Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Sep 9th, 2026
Feed Source
Detection Method is
Rule Name & Severity
Author
Last Updated
Labels
URLhaus: Malicious domain in message body or pdf attachment (trusted reporters)
Sublime Security
8mo ago
Jan 12th, 2026
URL with Unicode U+2044 (⁄) or U+2215 (∕) characters
@delivr_to
30d ago
Aug 11th, 2026
Vendor compromise: GovDelivery message with suspicious link
Sublime Security
1y ago
Aug 5th, 2025
VIP Impersonation: VIP handoff with fake forwarded invoice thread
Sublime Security
24d ago
Aug 17th, 2026
Xero infrastructure abuse
Sublime Security
10mo ago
Nov 3rd, 2025
Zoom Events newsletter abuse
Sublime Security
2mo ago
Jul 8th, 2026