Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Apr 24th, 2026
Feed Source
Detection Method is
Rule Name & Severity
Author
Last Updated
Labels
Abuse: Cloudflare Workers Hosted EvilTokens Domain Structure
Sublime Security
18d ago
Apr 6th, 2026
Attachment: Adobe image lure in body or attachment with suspicious link
Sublime Security
3mo ago
Jan 5th, 2026
Attachment: Calendar invite with Google redirect and invoice request
Sublime Security
16d ago
Apr 8th, 2026
Attachment: Calendar invite with suspicious link leading to an open redirect
Sublime Security
9mo ago
Jul 16th, 2025
Attachment: Callback phishing solicitation via image file
@vector_sec
3mo ago
Jan 12th, 2026
Attachment: DocuSign impersonation via PDF linking to new domain
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: EML file with IPFS links
Sublime Security
5mo ago
Nov 4th, 2025
Attachment: EML with link to credential phishing page
Sublime Security
9mo ago
Jul 16th, 2025
Attachment: EML with QR code redirecting to Cloudflare challenges
Sublime Security
23d ago
Apr 1st, 2026
Attachment: EML with SharePoint files shared from GoDaddy federated tenants
Sublime Security
7mo ago
Sep 23rd, 2025
Attachment: EML with Sharepoint link likely unrelated to sender
Sublime Security
7mo ago
Sep 23rd, 2025
Attachment: Fake Slack installer
Sublime Security
3y ago
Nov 29th, 2023
Attachment: Fake voicemail via PDF
Sublime Security
10d ago
Apr 14th, 2026
Attachment: Fake Zoom installer
Sublime Security
3y ago
Nov 29th, 2023
Attachment: HTML smuggling 'body onload' linking to suspicious destination
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: HTML smuggling Microsoft sign in
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: HTML smuggling - QR Code with suspicious links
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: HTML smuggling with atob and high entropy
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: HTML smuggling with auto-downloaded file
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: ICS calendar file with QR code containing recipient email address
Sublime Security
4d ago
Apr 20th, 2026
Attachment: ICS file with AWS Lambda URL
Sublime Security
23d ago
Apr 1st, 2026
Attachment: ICS file with links to newly registered domains
Sublime Security
4d ago
Apr 20th, 2026
Attachment: Legal themed message or PDF with suspicious indicators
Sublime Security
21d ago
Apr 3rd, 2026
Attachment: Link to Doubleclick.net open redirect
Sublime Security
8mo ago
Aug 5th, 2025
Attachment: Office document loads remote document template
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: Office document with VSTO add-in
@vector_sec
3mo ago
Jan 12th, 2026
Attachment: Office file contains OLE relationship to credential phishing page
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: Office file with credential phishing URLs
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: PDF bid/proposal lure with credential theft indicators
Sublime Security
28d ago
Mar 27th, 2026
Attachment: PDF file with link to fake Bitcoin exchange
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: PDF file with low reputation link to ZIP file (unsolicited)
Michael Tingle
3mo ago
Jan 12th, 2026
Attachment: PDF proposal with credential theft indicators
Sublime Security
1mo ago
Mar 17th, 2026
Attachment: PDF with a suspicious string and single URL
Sublime Security
14d ago
Apr 10th, 2026
Attachment: PDF with credential theft language and link to a free subdomain (unsolicited)
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: PDF with link to DMG file download
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: PDF with link to zip containing a wsf file
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: PDF with multistage landing - ClickUp abuse
Sublime Security
1mo ago
Feb 27th, 2026
Attachment: PDF with recipient email in link
Sublime Security
1mo ago
Mar 3rd, 2026
Attachment: PDF with suspicious language and redirect to suspicious file type
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: PDF with suspicious link and action-oriented language
Sublime Security
1mo ago
Mar 6th, 2026
Attachment: QR code with credential phishing indicators
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: QR code with encoded recipient targeting and redirect indicators
Sublime Security
2mo ago
Jan 30th, 2026
Attachment: QR code with recipient targeting and special characters
Sublime Security
2mo ago
Feb 21st, 2026
Attachment: QR code with suspicious URL patterns in EML file
Sublime Security
2mo ago
Feb 21st, 2026
Attachment: RTF file with suspicious link
Sublime Security
9mo ago
Jul 23rd, 2025
Attachment: Small text file with link containing recipient email address
Sublime Security
3mo ago
Jan 12th, 2026
Brand impersonation: AliExpress
Sublime Security
8mo ago
Aug 5th, 2025
Brand impersonation: Chase bank with credential phishing indicators
Sublime Security
3mo ago
Jan 12th, 2026
Brand impersonation: Coinbase with suspicious links
Sublime Security
7mo ago
Sep 22nd, 2025
Brand impersonation: DocuSign
Sublime Security
7d ago
Apr 17th, 2026