Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Sep 9th, 2026
Feed Source
Detection Method is
Rule Name & Severity
Author
Last Updated
Labels
Attachment: DOCX with hyperlink targeting recipient address
Sublime Security
8mo ago
Dec 17th, 2025
Attachment: Embedded Javascript in SVG file
Sublime Security
8mo ago
Jan 12th, 2026
Attachment: SVG files with evasion elements
Sublime Security
4mo ago
May 8th, 2026
Attachment: SVG file with hyperlinks and cursor styling
Sublime Security
3mo ago
May 20th, 2026
Attachment: Targeted DOCX with personalized recipient acknowledgement lure
Sublime Security
1mo ago
Aug 4th, 2026
Attachment: Word document with hyperlink and fraud language
Sublime Security
6d ago
Sep 4th, 2026