• Sublime Core Feed

Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Dec 19th, 2025
Feed Source
Detection Method is
Rule Name & Severity
Author
Last Updated
Labels
Attachment: EML with link to credential phishing page
Sublime Security
5mo ago
Jul 16th, 2025
/feeds/core/detection-rules/attachment-eml-with-link-to-credential-phishing-page-1df41cca
Attachment: HTML smuggling - QR Code with suspicious links
Sublime Security
5mo ago
Jul 16th, 2025
/feeds/core/detection-rules/attachment-html-smuggling-qr-code-with-suspicious-links-010e757d
Attachment: QR code with credential phishing indicators
Sublime Security
3mo ago
Sep 4th, 2025
/feeds/core/detection-rules/attachment-qr-code-with-credential-phishing-indicators-9f1681e1
Brand impersonation: DocuSign branded attachment lure with no DocuSign links
Sublime Security
2mo ago
Oct 22nd, 2025
/feeds/core/detection-rules/brand-impersonation-docusign-branded-attachment-lure-with-no-docusign-links-814a5694
Credential phishing content and link (untrusted sender)
Sublime Security
5d ago
Dec 17th, 2025
/feeds/core/detection-rules/credential-phishing-content-and-link-untrusted-sender-f0c95bb7
Credential phishing link (unknown sender)
Sublime Security
5mo ago
Jul 16th, 2025
/feeds/core/detection-rules/credential-phishing-link-unknown-sender-a278012b
Free subdomain link with credential theft indicators
Sublime Security
1y ago
Dec 12th, 2024
/feeds/core/detection-rules/free-subdomain-link-with-credential-theft-indicators-9187479c
Free subdomain link with login or captcha (untrusted sender)
Sublime Security
5mo ago
Jul 16th, 2025
/feeds/core/detection-rules/free-subdomain-link-with-login-or-captcha-untrusted-sender-93288f82
Google Accelerated Mobile Pages (AMP) abuse
Sublime Security
3mo ago
Sep 22nd, 2025
/feeds/core/detection-rules/google-accelerated-mobile-pages-amp-abuse-46907029
Google Drive abuse: Credential phishing link
Sublime Security
1y ago
Jul 31st, 2024
/feeds/core/detection-rules/google-drive-abuse-credential-phishing-link-c74aece0
Issuu document with suspicious embedded link
Sublime Security
4mo ago
Aug 5th, 2025
/feeds/core/detection-rules/issuu-document-with-suspicious-embedded-link-0d73f43d
Link: Adobe share with suspicious indicators
Sublime Security
4mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-adobe-share-with-suspicious-indicators-b33cae80
Link: chatbot.page platform abuse
Sublime Security
4mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-chatbotpage-platform-abuse-bfd6a076
Link: Credential phishing link with undisclosed recipients
Sublime Security
4mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-credential-phishing-link-with-undisclosed-recipients-06fc155e
Link: Cryptocurrency fraud with suspicious links
Sublime Security
21d ago
Dec 1st, 2025
/feeds/core/detection-rules/link-cryptocurrency-fraud-with-suspicious-links-d0da37ce
Link: Figma design deck with credential theft language
Sublime Security
4mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-figma-design-deck-with-credential-theft-language-87601924
Link: HR impersonation with suspicious domain indicators and credential theft
Sublime Security
19d ago
Dec 3rd, 2025
/feeds/core/detection-rules/link-hr-impersonation-with-suspicious-domain-indicators-and-credential-theft-f31f8831
Link: Microsoft Dynamics 365 form phishing
Sublime Security
17d ago
Dec 5th, 2025
/feeds/core/detection-rules/link-microsoft-dynamics-365-form-phishing-f72b9085
Link: Multistage landing - FreshDesk knowledge base abuse
Sublime Security
4mo ago
Aug 21st, 2025
/feeds/core/detection-rules/link-multistage-landing-freshdesk-knowledge-base-abuse-edd6acf7
Link: Multistage landing - Ludus presentation
Sublime Security
4mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-multistage-landing-ludus-presentation-a8b3c311
Link: Multistage landing - Scribd document
Sublime Security
4mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-multistage-landing-scribd-document-afa9807d
Link: Multistage landing - Trello board abuse
Sublime Security
4mo ago
Aug 20th, 2025
/feeds/core/detection-rules/link-multistage-landing-trello-board-abuse-14a5b23a
Link: Spam website with evasion indicators
Sublime Security
27d ago
Nov 25th, 2025
/feeds/core/detection-rules/link-spam-website-with-evasion-indicators-08bcd353
Link to auto-downloaded file with Adobe branding
Sublime Security
5mo ago
Jul 16th, 2025
/feeds/core/detection-rules/link-to-auto-downloaded-file-with-adobe-branding-e826c2cf
Link to auto-downloaded file with Google Drive branding
Sublime Security
5mo ago
Jul 16th, 2025
/feeds/core/detection-rules/link-to-auto-downloaded-file-with-google-drive-branding-4b5343be
Service abuse: Formester with suspicious link behavior
Sublime Security
3d ago
Dec 19th, 2025
/feeds/core/detection-rules/service-abuse-formester-with-suspicious-link-behavior-e4b74fd4
Suspicious recipient pattern and language with low reputation link to login
Sublime Security
1y ago
Apr 30th, 2024
/feeds/core/detection-rules/suspicious-recipient-pattern-and-language-with-low-reputation-link-to-login-a8ea0402
Suspicious recipients pattern with no Compauth pass and suspicious content
Sublime Security
4mo ago
Aug 5th, 2025
/feeds/core/detection-rules/suspicious-recipients-pattern-with-no-compauth-pass-and-suspicious-content-34fb65f6