Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Jul 25th, 2026
Feed Source
Detection Method is
Rule Name & Severity
Author
Last Updated
Labels
VIP impersonation: Fake thread with display name match, email mismatch
Sublime Security
3mo ago
Apr 3rd, 2026
VIP impersonation: Fake thread with VIPs missing email metadata
Sublime Security
13d ago
Jul 13th, 2026
VIP impersonation: Invoice fraud with mobile device sign-off
Sublime Security
19d ago
Jul 7th, 2026
VIP impersonation: Payment handoff with VIP display name authored fake threads
Sublime Security
13d ago
Jul 13th, 2026
VIP Impersonation via Google Group relay with suspicious indicators
Sublime Security
1mo ago
Jun 5th, 2026
VIP impersonation: VIP name within a delimited subject with fake previous threads
Sublime Security
18d ago
Jul 8th, 2026
VIP impersonation: VIP payment redirect handoff via fake threads
Sublime Security
13d ago
Jul 13th, 2026
VIP impersonation: VIP recipient of previous thread with HTML generator
Sublime Security
19d ago
Jul 7th, 2026
VIP impersonation with BEC language (near match, untrusted sender)
Sublime Security
4mo ago
Mar 25th, 2026
VIP impersonation with charitable donation fraud
Sublime Security
1mo ago
Jun 5th, 2026
VIP impersonation with urgent request (strict match, untrusted sender)
Sublime Security
4mo ago
Mar 25th, 2026
VIP local_part impersonation from unsolicited sender
Sublime Security
11mo ago
Aug 12th, 2025
Xero invoice abuse
Sublime Security
7mo ago
Dec 17th, 2025
X (Twitter) impersonation with credential phishing motives
Sublime Security
2mo ago
May 15th, 2026