Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Sep 9th, 2026
Feed Source
Detection Method is
Rule Name & Severity
Author
Last Updated
Labels
Service abuse: Outlook Groups with Google Sites link and evasion tag
Sublime Security
2mo ago
Jun 17th, 2026
Service abuse: Payoneer callback scam
Sublime Security
4mo ago
May 4th, 2026
Service abuse: PayPal manager account creation with callback scam indicators
Sublime Security
3mo ago
Jun 2nd, 2026
Service abuse: Postman reply-to mismatch with credential theft intent
Sublime Security
1mo ago
Jul 29th, 2026
Service abuse: Power Automate callback scam
Sublime Security
6d ago
Sep 4th, 2026
Service abuse: QuickBooks notification from new domain
Sublime Security
8mo ago
Jan 12th, 2026
Service abuse: QuickBooks notification with suspicious comments
Sublime Security
8mo ago
Jan 12th, 2026
Service abuse: Recruiting with suspicious language patterns from legitimate platforms
Sublime Security
11mo ago
Oct 7th, 2025
Service abuse: Roomsy with unrelated body content
Sublime Security
9mo ago
Dec 2nd, 2025
Service abuse: Sendgrid credential theft with personalized request targeting single recipient
Sublime Security
8mo ago
Jan 12th, 2026
Service abuse: SendGrid impersonation via Sendgrid from new sender
Sublime Security
1mo ago
Aug 3rd, 2026
Service abuse: SendThisFile with credential theft and financial language
Sublime Security
10mo ago
Oct 27th, 2025
Service abuse: Settime.io sender with callback scam intent
Sublime Security
2mo ago
Jun 24th, 2026
Service abuse: Square marketing with suspicious QR code
Sublime Security
3mo ago
May 26th, 2026
Service abuse: Substack credential theft with confusable characters and branded button redirects
Sublime Security
5mo ago
Mar 19th, 2026
Service abuse: SurveyMonkey survey from newly registered domain
Sublime Security
8mo ago
Jan 12th, 2026
Service abuse: SurveyMonkey with suspicious outbound links
Sublime Security
2mo ago
Jul 8th, 2026
Service abuse: Suspicious Datadog alert
Sublime Security
3mo ago
Jun 11th, 2026
Service abuse: Suspicious Zoom Docs link
Sublime Security
9mo ago
Dec 2nd, 2025
Service abuse: Task management message sent via SendGrid
Sublime Security
11mo ago
Oct 6th, 2025
Service abuse: Trello board invitation with VIP impersonation
Sublime Security
7mo ago
Feb 3rd, 2026
Service abuse: Vimeo with external plain-text links in message
Sublime Security
6mo ago
Mar 6th, 2026
Service abuse: WeTransfer callback scam
Sublime Security
7mo ago
Jan 30th, 2026
Service abuse: Wix redirect through bulk mailer domains
Sublime Security
8mo ago
Jan 12th, 2026
Service abuse: Wufoo credential theft
Sublime Security
1mo ago
Aug 5th, 2026
Service abuse: Zohodesk reply-to mismatch with job scam indicators
Sublime Security
1mo ago
Jul 22nd, 2026
Service abuse: Zoom Clips with suspicious reply-to address or links
Sublime Security
9d ago
Sep 1st, 2026
Service Abuse: Zoom with freemail reply-to and recipient address in greeting
Sublime Security
4mo ago
May 6th, 2026
Service abuse: Zoom with newly registered reply-to domain
Sublime Security
4mo ago
May 4th, 2026
Sharepoint link likely unrelated to sender
Sublime Security
8mo ago
Jan 12th, 2026
Sharepoint online with external recipients and external display name
@vector_sec
3y ago
Aug 17th, 2023
Spam: Attendee list solicitation
Sublime Security
1y ago
Aug 29th, 2025
Spam: Campaign with excessive space/char obfuscation and free file hosted link
Sublime Security
8mo ago
Jan 12th, 2026
Spam: Commonly observed formatting of unauthorized free giveaways
Sublime Security
7mo ago
Jan 14th, 2026
Spam: Default Microsoft Exchange Online sender domain (onmicrosoft.com)
Sublime Security
1mo ago
Aug 3rd, 2026
Spam: Fake dating profile notification
Sublime Security
5mo ago
Mar 20th, 2026
Spam: Fake photo share
Sublime Security
2d ago
Sep 8th, 2026
Spam: Firebase password reset from suspicious sender
Sublime Security
9mo ago
Dec 2nd, 2025
Spam/fraud: Predatory journal/research paper request
Sublime Security
10mo ago
Nov 3rd, 2025
Spam: Ghostwriting services scam with manipulative language
Sublime Security
10mo ago
Oct 17th, 2025
Spamhaus: Mail transiting a DROP listed network
Sublime Security
20h ago
Sep 9th, 2026
Spamhaus: Mail transiting an ASN-DROP listed network
Sublime Security
20h ago
Sep 9th, 2026
Spam: Item giveaway spam template
Sublime Security
1y ago
Aug 5th, 2025
Spam: Large financial amount mention from newly registered sender domain
Sublime Security
1mo ago
Aug 3rd, 2026
Spam: Link to blob.core.windows.net from new domain (<30d)
Sublime Security
1y ago
Jul 16th, 2025
Spam: Mastercard promotional content with image-based body
Sublime Security
10mo ago
Nov 5th, 2025
Spam: New job cold outreach from unsolicited sender
Sublime Security
11mo ago
Sep 29th, 2025
Spam: New link domain (<=10d) and emojis
Sublime Security
1y ago
Jul 16th, 2025
Spam: Sendersrv.com with financial communications and unsubscribe language
Sublime Security
6mo ago
Feb 24th, 2026
Spam: Sexually explicit content with emoji in subject from freemail provider
Sublime Security
6mo ago
Mar 10th, 2026