Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Jul 25th, 2026
Feed Source
Detection Method is
Rule Name & Severity
Author
Last Updated
Labels
Link: Microsoft protected message with matching sender and recipient addresses
Sublime Security
6mo ago
Jan 12th, 2026
Link: Multistage landing - Abused Adobe Acrobat hosted PDF
Sublime Security
12d ago
Jul 14th, 2026
Link: Multistage landing - Ludus presentation
Sublime Security
11mo ago
Aug 5th, 2025
Link: .onion From Unsolicited Sender
Sublime Security
12mo ago
Jul 30th, 2025
Link: PDF filename impersonation with credential theft language
Sublime Security
5mo ago
Feb 12th, 2026
Link: Personalized URL with recipient address on commonly abused web service
Sublime Security
3mo ago
Apr 1st, 2026
Link: Personal SharePoint with invalid recipients and credential theft language
Sublime Security
6mo ago
Jan 23rd, 2026
Link: Recipient domain in URL path
Sublime Security
6mo ago
Jan 12th, 2026
Link: Referrer anonymization service from untrusted sender
Sublime Security
11mo ago
Aug 5th, 2025
Link: Romance/Sexual Language With Suspicious Link
Sublime Security
1mo ago
Jun 17th, 2026
Link: Self-sender credential theft with configuration placeholder
Sublime Security
1mo ago
May 27th, 2026
Link: Self-sender with sender org in subject and credential theft indicator
Sublime Security
6mo ago
Jan 12th, 2026
Link: Self-sent message with quarterly document review request
Sublime Security
30d ago
Jun 26th, 2026
Link: Self-sent PDF lure with subject correlation
Sublime Security
1mo ago
Jun 4th, 2026
Link: SharePoint OneNote or PDF link with self sender behavior
Sublime Security
4mo ago
Feb 27th, 2026
Link: Shortened URL with fragment matching subject
Sublime Security
3mo ago
Apr 9th, 2026
Link: Single character path with credential theft body and self sender behavior or invalid recipient
Sublime Security
3mo ago
Apr 24th, 2026
Link: Squarespace infrastructure abuse
Sublime Security
11mo ago
Aug 5th, 2025
Link: Suspicious Sharepoint folder share
Sublime Security
11mo ago
Aug 5th, 2025
Link: Suspicious wp-admin path from mismatched sender domain
Sublime Security
9d ago
Jul 17th, 2026
Link: Uncommon SharePoint document type with sender's display name
Sublime Security
11mo ago
Aug 5th, 2025
macOS malware: Compiled AppleScript with document double-extension
Sublime Security
5mo ago
Feb 5th, 2026
Mass campaign: Cross Site Scripting (XSS) attempt
Sublime Security
1y ago
Jul 16th, 2025
Mass campaign: recipient address in subject, body, and link (untrusted sender)
Sublime Security
6mo ago
Jan 12th, 2026
Message traversed multiple onmicrosoft.com tenants
Sublime Security
6mo ago
Jan 12th, 2026
Microsoft infrastructure abuse with suspicious patterns
Sublime Security
6mo ago
Jan 12th, 2026
Newly registered sender or reply-to domain with newly registered linked domain
Sublime Security
11mo ago
Aug 5th, 2025
Observed IOC: Malicious reply-to domains
Sublime Security
2mo ago
Apr 27th, 2026
Observed IOC: Malicious reply-to email addresses
Sublime Security
2mo ago
Apr 27th, 2026
Observed IOC: Malicious reply-to root domains
Sublime Security
2mo ago
Apr 27th, 2026
Observed IOC: Malicious sender domains
Sublime Security
19h ago
Jul 25th, 2026
Observed IOC: Malicious sender email addresses
Sublime Security
20h ago
Jul 25th, 2026
Observed IOC: Malicious sender root domains
Sublime Security
1mo ago
Jun 12th, 2026
Open redirect: giving.lluh.org
Sublime Security
1y ago
May 23rd, 2025
Open redirect (go2.aspx) leading to Microsoft credential phishing
Sublime Security
6mo ago
Jan 12th, 2026
Open Redirect: Google domain with /url path and suspicious indicators
Sublime Security
1mo ago
Jun 5th, 2026
Open redirect: marketing.edinburghairport.com
Sublime Security
1y ago
May 23rd, 2025
Open redirect: next2.io
Sublime Security
1y ago
May 23rd, 2025
Open redirect: people.anuneo.com
Sublime Security
1y ago
May 23rd, 2025
Open redirect: queue.swytchbike.com
Sublime Security
6mo ago
Jan 12th, 2026
Open redirect: slubnaglowie.pl
Sublime Security
1y ago
May 23rd, 2025
Open redirect: Xfinity CMP Redirection to Google AMP
Sublime Security
11mo ago
Aug 5th, 2025
PayPal invoice abuse
Sublime Security
1mo ago
Jun 4th, 2026
PHP Mailer with common phishing attachments
@vector_sec
3y ago
Aug 21st, 2023
Potential prompt injection attack in body HTML
Sublime Security
6mo ago
Jan 12th, 2026
QR Code with suspicious indicators
Sublime Security
3mo ago
Apr 22nd, 2026
Reconnaissance: All recipients cc/bcc'd or undisclosed
Sublime Security
5mo ago
Feb 5th, 2026
Reconnaissance: Email address harvesting attempt
Sublime Security
5mo ago
Feb 23rd, 2026
Reconnaissance: Empty message from uncommon sender
Sublime Security
5mo ago
Feb 25th, 2026
Reconnaissance: Empty subject with mismatched reply-to from new sender
Sublime Security
5mo ago
Feb 6th, 2026