Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Sep 30th, 2026
Feed Source
Detection Method is
Rule Name & Severity
Author
Last Updated
Labels
Service abuse: Coursera callback scam
Sublime Security
2mo ago
Jul 21st, 2026
Service abuse: EventCreate links to newly registered domains
Sublime Security
30d ago
Aug 31st, 2026
Service abuse: GitHub notification with excessive mentions and suspicious links
Sublime Security
5mo ago
Apr 7th, 2026
Service abuse: Google Drive share from new reply-to domain
Sublime Security
10mo ago
Nov 13th, 2025
Service abuse: Google Firebase sender address with suspicious content
Sublime Security
3mo ago
Jun 18th, 2026
Service abuse: Microsoft Forms Pro with suspicious links or QR codes
Sublime Security
2mo ago
Jul 14th, 2026
Service abuse: Self-service platform redirecting to newly registered suspicious domain
Sublime Security
20d ago
Sep 10th, 2026
Service abuse: Zoom Clips with suspicious reply-to address or links
Sublime Security
29d ago
Sep 1st, 2026
Service abuse: Zoom with newly registered reply-to domain
Sublime Security
4mo ago
May 4th, 2026
Spam: Cold outreach from Cloudflare-hosted newly registered domain
Sublime Security
1mo ago
Aug 17th, 2026
Spam: Fake photo share
Sublime Security
7d ago
Sep 23rd, 2026
Spam/fraud: Predatory journal/research paper request
Sublime Security
11mo ago
Nov 3rd, 2025
Spam: Large financial amount mention from newly registered sender domain
Sublime Security
1mo ago
Aug 3rd, 2026
Spam: New link domain (<=10d) and emojis
Sublime Security
1y ago
Jul 16th, 2025
Suspected lookalike domain with suspicious language
Sublime Security
8mo ago
Jan 12th, 2026
Suspicious newly registered reply-to domain with engaging financial or urgent language
Sublime Security
7d ago
Sep 23rd, 2026
Vendor compromise: GovDelivery message with suspicious link
Sublime Security
1y ago
Aug 5th, 2025
Vendor impersonation: Thread hijacking with typosquat domain
Sublime Security
8mo ago
Jan 12th, 2026
VIP impersonation: Fake thread with display name match, email mismatch
Sublime Security
5mo ago
Apr 3rd, 2026