• Sublime Core Feed

Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Mar 9th, 2026
Feed Source
Detection Method is
Rule Name & Severity
Author
Last Updated
Labels
URLhaus: Malicious domain in message body or pdf attachment (trusted reporters)
Sublime Security
1mo ago
Jan 12th, 2026
/feeds/core/detection-rules/urlhaus-malicious-domain-in-message-body-or-pdf-attachment-trusted-reporters-cfca2986
URL with Unicode U+2044 (⁄) or U+2215 (∕) characters
@delivr_to
1mo ago
Jan 12th, 2026
/feeds/core/detection-rules/url-with-unicode-u2044-or-u2215-characters-12069f5b
Vendor compromise: GovDelivery message with suspicious link
Sublime Security
7mo ago
Aug 5th, 2025
/feeds/core/detection-rules/vendor-compromise-govdelivery-message-with-suspicious-link-0d2d5172
Xero infrastructure abuse
Sublime Security
4mo ago
Nov 3rd, 2025
/feeds/core/detection-rules/xero-infrastructure-abuse-918c4bd3
Zoom Events newsletter abuse
Sublime Security
1mo ago
Jan 12th, 2026
/feeds/core/detection-rules/zoom-events-newsletter-abuse-c8fce846