• Sublime Core Feed

Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Jan 23rd, 2026
Feed Source
Detection Method is
Rule Name & Severity
Author
Last Updated
Labels
Spam: New link domain (<=10d) and emojis
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/spam-new-link-domain-less10d-and-emojis-33677993
Spam: Sexually explicit Google Drive share
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/spam-sexually-explicit-google-drive-share-3f951c06
Spam: Sexually explicit Google group invitation
Sublime Security
2mo ago
Nov 12th, 2025
/feeds/core/detection-rules/spam-sexually-explicit-google-group-invitation-4e0bec29
Spam: Sexually explicit Looker Studio report
Sublime Security
3mo ago
Oct 2nd, 2025
/feeds/core/detection-rules/spam-sexually-explicit-looker-studio-report-f1e649cd
Spam: Single recipient duplicated in cc
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/spam-single-recipient-duplicated-in-cc-387cacc9
Spam: Unsolicited malformed PDF
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/spam-unsolicited-malformed-pdf-f0c50031
Spam: Unsolicited WordPress account creation or password reset request
Sublime Security
2mo ago
Nov 24th, 2025
/feeds/core/detection-rules/spam-unsolicited-wordpress-account-creation-or-password-reset-request-e182b6b2
Spam: URL shortener with short body content and emojis
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/spam-url-shortener-with-short-body-content-and-emojis-b7797e4c
Spam: Website errors solicitation
Sublime Security
1mo ago
Dec 11th, 2025
/feeds/core/detection-rules/spam-website-errors-solicitation-122ea794
Spoofable internal domain with suspicious signals
Sublime Security
6mo ago
Jul 23rd, 2025
/feeds/core/detection-rules/spoofable-internal-domain-with-suspicious-signals-40089d69
Subject and sender display name contains matching long alphanumeric string
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/subject-and-sender-display-name-contains-matching-long-alphanumeric-string-a8a0c831
Suspected cross-site scripting (XSS) found in subject
Sublime Security
4mo ago
Sep 4th, 2025
/feeds/core/detection-rules/suspected-cross-site-scripting-xss-found-in-subject-8a946cfa
Suspected lookalike domain with suspicious language
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/suspected-lookalike-domain-with-suspicious-language-3674ced0
Suspected WordPress abuse with cross-site scripting (XSS) indicators
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/suspected-wordpress-abuse-with-cross-site-scripting-xss-indicators-9c21225b
Suspicious attachment with unscannable Cloudflare link
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/suspicious-attachment-with-unscannable-cloudflare-link-00f92b6f
Suspicious DocuSign share from new domain
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/suspicious-docusign-share-from-new-domain-d430a1f3
Suspicious invoice reference with missing or image-only attachments
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/suspicious-invoice-reference-with-missing-or-image-only-attachments-466c1680
Suspicious Links to Cloudflare R2 and Edge Services
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/suspicious-links-to-cloudflare-r2-and-edge-services-5dd3e5c8
Suspicious link to Looker Studio (lookerstudio.google.com) from a new and unsolicited sender
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/suspicious-link-to-looker-studio-lookerstudiogooglecom-from-a-new-and-unsolicited-sender-dbb50cb4
Suspicious message with unscannable Cloudflare link
Sublime Security
4mo ago
Sep 22nd, 2025
/feeds/core/detection-rules/suspicious-message-with-unscannable-cloudflare-link-70ea21f9
Suspicious message with unscannable Vercel link
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/suspicious-message-with-unscannable-vercel-link-b5acffe7
Suspicious newly registered reply-to domain with engaging financial or urgent language
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/suspicious-newly-registered-reply-to-domain-with-engaging-financial-or-urgent-language-db4d9bb3
Suspicious recipient pattern and language with low reputation link to login
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/suspicious-recipient-pattern-and-language-with-low-reputation-link-to-login-a8ea0402
Suspicious request for financial information
Sublime Security
1mo ago
Dec 6th, 2025
/feeds/core/detection-rules/suspicious-request-for-financial-information-4ebdaa4d
Suspicious sender display name with long procedurally generated text blob
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/suspicious-sender-display-name-with-long-procedurally-generated-text-blob-2a40b043
Suspicious SharePoint file sharing
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/suspicious-sharepoint-file-sharing-971c3d9c
Suspicious subject with long procedurally generated text blob
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/suspicious-subject-with-long-procedurally-generated-text-blob-e819593d
Suspicious VBA macros from untrusted sender
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/suspicious-vba-macros-from-untrusted-sender-37cec120
Truth Social infrastructure abuse via link redirect
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/truth-social-infrastructure-abuse-via-link-redirect-aaaa30a8
Twitter infrastructure abuse via link shortener
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/twitter-infrastructure-abuse-via-link-shortener-99ca165e
Unicode QR code
Sublime Security
5mo ago
Aug 25th, 2025
/feeds/core/detection-rules/unicode-qr-code-1a0bdd25
Unusually long local part from untrusted sender address
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/unusually-long-local-part-from-untrusted-sender-address-91a9cd45
Vendor impersonation: Thread hijacking with typosquat domain
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/vendor-impersonation-thread-hijacking-with-typosquat-domain-9c2f38ed
Venmo payment request abuse
Sublime Security
4mo ago
Sep 5th, 2025
/feeds/core/detection-rules/venmo-payment-request-abuse-4450639a
VIP / Executive impersonation in subject (untrusted)
Sublime Security
5mo ago
Aug 14th, 2025
/feeds/core/detection-rules/vip-executive-impersonation-in-subject-untrusted-0a641fe5
VIP / Executive impersonation (strict match, untrusted)
Sublime Security
3mo ago
Sep 29th, 2025
/feeds/core/detection-rules/vip-executive-impersonation-strict-match-untrusted-e42c84b7
VIP impersonation: Fake thread with display name match, email mismatch
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/vip-impersonation-fake-thread-with-display-name-match-email-mismatch-11cc3e28
VIP Impersonation via Google Group relay with suspicious indicators
Sublime Security
2mo ago
Nov 12th, 2025
/feeds/core/detection-rules/vip-impersonation-via-google-group-relay-with-suspicious-indicators-57f9cd3b
VIP impersonation with BEC language (near match, untrusted sender)
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/vip-impersonation-with-bec-language-near-match-untrusted-sender-303081da
VIP impersonation with charitable donation fraud
Sublime Security
2mo ago
Nov 12th, 2025
/feeds/core/detection-rules/vip-impersonation-with-charitable-donation-fraud-35a56b8e
VIP impersonation with urgent request (strict match, untrusted sender)
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/vip-impersonation-with-urgent-request-strict-match-untrusted-sender-0dd1fa60
VIP local_part impersonation from unsolicited sender
Sublime Security
5mo ago
Aug 12th, 2025
/feeds/core/detection-rules/vip-localpart-impersonation-from-unsolicited-sender-74035fdc
Xero invoice abuse
Sublime Security
1mo ago
Dec 17th, 2025
/feeds/core/detection-rules/xero-invoice-abuse-6538c600
X (Twitter) impersonation with credential phishing motives
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/x-twitter-impersonation-with-credential-phishing-motives-0b60dca6