Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Jul 25th, 2026
Feed Source
Tactic or Technique is
Rule Name & Severity
Author
Last Updated
Labels
VIP impersonation: Fabricated thread history with fake VIP recipients
Sublime Security
18d ago
Jul 8th, 2026
VIP impersonation: Fake forwarded indicator with VIP recipient impersonation
Sublime Security
19d ago
Jul 7th, 2026
VIP impersonation: Fake thread with display name match, email mismatch
Sublime Security
3mo ago
Apr 3rd, 2026
VIP Impersonation via Google Group relay with suspicious indicators
Sublime Security
1mo ago
Jun 5th, 2026
VIP impersonation: VIP recipient of previous thread with HTML generator
Sublime Security
19d ago
Jul 7th, 2026
Xero infrastructure abuse
Sublime Security
8mo ago
Nov 3rd, 2025