• Sublime Core Feed

Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Jan 6th, 2026
Feed Source
Rule Name & Severity
Author
Last Updated
Labels
Attachment: Callback phishing solicitation via pdf file
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/attachment-callback-phishing-solicitation-via-pdf-file-ac33f097
Attachment: Legal themed message or PDF with suspicious indicators
Sublime Security
1mo ago
Dec 1st, 2025
/feeds/core/detection-rules/attachment-legal-themed-message-or-pdf-with-suspicious-indicators-19133301
Body: Embedded email headers indicative of thread hijacking/abuse
Sublime Security
1mo ago
Dec 1st, 2025
/feeds/core/detection-rules/body-embedded-email-headers-indicative-of-thread-hijackingabuse-6e8eeebb
Brand impersonation: Google Drive fake file share
Sublime Security
18d ago
Dec 19th, 2025
/feeds/core/detection-rules/brand-impersonation-google-drive-fake-file-share-b424a941
Brand impersonation: Microsoft with low reputation links
Sublime Security
27d ago
Dec 10th, 2025
/feeds/core/detection-rules/brand-impersonation-microsoft-with-low-reputation-links-b59201b6
Brand impersonation: Sharepoint fake file share
Sublime Security
27d ago
Dec 10th, 2025
/feeds/core/detection-rules/brand-impersonation-sharepoint-fake-file-share-ff8b296b
Brand impersonation: Wells Fargo
Sublime Security
11mo ago
Jan 15th, 2025
/feeds/core/detection-rules/brand-impersonation-wells-fargo-02d7301f
Fake message thread - Untrusted sender with a mismatched freemail reply-to address
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/fake-message-thread-untrusted-sender-with-a-mismatched-freemail-reply-to-address-ca64e819
Fake thread with suspicious indicators
Sublime Security
28d ago
Dec 9th, 2025
/feeds/core/detection-rules/fake-thread-with-suspicious-indicators-c2e18a57
HTML smuggling with atob in message body
Sublime Security
3y ago
Aug 17th, 2023
/feeds/core/detection-rules/html-smuggling-with-atob-in-message-body-0f86851f
Impersonation: Fake Gmail attachment
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/impersonation-fake-gmail-attachment-0f5a4e14
Impersonation: SharePoint reply header anomaly
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/impersonation-sharepoint-reply-header-anomaly-78875848
Impersonation: Suspected supplier impersonation with suspicious content
Sublime Security
11mo ago
Feb 3rd, 2025
/feeds/core/detection-rules/impersonation-suspected-supplier-impersonation-with-suspicious-content-63d8b1ce
Link: Secure SharePoint file share from new or unusual sender
Sublime Security
4mo ago
Sep 5th, 2025
/feeds/core/detection-rules/link-secure-sharepoint-file-share-from-new-or-unusual-sender-74ed3020
Link to Google Apps Script macro via comment tagging
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-to-google-apps-script-macro-via-comment-tagging-66fecd30
Link: Zoho form link from unsolicited sender
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-zoho-form-link-from-unsolicited-sender-eb04a9f2
Malformed URL prefix
Sublime Security
4mo ago
Sep 4th, 2025
/feeds/core/detection-rules/malformed-url-prefix-4e659d28
Service abuse: Random Google Firebase sender address with suspicious content
Sublime Security
1mo ago
Nov 26th, 2025
/feeds/core/detection-rules/service-abuse-random-google-firebase-sender-address-with-suspicious-content-9f8899a9
Spam: Attendee list solicitation
Sublime Security
4mo ago
Aug 29th, 2025
/feeds/core/detection-rules/spam-attendee-list-solicitation-69715b62
Spam: Fake photo share
Sublime Security
1mo ago
Nov 8th, 2025
/feeds/core/detection-rules/spam-fake-photo-share-eb086f7d
Spam: New link domain (<=10d) and emojis
Sublime Security
5mo ago
Jul 16th, 2025
/feeds/core/detection-rules/spam-new-link-domain-less10d-and-emojis-33677993
Spam: URL shortener with short body content and emojis
Sublime Security
5mo ago
Jul 23rd, 2025
/feeds/core/detection-rules/spam-url-shortener-with-short-body-content-and-emojis-b7797e4c
Suspicious invoice reference with missing or image-only attachments
Sublime Security
1mo ago
Dec 2nd, 2025
/feeds/core/detection-rules/suspicious-invoice-reference-with-missing-or-image-only-attachments-466c1680
URL with Unicode U+2044 (⁄) or U+2215 (∕) characters
@delivr_to
2y ago
Feb 23rd, 2024
/feeds/core/detection-rules/url-with-unicode-u2044-or-u2215-characters-12069f5b
VIP impersonation: Fake thread with display name match, email mismatch
Sublime Security
2y ago
Jul 29th, 2024
/feeds/core/detection-rules/vip-impersonation-fake-thread-with-display-name-match-email-mismatch-11cc3e28
VIP impersonation with charitable donation fraud
Sublime Security
1mo ago
Nov 12th, 2025
/feeds/core/detection-rules/vip-impersonation-with-charitable-donation-fraud-35a56b8e