Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Sep 30th, 2026
Feed Source
Tactic or Technique is
Rule Name & Severity
Author
Last Updated
Labels
Service abuse: Monday.com callback scam
Sublime Security
8mo ago
Jan 26th, 2026
Service abuse: Postman reply-to mismatch with credential theft intent
Sublime Security
2mo ago
Jul 29th, 2026
Service abuse: Self-service platform redirecting to newly registered suspicious domain
Sublime Security
20d ago
Sep 10th, 2026
Service abuse: Settime.io sender with callback scam intent
Sublime Security
3mo ago
Jun 24th, 2026
Service abuse: WeTransfer callback scam
Sublime Security
8mo ago
Jan 30th, 2026
Service abuse: Zohodesk reply-to mismatch with job scam indicators
Sublime Security
2mo ago
Jul 22nd, 2026
VIP Impersonation: VIP handoff with fake forwarded invoice thread
Sublime Security
1mo ago
Aug 17th, 2026