Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Jul 25th, 2026
Feed Source
Detection Method is
Rule Name & Severity
Author
Last Updated
Labels
Attachment: Malicious zip file matching zipline campaign
Sublime Security
1mo ago
Jun 25th, 2026
Attachment: PDF Object Hash - Encrypted PDFs with fake payment notification
Sublime Security
4mo ago
Mar 2nd, 2026
Body: Fake secure email portal with HTML obfuscation
Sublime Security
1mo ago
Jun 18th, 2026
Brand impersonation: Government / Tax Authority document lure
Sublime Security
12d ago
Jul 14th, 2026
Brand impersonation: ukr[.]net
Sublime Security
3y ago
Aug 21st, 2023
Link: 9WOLF phishkit initial landing URI
Sublime Security
5mo ago
Jan 30th, 2026
Link: Free file host link with 'Important Viewing Note' lure
Sublime Security
11d ago
Jul 15th, 2026
Link: Google Cloud Storage redirect to external domain
Sublime Security
26d ago
Jun 30th, 2026
Link: Landing page with search-ms protocol redirect
Sublime Security
3mo ago
Apr 7th, 2026
Link: URL redirecting to blob URL
Sublime Security
5mo ago
Feb 24th, 2026
MalwareBazaar: Malicious attachment hash in archive (trusted reporters)
Sublime Security
2mo ago
Apr 29th, 2026
MalwareBazaar: Malicious attachment hash (trusted reporters)
Sublime Security
4mo ago
Mar 26th, 2026
Malware: Pikabot delivery via URL auto-download
Sublime Security
2y ago
Apr 25th, 2024
Service abuse: Google OAuth with suspicious redirect destination
Sublime Security
1mo ago
May 27th, 2026
URLhaus: Malicious domain in message body or pdf attachment (trusted reporters)
Sublime Security
6mo ago
Jan 12th, 2026