Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Apr 24th, 2026
Feed Source
Detection Method is
Rule Name & Severity
Author
Last Updated
Labels
Open redirect: secondstreetapp.com
Sublime Security
3mo ago
Jan 12th, 2026
Open redirect: Shibboleth SSO Logout Return Parameter
Sublime Security
3mo ago
Jan 12th, 2026
Open redirect: shoppermeet.net
Sublime Security
3mo ago
Jan 12th, 2026
Open redirect: shoppingwebapi.didatravel.com
Sublime Security
8mo ago
Aug 5th, 2025
Open redirect: Signature Travel Network
Sublime Security
11mo ago
May 23rd, 2025
Open redirect: Slack
Sublime Security
3mo ago
Jan 12th, 2026
Open redirect: slubnaglowie.pl
Sublime Security
11mo ago
May 23rd, 2025
Open redirect: smartadserver.com
Sublime Security
3mo ago
Jan 12th, 2026
Open redirect: smore.com
Sublime Security
3mo ago
Jan 12th, 2026
Open redirect: Snapchat
@vector_sec
3y ago
Dec 20th, 2023
Open redirect: social.bigpress.net
Sublime Security
8mo ago
Aug 5th, 2025
Open redirect: ssg-financial.com
Sublime Security
8mo ago
Aug 5th, 2025
Open redirect: stats.lib.pdx.edu
Sublime Security
3mo ago
Jan 12th, 2026
Open redirect: storematch.jp
Sublime Security
3mo ago
Jan 12th, 2026
Open redirect: Ticketmaster
Sublime Security
3mo ago
Jan 12th, 2026
Open redirect: TikTok
Sublime Security
3mo ago
Jan 12th, 2026
Open redirect: tkqlhce.com
Sublime Security
3mo ago
Jan 12th, 2026
Open redirect: tuttocauzioni.it
Sublime Security
8mo ago
Aug 5th, 2025
Open redirect: unitedwaynwvt.org
Sublime Security
3mo ago
Jan 12th, 2026
Open redirect: U.S. Antarctic Program Data Center (USAP-DC)
Sublime Security
3y ago
Sep 8th, 2023
Open redirect: ust.hk
Sublime Security
3mo ago
Jan 12th, 2026
Open redirect: vconfex.com
Sublime Security
3mo ago
Jan 12th, 2026
Open redirect: VK
@vector_sec
3mo ago
Jan 12th, 2026
Open redirect: weblinkconnect.com
Sublime Security
8mo ago
Aug 5th, 2025
Open redirect: whitefox.pl
Sublime Security
3mo ago
Jan 12th, 2026
Open redirect: Xfinity CMP Redirection to Google AMP
Sublime Security
8mo ago
Aug 5th, 2025
Open redirect: xfinity.com
Sublime Security
3mo ago
Jan 12th, 2026
Open redirect: YouTube
@vector_sec
2y ago
Apr 24th, 2024
Open redirect: YouTube --> Google Redirection Chain
Sublime Security
3mo ago
Jan 12th, 2026
Outlook hyperlink bypass: left-to-right mark (LRM) in base HTML tag
Sublime Security
4mo ago
Dec 10th, 2025
PDF attachment with Google (AE) redirecting to a php or zip file
Sublime Security
3mo ago
Jan 12th, 2026
QR code to auto-download of a suspicious file type (unsolicited)
Sublime Security
6mo ago
Oct 17th, 2025
QR Code with suspicious indicators
Sublime Security
3d ago
Apr 22nd, 2026
Reconnaissance: Email address harvesting attempt
Sublime Security
2mo ago
Feb 23rd, 2026
Recruitee Infrastructure Abuse
Sublime Security
9mo ago
Jul 16th, 2025
Request for Quote or Purchase (RFQ|RFP) with HTML smuggling attachment
Sublime Security
3mo ago
Jan 12th, 2026
Request for Quote or Purchase (RFQ|RFP) with suspicious sender or recipient pattern
Sublime Security
1mo ago
Mar 9th, 2026
Salesforce infrastructure abuse
Sublime Security
3mo ago
Jan 12th, 2026
Self-sent fake PDF attachment with misleading link
Sublime Security
3mo ago
Jan 12th, 2026
Service abuse: Apple TestFlight with suspicious developer reference
Sublime Security
2mo ago
Feb 6th, 2026
Service abuse: AppSheet infrastructure with suspicious indicators
Sublime Security
6mo ago
Oct 6th, 2025
Service abuse: Behance document sharing with suspicious language
Sublime Security
29d ago
Mar 27th, 2026
Service abuse: Callback phishing via Microsoft Teams invite
Sublime Security
4mo ago
Dec 12th, 2025
Service abuse: File sharing impersonation with external SharePoint links
Sublime Security
1mo ago
Mar 9th, 2026
Service abuse: FlipHTML5 with attachment deception and credential theft language
Sublime Security
3mo ago
Jan 12th, 2026
Service abuse: Formester with suspicious link behavior
Sublime Security
4mo ago
Dec 19th, 2025
Service abuse: GitHub notification with excessive mentions and suspicious links
Sublime Security
18d ago
Apr 7th, 2026
Service abuse: Google account notification with links to free file host
Sublime Security
8mo ago
Aug 5th, 2025
Service abuse: Google application integration redirecting to suspicious hosts
Sublime Security
4mo ago
Dec 17th, 2025
Service abuse: Google Firebase sender address with suspicious content
Sublime Security
23d ago
Apr 2nd, 2026