Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Jul 25th, 2026
Feed Source
Detection Method is
Rule Name & Severity
Author
Last Updated
Labels
Adobe branded PDF file linking to a password-protected file from untrusted sender
Sublime Security
2mo ago
Apr 29th, 2026
Attachment: Adobe image lure in body or attachment with suspicious link
Sublime Security
1mo ago
Jun 5th, 2026
Attachment: Callback phishing solicitation via image file
@vector_sec
6mo ago
Jan 12th, 2026
Attachment: Callback phishing solicitation via pdf file
Sublime Security
1mo ago
Jun 5th, 2026
Attachment: Compensation review lure with QR code
Sublime Security
3mo ago
Apr 14th, 2026
Attachment: Compensation-themed DOCX with QR code credential theft
Sublime Security
1mo ago
May 29th, 2026
Attachment: Dropbox image lure with no Dropbox domains in links
Sublime Security
1y ago
Jul 16th, 2025
Attachment: Duplicated header pages in fraudulent multi-page PDF Request for Quotation
Sublime Security
1mo ago
Jun 25th, 2026
Attachment: EML with link to credential phishing page
Sublime Security
1y ago
Jul 16th, 2025
Attachment: Fake attachment image lure
Sublime Security
1mo ago
Jun 5th, 2026
Attachment: Fake lawyer & sports agent identities
Sublime Security
6mo ago
Jan 26th, 2026
Attachment: Fake scan-to-email
Sublime Security
10mo ago
Sep 22nd, 2025
Attachment: Fake voicemail via PDF
Sublime Security
2mo ago
Apr 30th, 2026
Attachment: Fictitious invoice using LinkedIn's address
Sublime Security
10mo ago
Sep 3rd, 2025
Attachment: Invoice and W-9 PDFs with suspicious creators
Sublime Security
30d ago
Jun 26th, 2026
Attachment: Legal themed message or PDF with suspicious indicators
Sublime Security
3mo ago
Apr 3rd, 2026
Attachment: Microsoft 365 credential phishing
Sublime Security
1mo ago
Jun 5th, 2026
Attachment: Microsoft SharePoint Impersonation via images in macro-enabled attachment
Sublime Security
10d ago
Jul 16th, 2026
Attachment: Office file with document sharing and browser instruction lures
Sublime Security
5mo ago
Jan 29th, 2026
Attachment: PDF bid/proposal lure with credential theft indicators
Sublime Security
4mo ago
Mar 27th, 2026
Attachment: PDF proposal with credential theft indicators
Sublime Security
4mo ago
Mar 17th, 2026
Attachment: PDF with credential theft language and link to a free subdomain (unsolicited)
Sublime Security
6mo ago
Jan 12th, 2026
Attachment: PDF with suspicious language and redirect to suspicious file type
Sublime Security
6mo ago
Jan 12th, 2026
Attachment: RFP/RFQ impersonating government entities
Sublime Security
2y ago
Jan 30th, 2024
Attachment: Soda PDF producer with encryption themes
Sublime Security
11mo ago
Aug 5th, 2025
Attachment soliciting user to enable macros
Sublime Security
6mo ago
Jan 12th, 2026
Attachment: Suspicious PDF created with headless browser
Sublime Security
25d ago
Jul 1st, 2026
Attachment: USDA bid invitation impersonation
Sublime Security
11mo ago
Aug 5th, 2025
Brand impersonation: Adobe Acrobat Sign PDF phishing file format template
Sublime Security
1mo ago
Jun 1st, 2026
Brand impersonation: Amazon Web Services (AWS)
Sublime Security
20d ago
Jul 6th, 2026
Brand impersonation: Amazon with suspicious attachment
Sublime Security
3mo ago
Apr 14th, 2026
Brand impersonation: DocuSign branded attachment lure with no DocuSign links
Sublime Security
9mo ago
Oct 22nd, 2025
Brand impersonation: DocuSign PDF attachment with suspicious link
Sublime Security
9mo ago
Oct 22nd, 2025
Brand impersonation: Fake Fax
Sublime Security
1mo ago
Jun 17th, 2026
Brand impersonation: Fake procurement/RFQ PDF from energy and industrial companies
Sublime Security
1mo ago
Jun 25th, 2026
Brand impersonation: Figma with malicious document access overlay
Sublime Security
1mo ago
May 27th, 2026
Brand impersonation: Google fake sign-in warning
Sublime Security
6mo ago
Jan 12th, 2026
Brand impersonation: Internal Revenue Service
Sublime Security
12d ago
Jul 14th, 2026
Brand impersonation: Microsoft quarantine release notification in image attachment
Sublime Security
1y ago
Jul 16th, 2025
Brand impersonation: Microsoft Teams
Sublime Security
2y ago
Dec 3rd, 2024
Brand impersonation: Microsoft with low reputation links
Sublime Security
1mo ago
Jun 5th, 2026
Brand impersonation: SendGrid
Sublime Security
4mo ago
Mar 12th, 2026
Brand impersonation: SharePoint PDF attachment with credential theft language
Sublime Security
2mo ago
May 4th, 2026
Brand Impersonation: Shein
Sublime Security
9mo ago
Oct 15th, 2025
Brand impersonation: Square
Sublime Security
9mo ago
Oct 16th, 2025
Brand impersonation: TikTok
Sublime Security
5mo ago
Feb 12th, 2026
Brand impersonation: Toronto-Dominion Bank
Sublime Security
3mo ago
Apr 3rd, 2026
Callback phishing: Branded invoice from sender/reply-to domain less than 30 days old
Sublime Security
9mo ago
Oct 17th, 2025
Callback phishing in body or attachment (untrusted sender)
Sublime Security
4mo ago
Mar 27th, 2026
Callback phishing: Social Security Administration fraud
Sublime Security
6mo ago
Jan 12th, 2026