Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Apr 24th, 2026
Feed Source
Detection Method is
Rule Name & Severity
Author
Last Updated
Labels
Adobe branded PDF file linking to a password-protected file from untrusted sender
Sublime Security
9mo ago
Jul 16th, 2025
Attachment: 7z Archive Containing RAR File
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: Any HTML file (unsolicited)
Sublime Security
5mo ago
Nov 3rd, 2025
Attachment: Any HTML file within archive (unsolicited)
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: Any .sap file (unsolicited)
Sublime Security
5mo ago
Oct 27th, 2025
Attachment: Archive containing disallowed file type
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: Archive containing HTML file with file scheme link
Sublime Security
1mo ago
Mar 17th, 2026
Attachment: Archive contains DLL-loading macro
Sublime Security
3y ago
Dec 28th, 2023
Attachment: Archive with embedded CHM file
Sublime Security
3y ago
Aug 21st, 2023
Attachment: Archive with embedded EXE file
Sublime Security
2y ago
Feb 27th, 2024
Attachment: Archive with pdf, txt and wsf files
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: Base64 encoded bash command in filename
@vector_sec
7mo ago
Sep 5th, 2025
Attachment: Calendar file with invisible Unicode characters
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: Calendar invite from recently registered domain
Sublime Security
7mo ago
Sep 25th, 2025
Attachment: Calendar invite with Google redirect and invoice request
Sublime Security
16d ago
Apr 8th, 2026
Attachment: Callback phishing solicitation via pdf file
Sublime Security
8mo ago
Aug 5th, 2025
Attachment: Callback phishing solicitation via text-based file
Sublime Security
7mo ago
Sep 22nd, 2025
Attachment: cmd file extension
Sublime Security
2mo ago
Feb 9th, 2026
Attachment: Cold outreach with invitation subject and not attachment
Sublime Security
21d ago
Apr 3rd, 2026
Attachment: Compensation review lure with QR code
Sublime Security
10d ago
Apr 14th, 2026
Attachment: Credit card application with WhatsApp contact
Sublime Security
5mo ago
Nov 20th, 2025
Attachment: .csproj with suspicious commands
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: CVE-2021-40444 - MSHTML Remote Code Execution Vulnerability
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: CVE-2023-21716 - Microsoft Office Remote Code Execution Vulnerability
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: CVE-2025-24071 - Microsoft Windows File Explorer Spoofing Vulnerability
Sublime Security
1y ago
Mar 21st, 2025
Attachment: Decoy PDF author (Julie P.)
Sublime Security
8mo ago
Aug 5th, 2025
Attachment: DocuSign impersonation via PDF linking to new domain
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: DOCX with hyperlink targeting recipient address
Sublime Security
4mo ago
Dec 17th, 2025
Attachment: Double base64-encoded zip file in HTML smuggling attachment
@ajpc500
8mo ago
Aug 5th, 2025
Attachment: Dropbox image lure with no Dropbox domains in links
Sublime Security
9mo ago
Jul 16th, 2025
Attachment: EICAR string present
@ajpc500
8mo ago
Aug 5th, 2025
Attachment: Embedded Javascript in SVG file
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: Embedded VBScript in MHT file (unsolicited)
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: EML containing a base64 encoded script
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: EML file contains HTML attachment with login portal indicators
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: EML file with HTML attachment (unsolicited)
Sublime Security
8mo ago
Aug 20th, 2025
Attachment: EML file with IPFS links
Sublime Security
5mo ago
Nov 4th, 2025
Attachment: EML with embedded Javascript in SVG file
Sublime Security
8mo ago
Aug 8th, 2025
Attachment: EML with Encrypted ZIP
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: EML with link to credential phishing page
Sublime Security
9mo ago
Jul 16th, 2025
Attachment: EML with QR code redirecting to Cloudflare challenges
Sublime Security
23d ago
Apr 1st, 2026
Attachment: EML with SharePoint files shared from GoDaddy federated tenants
Sublime Security
7mo ago
Sep 23rd, 2025
Attachment: EML with Sharepoint link likely unrelated to sender
Sublime Security
7mo ago
Sep 23rd, 2025
Attachment: EML with suspicious indicators
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: Emotet heavily padded doc in zip file
Sublime Security
9mo ago
Jul 16th, 2025
Attachment: Employment contract update with suspicious file naming
Sublime Security
2mo ago
Jan 28th, 2026
Attachment: Encrypted Microsoft Office file (unsolicited)
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: Encrypted PDF with credential theft body
Sublime Security
15d ago
Apr 9th, 2026
Attachment: Encrypted ZIP containing VHDX file
Sublime Security
21d ago
Apr 3rd, 2026
Attachment: Encrypted zip file with payment-related lure
Sublime Security
5mo ago
Nov 25th, 2025