Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Jul 25th, 2026
Feed Source
Detection Method is
Rule Name & Severity
Author
Last Updated
Labels
VIP impersonation with charitable donation fraud
Sublime Security
1mo ago
Jun 5th, 2026
VIP impersonation with invoicing request
Sublime Security
2y ago
Apr 23rd, 2024
VIP impersonation with urgent request (strict match, untrusted sender)
Sublime Security
4mo ago
Mar 25th, 2026
VIP impersonation with w2 request with reply-to mismatch
Sublime Security
4mo ago
Mar 12th, 2026
Xero infrastructure abuse
Sublime Security
8mo ago
Nov 3rd, 2025
Xero invoice abuse
Sublime Security
7mo ago
Dec 17th, 2025
X (Twitter) impersonation with credential phishing motives
Sublime Security
2mo ago
May 15th, 2026
Zoom Events newsletter abuse
Sublime Security
18d ago
Jul 8th, 2026