Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Jul 27th, 2026
Feed Source
Detection Method is
Rule Name & Severity
Author
Last Updated
Labels
Reconnaissance: Hotel booking reply-to redirect
Sublime Security
6mo ago
Jan 27th, 2026
Reconnaissance: Large unknown recipient list
Sublime Security
8mo ago
Nov 24th, 2025
Reconnaissance: Short generic greeting message
Sublime Security
1mo ago
Jun 17th, 2026
Russia return-path TLD (untrusted sender)
Sublime Security
5mo ago
Feb 13th, 2026
Salesforce infrastructure abuse
Sublime Security
6mo ago
Jan 12th, 2026
Scam: Fake estate sale offering welding equipment and tools
Sublime Security
2mo ago
May 12th, 2026
Scam soliciting employer review/rating
Sublime Security
1mo ago
Jun 12th, 2026
Self-impersonation: Sender matches recipient with bolded name and suspicious link
Sublime Security
1mo ago
Jun 16th, 2026
Self-sender with copy/paste instructions and suspicious domains (French/Français)
Sublime Security
3mo ago
Apr 16th, 2026
Sendgrid onmicrosoft.com domain phishing
@ajpc500
6mo ago
Jan 12th, 2026
Sendgrid voicemail phish
Sublime Security
8mo ago
Nov 24th, 2025
Service abuse: Adobe Creative Cloud share from an unsolicited sender address
Sublime Security
9mo ago
Oct 22nd, 2025
Service abuse: Adobe legitimate domain with document approval language
Sublime Security
6mo ago
Jan 23rd, 2026
Service abuse: Adobe Sign notification from an unsolicited reply-to address
Sublime Security
11mo ago
Aug 5th, 2025
Service Abuse: Box file sharing with credential phishing intent
Sublime Security
6mo ago
Jan 12th, 2026
Service abuse: Cisco secure email service with financial request
Sublime Security
9mo ago
Oct 1st, 2025
Service abuse: DocSend share from an unsolicited reply-to address
Sublime Security
1mo ago
Jun 18th, 2026
Service abuse: DocSend share from newly registered domain
Sublime Security
6mo ago
Jan 12th, 2026
Service abuse: DocuSign notification with suspicious sender or document name
Sublime Security
11mo ago
Aug 5th, 2025
Service abuse: DocuSign share from an unsolicited reply-to address
Sublime Security
6mo ago
Jan 12th, 2026
Service abuse: Domains By Proxy sender
Sublime Security
4mo ago
Mar 18th, 2026
Service abuse: Dropbox share from an unsolicited reply-to address
Sublime Security
11mo ago
Aug 5th, 2025
Service abuse: Dropbox share from new domain
Sublime Security
6mo ago
Jan 12th, 2026
Service abuse: Dropbox share with suspicious sender or document name
Sublime Security
6mo ago
Jan 12th, 2026
Service Abuse: ExactTarget with suspicious sender indicators
Sublime Security
8mo ago
Nov 8th, 2025
Service abuse: Free provider with SendGrid routing
Sublime Security
6mo ago
Jan 8th, 2026
Service abuse: GitHub notification with excessive mentions and suspicious links
Sublime Security
3mo ago
Apr 7th, 2026
Service abuse: Google account notification with links to free file host
Sublime Security
11mo ago
Aug 5th, 2025
Service abuse: Google application integration redirecting to suspicious hosts
Sublime Security
7mo ago
Dec 17th, 2025
Service abuse: Google classroom solicitation
Sublime Security
6mo ago
Jan 12th, 2026
Service abuse: Google Drive share from an unsolicited reply-to address
Sublime Security
11mo ago
Aug 5th, 2025
Service abuse: Google Drive share from new reply-to domain
Sublime Security
8mo ago
Nov 13th, 2025
Service abuse: Google Firebase sender address with suspicious content
Sublime Security
1mo ago
Jun 18th, 2026
Service abuse: HelloSign from an unsolicited sender address
Sublime Security
11mo ago
Aug 5th, 2025
Service Abuse: HelloSign share with suspicious sender or document name
Sublime Security
1mo ago
May 28th, 2026
Service abuse: Monday.com infrastructure with phishing intent
Sublime Security
4mo ago
Mar 9th, 2026
Service abuse: Notion free-tier account impersonating VIP
Sublime Security
13d ago
Jul 14th, 2026
Service abuse: Outlook Groups with Google Sites link and evasion tag
Sublime Security
1mo ago
Jun 17th, 2026
Service abuse: Payoneer callback scam
Sublime Security
2mo ago
May 4th, 2026
Service abuse: QuickBooks notification from new domain
Sublime Security
6mo ago
Jan 12th, 2026
Service abuse: QuickBooks notification with suspicious comments
Sublime Security
6mo ago
Jan 12th, 2026
Service abuse: Recruiting with suspicious language patterns from legitimate platforms
Sublime Security
9mo ago
Oct 7th, 2025
Service abuse: Roomsy with unrelated body content
Sublime Security
7mo ago
Dec 2nd, 2025
Service abuse: Sendgrid credential theft with personalized request targeting single recipient
Sublime Security
6mo ago
Jan 12th, 2026
Service abuse: SendGrid impersonation via Sendgrid from new sender
Sublime Security
6mo ago
Jan 12th, 2026
Service abuse: SurveyMonkey survey from newly registered domain
Sublime Security
6mo ago
Jan 12th, 2026
Service abuse: Suspicious Zoom Docs link
Sublime Security
7mo ago
Dec 2nd, 2025
Service abuse: Task management message sent via SendGrid
Sublime Security
9mo ago
Oct 6th, 2025
Service abuse: Trello board invitation with VIP impersonation
Sublime Security
5mo ago
Feb 3rd, 2026
Service abuse: Zohodesk reply-to mismatch with job scam indicators
Sublime Security
5d ago
Jul 22nd, 2026