Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Sep 9th, 2026
Feed Source
Detection Method is
Rule Name & Severity
Author
Last Updated
Labels
Attachment: PDF with link to zip containing a wsf file
Sublime Security
8mo ago
Jan 12th, 2026
Attachment: PDF with multistage landing - ClickUp abuse
Sublime Security
6mo ago
Feb 27th, 2026
Attachment: PDF with recipient email in link
Sublime Security
3mo ago
Jun 10th, 2026
Attachment: PDF with self-service platform links with self sender or blank recipients
Sublime Security
3mo ago
Jun 10th, 2026
Attachment: PDF with suspicious language and redirect to suspicious file type
Sublime Security
8mo ago
Jan 12th, 2026
Attachment: PDF with suspicious link and action-oriented language
Sublime Security
23d ago
Aug 18th, 2026
Attachment: PDF with View RFP Document lure with external link
Sublime Security
14d ago
Aug 27th, 2026
Attachment: QR code with credential phishing indicators
Sublime Security
1mo ago
Jul 27th, 2026
Attachment: QR code with encoded recipient targeting and redirect indicators
Sublime Security
7mo ago
Jan 30th, 2026
Attachment: QR code with recipient targeting and special characters
Sublime Security
6mo ago
Feb 21st, 2026
Attachment: QR code with suspicious URL patterns in EML file
Sublime Security
6mo ago
Feb 21st, 2026
Attachment: Romance scam with image lure and advance-fee or suspicious link indicators
Sublime Security
2mo ago
Jul 1st, 2026
Attachment: RTF file with suspicious link
Sublime Security
1y ago
Jul 23rd, 2025
Attachment: RTF with link to free-hosted Cloudflare Pages
Sublime Security
28d ago
Aug 13th, 2026
Attachment: Single-page PDF with S3-hosted HTML link
Sublime Security
1mo ago
Jul 16th, 2026
Attachment: Small text file with link containing recipient email address
Sublime Security
3mo ago
May 14th, 2026
Attachment: Word document with hyperlink and fraud language
Sublime Security
6d ago
Sep 4th, 2026
BEC/Fraud: Self-addressed reply with unrelated link in ongoing thread
Sublime Security
15d ago
Aug 26th, 2026
Body: CSS clamp() font obfuscation
Sublime Security
9d ago
Sep 1st, 2026
Body: Fake secure email portal with HTML obfuscation
Sublime Security
2mo ago
Jun 18th, 2026
Brand impersonation: AliExpress
Sublime Security
1y ago
Aug 5th, 2025
Brand impersonation: Bids & Tenders
Sublime Security
1mo ago
Jul 21st, 2026
Brand impersonation: Chase bank with credential phishing indicators
Sublime Security
8mo ago
Jan 12th, 2026
Brand impersonation: Cloud services with credential theft intent
Sublime Security
7d ago
Sep 3rd, 2026
Brand impersonation: Coinbase with suspicious links
Sublime Security
11mo ago
Sep 22nd, 2025
Brand impersonation: DocuSign
Sublime Security
3mo ago
Jun 1st, 2026
Brand impersonation: DocuSign PDF attachment with suspicious link
Sublime Security
10mo ago
Oct 22nd, 2025
Brand impersonation: Fake DocuSign HTML table not linking to DocuSign domains
Sublime Security
3mo ago
Jun 5th, 2026
Brand impersonation: Fake Fax
Sublime Security
2mo ago
Jun 17th, 2026
Brand impersonation: Figma with malicious document access overlay
Sublime Security
3mo ago
May 27th, 2026
Brand Impersonation: Gemini Trust Company
Sublime Security
8mo ago
Jan 12th, 2026
Brand impersonation: Google Careers
Sublime Security
10mo ago
Nov 12th, 2025
Brand impersonation: Google Drive fake file share
Sublime Security
2mo ago
Jun 26th, 2026
Brand impersonation: Google fake sign-in warning
Sublime Security
8mo ago
Jan 12th, 2026
Brand impersonation: Google Meet with malicious link
Sublime Security
1mo ago
Aug 7th, 2026
Brand impersonation: Google Workspace alert notification
Sublime Security
9mo ago
Dec 2nd, 2025
Brand impersonation: Government / Tax Authority document lure
Sublime Security
1mo ago
Jul 14th, 2026
Brand impersonation: LastPass
Sublime Security
6mo ago
Mar 5th, 2026
Brand impersonation: Microsoft logo image linking to free file host
Sublime Security
20d ago
Aug 21st, 2026
Brand impersonation: Microsoft logo or suspicious language with open redirect
Sublime Security
3mo ago
Jun 5th, 2026
Brand impersonation: Microsoft Planner with suspicious link
Sublime Security
29d ago
Aug 12th, 2026
Brand impersonation: Microsoft Teams invitation
Sublime Security
2mo ago
Jun 26th, 2026
Brand impersonation: Microsoft with low reputation links
Sublime Security
14d ago
Aug 27th, 2026
Brand impersonation: Navan
Sublime Security
7mo ago
Feb 9th, 2026
Brand impersonation: Paperless Post
Sublime Security
10d ago
Aug 31st, 2026
Brand impersonation: Proofpoint secure messaging without legitimate indicators
Sublime Security
2mo ago
Jun 26th, 2026
Brand impersonation: Purdue ePlanroom with suspicious links
Sublime Security
9mo ago
Dec 2nd, 2025
Brand impersonation: Robinhood
Sublime Security
14d ago
Aug 27th, 2026
Brand impersonation: Sharepoint fake file share
Sublime Security
8mo ago
Jan 12th, 2026
Brand impersonation: SharePoint PDF attachment with credential theft language
Sublime Security
4mo ago
May 4th, 2026