Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Jun 8th, 2026
Feed Source
Detection Method is
Rule Name & Severity
Author
Last Updated
Labels
Service abuse: Adobe Creative Cloud share from an unsolicited sender address
Sublime Security
7mo ago
Oct 22nd, 2025
Service abuse: Amazon invitation with suspected callback phishing
Sublime Security
18d ago
May 22nd, 2026
Service abuse: Apple TestFlight with suspicious developer reference
Sublime Security
4mo ago
Feb 6th, 2026
Service abuse: Google Firebase sender address with suspicious content
Sublime Security
2mo ago
Apr 2nd, 2026
Service abuse: HelloSign from an unsolicited sender address
Sublime Security
10mo ago
Aug 5th, 2025
Service abuse: HungerRush domain with SendGrid tracking targeting ProtonMail
Sublime Security
3mo ago
Mar 4th, 2026
Service abuse: Meetup.com redirect with brand impersonation
Sublime Security
1mo ago
Apr 15th, 2026
Service abuse: Substack credential theft with confusable characters and branded button redirects
Sublime Security
2mo ago
Mar 19th, 2026
Service abuse: Suspicious Zoom Docs link
Sublime Security
6mo ago
Dec 2nd, 2025
Service abuse: Trello board invitation with VIP impersonation
Sublime Security
4mo ago
Feb 3rd, 2026
Sharepoint link likely unrelated to sender
Sublime Security
4mo ago
Jan 12th, 2026
Spam: Commonly observed formatting of unauthorized free giveaways
Sublime Security
4mo ago
Jan 14th, 2026
Spam: Item giveaway spam template
Sublime Security
10mo ago
Aug 5th, 2025
URI protocol handler: search-ms
Sublime Security
4mo ago
Jan 12th, 2026
Venmo payment request abuse
Sublime Security
1mo ago
May 4th, 2026
Zoom Events newsletter abuse
Sublime Security
4mo ago
Jan 12th, 2026