Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Sep 9th, 2026
Feed Source
Detection Method is
Rule Name & Severity
Author
Last Updated
Labels
Job scam (unsolicited sender)
Sublime Security
10mo ago
Nov 3rd, 2025
Job scam with specific salary pattern
Sublime Security
21d ago
Aug 20th, 2026
Link abuse: Self-service creation platform link with suspicious recipient behavior
Sublime Security
9mo ago
Dec 2nd, 2025
Link: Base64 encoded recipient address in URL fragment with subject hash
Sublime Security
8mo ago
Jan 12th, 2026
Link: BEC with newly registered domains and financial keywords
Sublime Security
4mo ago
May 1st, 2026
Link: Credential phishing link with undisclosed recipients
Sublime Security
17d ago
Aug 24th, 2026
Link: Credential phishing traversing Russian infrastructure
Sublime Security
1y ago
Aug 5th, 2025
Link: Credential phishing via WordPress
Sublime Security
1y ago
Aug 5th, 2025
Link: Cryptocurrency fraud with suspicious links
Sublime Security
9mo ago
Dec 1st, 2025
Link: Direct link to riddle.com hosted showcase
Sublime Security
8mo ago
Jan 12th, 2026
Link: Direct link to Zoom Docs from non-Zoom sender
Sublime Security
1y ago
Aug 5th, 2025
Link: Display text matches subject line
Sublime Security
9mo ago
Nov 14th, 2025
Link: Executable file download with suspicious message content
Sublime Security
10mo ago
Oct 16th, 2025
Link: Fake RFP/bid reference number lure
Sublime Security
16d ago
Aug 25th, 2026
Link: File sharing impersonation with suspicious language and sending patterns
Sublime Security
4mo ago
Apr 30th, 2026
Link: Free file hosting with undisclosed recipients
Sublime Security
5mo ago
Mar 19th, 2026
Link: Free subdomain host with undisclosed recipients
Sublime Security
8mo ago
Jan 12th, 2026
Link: Generic financial document with proceedural timeline template
Sublime Security
2mo ago
Jul 10th, 2026
Link: Intuit link abuse with file share context
Sublime Security
8mo ago
Jan 12th, 2026
Link: Invalid reply-to with recipient details in subject, body, and encoded link
Sublime Security
1mo ago
Jul 16th, 2026
Link: Microsoft protected message with suspicious recipient patterns
Sublime Security
14d ago
Aug 27th, 2026
Link: Mismatched Shopify template button href
Sublime Security
21d ago
Aug 20th, 2026
Link: Multistage landing - Abused Adobe Acrobat hosted PDF
Sublime Security
1mo ago
Jul 14th, 2026
Link: Multistage landing - Ludus presentation
Sublime Security
1y ago
Aug 5th, 2025
Link: .onion From Unsolicited Sender
Sublime Security
1y ago
Jul 30th, 2025
Link: PDF filename impersonation with credential theft language
Sublime Security
6mo ago
Feb 12th, 2026
Link: Personalized URL with recipient address on commonly abused web service
Sublime Security
5mo ago
Apr 1st, 2026
Link: Personal SharePoint with invalid recipients and credential theft language
Sublime Security
7mo ago
Jan 23rd, 2026
Link: Recipient domain in URL path
Sublime Security
8mo ago
Jan 12th, 2026
Link: Referrer anonymization service from untrusted sender
Sublime Security
1y ago
Aug 5th, 2025
Link: Romance/Sexual Language With Suspicious Link
Sublime Security
2mo ago
Jun 17th, 2026
Link: Self-sender credential theft with configuration placeholder
Sublime Security
3mo ago
May 27th, 2026
Link: Self-sender with sender org in subject and credential theft indicator
Sublime Security
16d ago
Aug 25th, 2026
Link: Self-sent message with quarterly document review request
Sublime Security
2mo ago
Jun 26th, 2026
Link: Self-sent PDF lure with subject correlation
Sublime Security
3mo ago
Jun 4th, 2026
Link: SharePoint OneNote or PDF link with self sender behavior
Sublime Security
6mo ago
Feb 27th, 2026
Link: Shortened URL with fragment matching subject
Sublime Security
5mo ago
Apr 9th, 2026
Link: Single character path with credential theft body and self sender behavior or invalid recipient
Sublime Security
4mo ago
Apr 24th, 2026
Link: Squarespace infrastructure abuse
Sublime Security
1y ago
Aug 5th, 2025
Link: Suspicious Sharepoint folder share
Sublime Security
1y ago
Aug 5th, 2025
Link: Suspicious wp-admin path from mismatched sender domain
Sublime Security
1mo ago
Jul 17th, 2026
Link: Uncommon SharePoint document type with sender's display name
Sublime Security
1y ago
Aug 5th, 2025
macOS malware: Compiled AppleScript with document double-extension
Sublime Security
7mo ago
Feb 5th, 2026
Mass campaign: Cross Site Scripting (XSS) attempt
Sublime Security
1y ago
Jul 16th, 2025
Mass campaign: recipient address in subject, body, and link (untrusted sender)
Sublime Security
8mo ago
Jan 12th, 2026
Message traversed multiple onmicrosoft.com tenants
Sublime Security
8mo ago
Jan 12th, 2026
Microsoft infrastructure abuse with suspicious patterns
Sublime Security
8mo ago
Jan 12th, 2026
Newly registered sender or reply-to domain with newly registered linked domain
Sublime Security
1y ago
Aug 5th, 2025
Observed IOC: Mail transiting bulletproof host - SmartApe
Sublime Security
14d ago
Aug 27th, 2026
Observed IOC: Mail transiting OFAC-sanctioned bulletproof host Aeza Group
Sublime Security
2d ago
Sep 8th, 2026