Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Sep 9th, 2026
Feed Source
Tactic or Technique is
Rule Name & Severity
Author
Last Updated
Labels
VIP impersonation: Invoice fraud with mobile device sign-off
Sublime Security
1mo ago
Aug 10th, 2026
VIP impersonation: Payment handoff with VIP display name authored fake threads
Sublime Security
17d ago
Aug 24th, 2026
VIP Impersonation via Google Group relay with suspicious indicators
Sublime Security
1mo ago
Aug 5th, 2026
VIP Impersonation: VIP handoff with fake forwarded invoice thread
Sublime Security
24d ago
Aug 17th, 2026
VIP impersonation: VIP name within a delimited subject with fake previous threads
Sublime Security
2mo ago
Jul 8th, 2026
VIP impersonation: VIP payment redirect handoff via fake threads
Sublime Security
1mo ago
Aug 10th, 2026
VIP impersonation: VIP recipient of previous thread with HTML generator
Sublime Security
2mo ago
Jul 7th, 2026
VIP impersonation with BEC language (near match, untrusted sender)
Sublime Security
5mo ago
Mar 25th, 2026
VIP impersonation with charitable donation fraud
Sublime Security
3mo ago
Jun 5th, 2026
VIP impersonation with urgent request (strict match, untrusted sender)
Sublime Security
5mo ago
Mar 25th, 2026
Xero infrastructure abuse
Sublime Security
10mo ago
Nov 3rd, 2025
Xero invoice abuse
Sublime Security
8mo ago
Dec 17th, 2025
X (Twitter) impersonation with credential phishing motives
Sublime Security
3mo ago
May 15th, 2026
Zoom Events newsletter abuse
Sublime Security
2mo ago
Jul 8th, 2026