Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Sep 30th, 2026
Feed Source
Detection Method is
Rule Name & Severity
Author
Last Updated
Labels
Attachment: Calendar invite from recently registered domain
Sublime Security
5mo ago
Apr 28th, 2026
Attachment: DocuSign impersonation via PDF linking to new domain
Sublime Security
7d ago
Sep 23rd, 2026
Attachment: Embedded MSG file with payment lure and newly registered domain
Sublime Security
5d ago
Sep 25th, 2026
Attachment: ICS calendar invite with bid/RFP lure and suspicious link
Sublime Security
2d ago
Sep 28th, 2026
Attachment: ICS calendar invite with financial lure and suspicious link
Sublime Security
30d ago
Aug 31st, 2026
Attachment: ICS calendar with suspicious link Leading to minimal JS landing page
Sublime Security
2d ago
Sep 28th, 2026
Attachment: ICS file with credential theft indicators
Sublime Security
2d ago
Sep 28th, 2026
Attachment: ICS file with links to newly registered domains
Sublime Security
5mo ago
Apr 20th, 2026
Attachment: ICS voicemail lure with suspicious link
Sublime Security
2d ago
Sep 28th, 2026
Attachment: Legal themed message or PDF with suspicious indicators
Sublime Security
15d ago
Sep 15th, 2026
Attachment: PDF with multistage landing - ClickUp abuse
Sublime Security
7mo ago
Feb 27th, 2026
BEC: Financial fraud from newly registered sender domain
Sublime Security
3mo ago
Jun 25th, 2026
BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns
Sublime Security
5mo ago
Apr 17th, 2026
BEC: Wealth management lure from newly registered domain
Sublime Security
22d ago
Sep 8th, 2026
Brand impersonation: Anthropic/Claude with newly registered domain
Sublime Security
2mo ago
Jul 24th, 2026
Brand impersonation: Microsoft fake sign-in alert
Sublime Security
2mo ago
Jul 27th, 2026
Brand Impersonation: OpenAI with ChatGPT Ads lure
Sublime Security
3mo ago
Jun 24th, 2026
Brand impersonation: SharePoint PDF attachment with credential theft language
Sublime Security
7d ago
Sep 23rd, 2026
Brand impersonation: Silicon Valley Bank
Sublime Security
8mo ago
Jan 12th, 2026
Brand impersonation: Stripe notification
Sublime Security
7d ago
Sep 23rd, 2026
Callback phishing: Branded invoice from sender/reply-to domain less than 30 days old
Sublime Security
11mo ago
Oct 17th, 2025
Credential phishing: Fake security alert from newly registered domain
Sublime Security
13d ago
Sep 17th, 2026
Fraudulent order confirmation/shipping notification from Chinese sender domain
Sublime Security
8mo ago
Jan 12th, 2026
Generic service abuse from newly registered domain
Sublime Security
1y ago
Aug 5th, 2025
Impersonation: Suspected supplier impersonation with suspicious content
Sublime Security
2mo ago
Jul 27th, 2026
Link: Abused Adobe Express
Sublime Security
1y ago
Jul 23rd, 2025
Link: Commonly Abused Web Service redirecting to ZIP file
Sublime Security
6mo ago
Mar 10th, 2026
Link: Cryptocurrency fraud with suspicious links
Sublime Security
10mo ago
Dec 1st, 2025
Link: Document-themed link to newly registered domain
Sublime Security
1mo ago
Aug 18th, 2026
Link: Fake video link from newly registered domain
Sublime Security
22d ago
Sep 8th, 2026
Link: Financial account issue with suspicious indicators
Sublime Security
6mo ago
Mar 24th, 2026
Link: Google Firebase dynamic link that redirects to new domain (<7 days old)
@ajpc500
8mo ago
Jan 12th, 2026
Link: Multistage landing - Abused Adobe frame.io
Sublime Security
1y ago
Aug 5th, 2025
Link: Multistage landing - Abused Docusign
Sublime Security
1y ago
Aug 5th, 2025
Link: Multistage landing - Abused Google Drive
Sublime Security
1y ago
Aug 5th, 2025
Link: Multistage landing - ClickUp abuse
Sublime Security
7mo ago
Feb 27th, 2026
Link: Multistage landing - Published Google Doc
Sublime Security
1y ago
Aug 5th, 2025
Link: Newly registered domain in reference lure
Sublime Security
1d ago
Sep 29th, 2026
Link: Newly registered suspicious domain with single-character HTML filename
Sublime Security
5d ago
Sep 25th, 2026
Link: Observed URL pattern with specific domain registrar
Sublime Security
3mo ago
Jun 12th, 2026
Link: Recently registered .vu domain in lure
Sublime Security
1mo ago
Aug 28th, 2026
Link: Romance/Sexual Language With Suspicious Link
Sublime Security
23h ago
Sep 29th, 2026
Link: Tax document lure Portuguese/Spanish with suspicious domains
Sublime Security
5mo ago
Apr 14th, 2026
New link domain (<=10d) from untrusted sender
Sublime Security
1mo ago
Aug 10th, 2026
Newly registered sender or reply-to domain with newly registered linked domain
Sublime Security
1y ago
Aug 5th, 2025
New sender domain (<=10d) from untrusted sender
Sublime Security
2y ago
Nov 20th, 2024
Open redirect: Recipient address embedded in redirect URL pointing to newly registered domain
Sublime Security
2mo ago
Jul 24th, 2026
Recruitee Infrastructure Abuse
Sublime Security
1y ago
Jul 16th, 2025
Service abuse: Adobe message from newly registered domain
Sublime Security
2mo ago
Jul 31st, 2026
Service abuse: AppSheet infrastructure with suspicious indicators
Sublime Security
11mo ago
Oct 6th, 2025