Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Sep 9th, 2026
Feed Source
Detection Method is
Rule Name & Severity
Author
Last Updated
Labels
Attachment: PDF with secure document acknowledgment prompt
Sublime Security
1mo ago
Jul 17th, 2026
Attachment: PDF with self-service platform links with self sender or blank recipients
Sublime Security
3mo ago
Jun 10th, 2026
Attachment: PDF with specific author metadata
Sublime Security
3mo ago
Jun 1st, 2026
Attachment: PDF with specific W-9 lure
Sublime Security
2mo ago
Jul 1st, 2026
Attachment: PDF with split QR code
Sublime Security
4mo ago
Apr 15th, 2026
Attachment: PDF with suspicious document view lure
Sublime Security
1mo ago
Jul 14th, 2026
Attachment: PDF with suspicious HeadlessChrome metadata
Sublime Security
17d ago
Aug 24th, 2026
Attachment: PDF with suspicious internal object reference identifier
Sublime Security
2mo ago
Jun 29th, 2026
Attachment: PDF with suspicious language and redirect to suspicious file type
Sublime Security
8mo ago
Jan 12th, 2026
Attachment: PDF with suspicious link and action-oriented language
Sublime Security
23d ago
Aug 18th, 2026
Attachment: PDF with suspicious view document characteristics
Sublime Security
4mo ago
Apr 23rd, 2026
Attachment: PDF with View RFP Document lure with external link
Sublime Security
14d ago
Aug 27th, 2026
Attachment: PDF with W-9 form indicators
Sublime Security
2mo ago
Jun 26th, 2026
Attachment: Potential sandbox evasion in Office file
@ajpc500
8mo ago
Jan 12th, 2026
Attachment: PowerPoint with suspicious hyperlink
Sublime Security
8mo ago
Jan 12th, 2026
Attachment: PowerShell content
@ajpc500
1y ago
Aug 5th, 2025
Attachment: QR code link with base64-encoded recipient address
Sublime Security
4mo ago
Apr 29th, 2026
Attachment: QR code with encoded recipient targeting and redirect indicators
Sublime Security
7mo ago
Jan 30th, 2026
Attachment: QR code with recipient targeting and special characters
Sublime Security
6mo ago
Feb 21st, 2026
Attachment: QR code with suspicious URL patterns in EML file
Sublime Security
6mo ago
Feb 21st, 2026
Attachment: QR code with userinfo portion
Sublime Security
4mo ago
Apr 30th, 2026
Attachment: QuickBooks PDF lure
Sublime Security
21d ago
Aug 20th, 2026
Attachment: RDP connection file
@ajpc500
1y ago
Aug 5th, 2025
Attachment: RFC822 containing suspicious file sharing language with links from untrusted sender
Sublime Security
10mo ago
Nov 4th, 2025
Attachment: RFP/RFQ impersonating government entities
Sublime Security
2y ago
Jan 30th, 2024
Attachment: Risk assessment PDF with inline image
Sublime Security
16d ago
Aug 25th, 2026
Attachment: Romance scam with image lure and advance-fee or suspicious link indicators
Sublime Security
2mo ago
Jul 1st, 2026
Attachment: RTF file with suspicious link
Sublime Security
1y ago
Jul 23rd, 2025
Attachment: RTF with embedded content
@amitchell516
2y ago
Feb 26th, 2024
Attachment: RTF with link to free-hosted Cloudflare Pages
Sublime Security
28d ago
Aug 13th, 2026
Attachment: Self-sender PDF with minimal content and view prompt
Sublime Security
6mo ago
Feb 12th, 2026
Attachment: SFX archive containing commands
Sublime Security
8mo ago
Jan 12th, 2026
Attachment: Single-page PDF with S3-hosted HTML link
Sublime Security
1mo ago
Jul 16th, 2026
Attachment: Small text file with link containing recipient email address
Sublime Security
3mo ago
May 14th, 2026
Attachment: Soda PDF producer with encryption themes
Sublime Security
1y ago
Aug 5th, 2025
Attachment soliciting user to enable macros
Sublime Security
8mo ago
Jan 12th, 2026
Attachment: Suspicious employee policy update document lure
Sublime Security
8mo ago
Dec 26th, 2025
Attachment: Suspicious PDF created with headless browser
Sublime Security
2mo ago
Jul 1st, 2026
Attachment: SVG file execution
Sublime Security
1y ago
Aug 8th, 2025
Attachment: SVG files with evasion elements
Sublime Security
4mo ago
May 8th, 2026
Attachment: SVG file with HTML entity encoded href attributes
Sublime Security
3mo ago
May 20th, 2026
Attachment: SVG file with hyperlinks and cursor styling
Sublime Security
3mo ago
May 20th, 2026
Attachment: TAR file with RAR type
Sublime Security
4mo ago
Apr 24th, 2026
Attachment: Targeted DOCX with personalized recipient acknowledgement lure
Sublime Security
1mo ago
Aug 4th, 2026
Attachment: Uncommon compressed file
Sublime Security
8mo ago
Jan 12th, 2026
Attachment: USDA bid invitation impersonation
Sublime Security
1y ago
Aug 5th, 2025
Attachment: Web files with suspicious comments
Sublime Security
1y ago
Aug 8th, 2025
Attachment: WinRAR CVE-2025-8088 exploitation
Sublime Security
8mo ago
Jan 12th, 2026
Attachment with auto-executing macro (unsolicited)
Sublime Security
3mo ago
Jun 5th, 2026
Attachment with auto-opening VBA macro (unsolicited)
Sublime Security
8mo ago
Jan 12th, 2026