• Sublime Core Feed

Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Jan 23rd, 2026
Feed Source
Detection Method is
Rule Name & Severity
Author
Last Updated
Labels
Open redirect: stats.lib.pdx.edu
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/open-redirect-statslibpdxedu-0fe96183
Open redirect: storematch.jp
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/open-redirect-storematchjp-849bfbb8
Open redirect: Ticketmaster
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/open-redirect-ticketmaster-a5b3901f
Open redirect: TikTok
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/open-redirect-tiktok-d231d135
Open redirect: tkqlhce.com
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/open-redirect-tkqlhcecom-44eef073
Open redirect: tuttocauzioni.it
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/open-redirect-tuttocauzioniit-6c0b2cb9
Open redirect: unitedwaynwvt.org
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/open-redirect-unitedwaynwvtorg-da6eb27a
Open redirect: U.S. Antarctic Program Data Center (USAP-DC)
Sublime Security
3y ago
Sep 8th, 2023
/feeds/core/detection-rules/open-redirect-us-antarctic-program-data-center-usap-dc-c499d041
Open redirect: ust.hk
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/open-redirect-usthk-700a19fb
Open redirect: vconfex.com
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/open-redirect-vconfexcom-877de339
Open redirect: VK
@vector_sec
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/open-redirect-vk-6ebd6d42
Open redirect: weblinkconnect.com
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/open-redirect-weblinkconnectcom-967f7a11
Open redirect: whitefox.pl
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/open-redirect-whitefoxpl-18b74a2a
Open redirect: Xfinity CMP Redirection to Google AMP
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/open-redirect-xfinity-cmp-redirection-to-google-amp-c0805b80
Open redirect: xfinity.com
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/open-redirect-xfinitycom-7b9012fa
Open redirect: YouTube
@vector_sec
2y ago
Apr 24th, 2024
/feeds/core/detection-rules/open-redirect-youtube-fb33bffe
Open redirect: YouTube --> Google Redirection Chain
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/open-redirect-youtube-greater-google-redirection-chain-67823fac
Outlook hyperlink bypass: left-to-right mark (LRM) in base HTML tag
Sublime Security
1mo ago
Dec 10th, 2025
/feeds/core/detection-rules/outlook-hyperlink-bypass-left-to-right-mark-lrm-in-base-html-tag-160cc681
PDF attachment with Google (AE) redirecting to a php or zip file
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/pdf-attachment-with-google-ae-redirecting-to-a-php-or-zip-file-57ae513f
QR code to auto-download of a suspicious file type (unsolicited)
Sublime Security
3mo ago
Oct 17th, 2025
/feeds/core/detection-rules/qr-code-to-auto-download-of-a-suspicious-file-type-unsolicited-eed87ea2
QR Code with suspicious indicators
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/qr-code-with-suspicious-indicators-04f5c34f
Reconnaissance: Email address harvesting attempt
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/reconnaissance-email-address-harvesting-attempt-bb31efbc
Recruitee Infrastructure Abuse
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/recruitee-infrastructure-abuse-31cab83d
Request for Quote or Purchase (RFQ|RFP) with HTML smuggling attachment
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/request-for-quote-or-purchase-rfqorrfp-with-html-smuggling-attachment-a47a5755
Request for Quote or Purchase (RFQ|RFP) with suspicious sender or recipient pattern
Sublime Security
9d ago
Jan 15th, 2026
/feeds/core/detection-rules/request-for-quote-or-purchase-rfqorrfp-with-suspicious-sender-or-recipient-pattern-2ac0d329
Salesforce infrastructure abuse
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/salesforce-infrastructure-abuse-78a77c70
Self-sent fake PDF attachment with misleading link
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/self-sent-fake-pdf-attachment-with-misleading-link-8a285d2e
Service abuse: AppSheet infrastructure with suspicious indicators
Sublime Security
3mo ago
Oct 6th, 2025
/feeds/core/detection-rules/service-abuse-appsheet-infrastructure-with-suspicious-indicators-5937646a
Service abuse: Callback phishing via Microsoft Teams invite
Sublime Security
1mo ago
Dec 12th, 2025
/feeds/core/detection-rules/service-abuse-callback-phishing-via-microsoft-teams-invite-13e35e5f
Service abuse: FlipHTML5 with attachment deception and credential theft language
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/service-abuse-fliphtml5-with-attachment-deception-and-credential-theft-language-02464799
Service abuse: Formester with suspicious link behavior
Sublime Security
1mo ago
Dec 19th, 2025
/feeds/core/detection-rules/service-abuse-formester-with-suspicious-link-behavior-e4b74fd4
Service abuse: Google account notification with links to free file host
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/service-abuse-google-account-notification-with-links-to-free-file-host-59786115
Service abuse: Google application integration redirecting to suspicious hosts
Sublime Security
1mo ago
Dec 17th, 2025
/feeds/core/detection-rules/service-abuse-google-application-integration-redirecting-to-suspicious-hosts-473d3247
Service abuse: Monday.com infrastructure with phishing intent
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/service-abuse-mondaycom-infrastructure-with-phishing-intent-a346e3b1
Service abuse: Random Google Firebase sender address with suspicious content
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/service-abuse-random-google-firebase-sender-address-with-suspicious-content-9f8899a9
Service abuse: SendGrid-formatted link with actor-controlled fragment
Sublime Security
2mo ago
Nov 24th, 2025
/feeds/core/detection-rules/service-abuse-sendgrid-formatted-link-with-actor-controlled-fragment-cb511fe9
Service abuse: Wix redirect through bulk mailer domains
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/service-abuse-wix-redirect-through-bulk-mailer-domains-60af216d
Sharepoint file share with suspicious recipients pattern
Sublime Security
2y ago
Mar 27th, 2024
/feeds/core/detection-rules/sharepoint-file-share-with-suspicious-recipients-pattern-998a0826
Sharepoint link likely unrelated to sender
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/sharepoint-link-likely-unrelated-to-sender-6870f489
Shopify infrastructure abuse
Sublime Security
2y ago
Nov 13th, 2024
/feeds/core/detection-rules/shopify-infrastructure-abuse-844ff164
Spam: Commonly observed formatting of unauthorized free giveaways
Sublime Security
10d ago
Jan 14th, 2026
/feeds/core/detection-rules/spam-commonly-observed-formatting-of-unauthorized-free-giveaways-8bc49fa3
Spam: Fake dating profile notification
Sublime Security
1mo ago
Dec 3rd, 2025
/feeds/core/detection-rules/spam-fake-dating-profile-notification-0f33fea2
Spam: Fake photo share
Sublime Security
2mo ago
Nov 8th, 2025
/feeds/core/detection-rules/spam-fake-photo-share-eb086f7d
Spam: Firebase password reset from suspicious sender
Sublime Security
1mo ago
Dec 2nd, 2025
/feeds/core/detection-rules/spam-firebase-password-reset-from-suspicious-sender-a2f673a9
Spam/fraud: Predatory journal/research paper request
Sublime Security
2mo ago
Nov 3rd, 2025
/feeds/core/detection-rules/spamfraud-predatory-journalresearch-paper-request-263ca56b
Spam: Link to blob.core.windows.net from new domain (<30d)
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/spam-link-to-blobcorewindowsnet-from-new-domain-less30d-a09b3800
Spam: New job cold outreach from unsolicited sender
Sublime Security
3mo ago
Sep 29th, 2025
/feeds/core/detection-rules/spam-new-job-cold-outreach-from-unsolicited-sender-ec39b789
Spam: New link domain (<=10d) and emojis
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/spam-new-link-domain-less10d-and-emojis-33677993
Spam: Single recipient duplicated in cc
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/spam-single-recipient-duplicated-in-cc-387cacc9
Spam: Unsolicited WordPress account creation or password reset request
Sublime Security
2mo ago
Nov 24th, 2025
/feeds/core/detection-rules/spam-unsolicited-wordpress-account-creation-or-password-reset-request-e182b6b2