDF with fake invoice using suspicious font sizing
Sublime Security
1mo ago
Jun 9th, 2026
Attachment: PDF with JSFck obfuscation
Sublime Security
3mo ago
Apr 22nd, 2026
Attachment: PDF with link to DMG file download
Sublime Security
6mo ago
Jan 12th, 2026
Attachment: PDF with link to zip containing a wsf file
Sublime Security
6mo ago
Jan 12th, 2026
Attachment: PDF with localhost IP in EXIF title metadata
Sublime Security
27d ago
Jun 29th, 2026
Attachment: PDF with Microsoft Purview message impersonation
Sublime Security
8mo ago
Nov 10th, 2025
Attachment: PDF with multistage landing - ClickUp abuse
Sublime Security
4mo ago
Feb 27th, 2026
Attachment: PDF with password in filename matching body text
Sublime Security
5mo ago
Feb 19th, 2026
Attachment: PDF with personal Microsoft OneNote URL
Sublime Security
7mo ago
Dec 4th, 2025
Attachment: PDF with QR code containing recipient-specific credential theft content
Sublime Security
1mo ago
Jun 10th, 2026
Attachment: PDF with quote lure
Sublime Security
25d ago
Jul 1st, 2026
Attachment: PDF with recipient email in link
Sublime Security
1mo ago
Jun 10th, 2026
Attachment: PDF with ReportLab library and default metadata
Sublime Security
4mo ago
Feb 27th, 2026
Attachment: PDF With SAI Global ISO9001 Logo
Sublime Security
3mo ago
Apr 15th, 2026
Attachment: PDF with secure document acknowledgment prompt
Sublime Security
9d ago
Jul 17th, 2026
Attachment: PDF with self-service platform links with self sender or blank recipients
Sublime Security
1mo ago
Jun 10th, 2026
Attachment: PDF with specific author metadata
Sublime Security
1mo ago
Jun 1st, 2026
Attachment: PDF with specific W-9 lure
Sublime Security
25d ago
Jul 1st, 2026
Attachment: PDF with split QR code
Sublime Security
3mo ago
Apr 15th, 2026
Attachment: PDF with suspicious document view lure
Sublime Security
12d ago
Jul 14th, 2026
Attachment: PDF with suspicious HeadlessChrome metadata
Sublime Security
2mo ago
May 1st, 2026
Attachment: PDF with suspicious internal object reference identifier
Sublime Security
27d ago
Jun 29th, 2026
Attachment: PDF with suspicious language and redirect to suspicious file type
Sublime Security
6mo ago
Jan 12th, 2026
Attachment: PDF with suspicious link and action-oriented language
Sublime Security
2mo ago
May 18th, 2026
Attachment: PDF with suspicious view document characteristics
Sublime Security
3mo ago
Apr 23rd, 2026
Attachment: PDF with W-9 form indicators
Sublime Security
30d ago
Jun 26th, 2026
Attachment: Potential sandbox evasion in Office file
@ajpc500
6mo ago
Jan 12th, 2026
Attachment: PowerPoint with suspicious hyperlink
Sublime Security
6mo ago
Jan 12th, 2026
Attachment: PowerShell content
@ajpc500
11mo ago
Aug 5th, 2025
Attachment: QR code link with base64-encoded recipient address
Sublime Security
2mo ago
Apr 29th, 2026
Attachment: QR code with encoded recipient targeting and redirect indicators
Sublime Security
5mo ago
Jan 30th, 2026
Attachment: QR code with recipient targeting and special characters
Sublime Security
5mo ago
Feb 21st, 2026
Attachment: QR code with suspicious URL patterns in EML file
Sublime Security
5mo ago
Feb 21st, 2026