• Sublime Core Feed

Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Jan 23rd, 2026
Feed Source
Detection Method is
Rule Name & Severity
Author
Last Updated
Labels
Link: Multistage Landing - Abused Buildin.ai
Sublime Security
4mo ago
Sep 5th, 2025
/feeds/core/detection-rules/link-multistage-landing-abused-buildinai-e0a79ef5
Link: Multistage landing - Abused Docusign
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-multistage-landing-abused-docusign-4189a645
Link: Multistage landing - Abused Google Drive
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-multistage-landing-abused-google-drive-c86288b4
Link: Multistage landing - FreshDesk knowledge base abuse
Sublime Security
5mo ago
Aug 21st, 2025
/feeds/core/detection-rules/link-multistage-landing-freshdesk-knowledge-base-abuse-edd6acf7
Link: Multistage landing - JotForm abuse
Sublime Security
1mo ago
Dec 1st, 2025
/feeds/core/detection-rules/link-multistage-landing-jotform-abuse-5b64326f
Link: Multistage landing - Ludus presentation
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-multistage-landing-ludus-presentation-a8b3c311
Link: Multistage landing - Microsoft Forms abuse
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-multistage-landing-microsoft-forms-abuse-85a2cd12
Link: Multistage landing - Published Google Doc
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-multistage-landing-published-google-doc-031e1ff8
Link: Multistage landing - Scribd document
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-multistage-landing-scribd-document-afa9807d
Link: Multistage landing - Trello board abuse
Sublime Security
5mo ago
Aug 20th, 2025
/feeds/core/detection-rules/link-multistage-landing-trello-board-abuse-14a5b23a
Link: MyActiveCampaign Link Abuse
Sublime Security
5mo ago
Aug 20th, 2025
/feeds/core/detection-rules/link-myactivecampaign-link-abuse-f5b91ce5
Link: Obfuscation via userinfo with excessive URL padding
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-obfuscation-via-userinfo-with-excessive-url-padding-806317a3
Link: .onion From Unsolicited Sender
Sublime Security
5mo ago
Jul 30th, 2025
/feeds/core/detection-rules/link-onion-from-unsolicited-sender-9ac0fc83
Link: PDF and financial display text to free file host
Sublime Security
4mo ago
Sep 24th, 2025
/feeds/core/detection-rules/link-pdf-and-financial-display-text-to-free-file-host-b010740b
Link: Personal SharePoint with invalid recipients and credential theft language
Sublime Security
7h ago
Jan 23rd, 2026
/feeds/core/detection-rules/link-personal-sharepoint-with-invalid-recipients-and-credential-theft-language-79d5403d
Link: QR code with phishing disposition in img or pdf
Sublime Security
5mo ago
Jul 30th, 2025
/feeds/core/detection-rules/link-qr-code-with-phishing-disposition-in-img-or-pdf-8e8949f6
Link: QR Code with suspicious language (untrusted sender)
Sublime Security
5mo ago
Jul 30th, 2025
/feeds/core/detection-rules/link-qr-code-with-suspicious-language-untrusted-sender-25a84d1c
Link: QuickBooks image lure with suspicious link
Sublime Security
6mo ago
Jul 23rd, 2025
/feeds/core/detection-rules/link-quickbooks-image-lure-with-suspicious-link-3826a923
Link: Recipient domain in URL path
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-recipient-domain-in-url-path-de08731f
Link: Referrer anonymization service from untrusted sender
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-referrer-anonymization-service-from-untrusted-sender-9fab2e1e
Link: Romance/Sexual Language With Suspicious Link
Sublime Security
5mo ago
Aug 22nd, 2025
/feeds/core/detection-rules/link-romancesexual-language-with-suspicious-link-d5694cae
Link: ScreenConnect installer with suspicious relay domain
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-screenconnect-installer-with-suspicious-relay-domain-37d21eef
Link: Scribd fullscreen link from suspicious sender
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-scribd-fullscreen-link-from-suspicious-sender-9e9bc972
Link: Self-sender with sender org in subject and credential theft indicator
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-self-sender-with-sender-org-in-subject-and-credential-theft-indicator-bfa9aa08
Link: Self-sent message with quarterly document review request
Sublime Security
2d ago
Jan 21st, 2026
/feeds/core/detection-rules/link-self-sent-message-with-quarterly-document-review-request-3c42cec6
Link: SharePoint filename matches org name
Sublime Security
3mo ago
Sep 26th, 2025
/feeds/core/detection-rules/link-sharepoint-filename-matches-org-name-cb954726
Link: SharePoint files shared from GoDaddy federated tenants
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/link-sharepoint-files-shared-from-godaddy-federated-tenants-0e26cdd2
Link: Spam website with evasion indicators
Sublime Security
1mo ago
Nov 25th, 2025
/feeds/core/detection-rules/link-spam-website-with-evasion-indicators-08bcd353
Link: Squarespace infrastructure abuse
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-squarespace-infrastructure-abuse-a8fe9d30
Link: Suspicious Sharepoint folder share
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-suspicious-sharepoint-folder-share-6168a08c
Link: Suspicious URL with recipient targeting and special characters
Sublime Security
1d ago
Jan 22nd, 2026
/feeds/core/detection-rules/link-suspicious-url-with-recipient-targeting-and-special-characters-e808be3a
Link to a domain with punycode characters
@ajpc500
2mo ago
Nov 12th, 2025
/feeds/core/detection-rules/link-to-a-domain-with-punycode-characters-74b3698c
Link to auto-downloaded disk image in encrypted zip
@ajpc500
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-to-auto-downloaded-disk-image-in-encrypted-zip-b50f0cb1
Link to auto-downloaded DMG in archive
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/link-to-auto-downloaded-dmg-in-archive-dc04cdd8
Link to auto-downloaded DMG in encrypted zip
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/link-to-auto-downloaded-dmg-in-encrypted-zip-43af98d3
Link to auto-downloaded file with Adobe branding
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/link-to-auto-downloaded-file-with-adobe-branding-e826c2cf
Link to auto-downloaded file with Google Drive branding
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-to-auto-downloaded-file-with-google-drive-branding-4b5343be
Link to auto-download of a suspicious file type (unsolicited)
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-to-auto-download-of-a-suspicious-file-type-unsolicited-67ae2152
Link to Google Apps Script macro (unsolicited)
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-to-google-apps-script-macro-unsolicited-d10146df
Link to Google Apps Script macro via comment tagging
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-to-google-apps-script-macro-via-comment-tagging-66fecd30
Link: Tycoon2FA phishing kit (non-exhaustive)
Sublime Security
19h ago
Jan 23rd, 2026
/feeds/core/detection-rules/link-tycoon2fa-phishing-kit-non-exhaustive-a070d4e2
Link: Uncommon SharePoint document type with sender's display name
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-uncommon-sharepoint-document-type-with-senders-display-name-02d290b2
Link: URL scheme obfuscation via split HTML anchors
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-url-scheme-obfuscation-via-split-html-anchors-10375948
Link: Webflow link from unsolicited sender
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-webflow-link-from-unsolicited-sender-d4f3b8cf
Link: Zoho form link from unsolicited sender
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-zoho-form-link-from-unsolicited-sender-eb04a9f2
Low reputation link to auto-downloaded HTML file with smuggling indicators
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/low-reputation-link-to-auto-downloaded-html-file-with-smuggling-indicators-339676c6
Malformed URL prefix
Sublime Security
4mo ago
Sep 4th, 2025
/feeds/core/detection-rules/malformed-url-prefix-4e659d28
Malware: Pikabot delivery via URL auto-download
Sublime Security
2y ago
Apr 25th, 2024
/feeds/core/detection-rules/malware-pikabot-delivery-via-url-auto-download-f4be4572
Microsoft device code phishing
@ajpc500
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/microsoft-device-code-phishing-61f3ae67
Mismatched links: Free file share with urgent language
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/mismatched-links-free-file-share-with-urgent-language-478334c8