• Sublime Core Feed

Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Jan 23rd, 2026
Feed Source
Tactic or Technique is
Rule Name & Severity
Author
Last Updated
Labels
Attachment: USDA bid invitation impersonation
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/attachment-usda-bid-invitation-impersonation-34eb9493
Attachment with VBA macros from employee impersonation (unsolicited)
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/attachment-with-vba-macros-from-employee-impersonation-unsolicited-9b262123
BEC: Employee impersonation with subject manipulation
Sublime Security
7d ago
Jan 16th, 2026
/feeds/core/detection-rules/bec-employee-impersonation-with-subject-manipulation-9adfc77b
BEC/Fraud: Generic scam attempt to undisclosed recipients
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/becfraud-generic-scam-attempt-to-undisclosed-recipients-5dac401f
BEC/Fraud: Penpal scam
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/becfraud-penpal-scam-a4bdfa17
BEC/Fraud: Romance scam
Sublime Security
1d ago
Jan 22nd, 2026
/feeds/core/detection-rules/becfraud-romance-scam-0243cdaa
BEC/Fraud: Student loan callback phishing
Sublime Security
4mo ago
Sep 5th, 2025
/feeds/core/detection-rules/becfraud-student-loan-callback-phishing-a71f82c3
BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/becfraud-urgent-language-and-suspicious-sendinginfrastructure-patterns-ba8a79e0
BEC with unusual reply-to or return-path mismatch
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/bec-with-unusual-reply-to-or-return-path-mismatch-83e5e2df
Benefits enrollment impersonation
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/benefits-enrollment-impersonation-5a6eb5a8
Body: Embedded email headers indicative of thread hijacking/abuse
Sublime Security
1mo ago
Dec 1st, 2025
/feeds/core/detection-rules/body-embedded-email-headers-indicative-of-thread-hijackingabuse-6e8eeebb
Body HTML: Recipient SLD in HTML class
Sublime Security
4mo ago
Sep 23rd, 2025
/feeds/core/detection-rules/body-html-recipient-sld-in-html-class-d395e41d
Brand impersonation: AARP
Sublime Security
1mo ago
Dec 1st, 2025
/feeds/core/detection-rules/brand-impersonation-aarp-561a7f87
Brand impersonation: Adobe Sign with suspicious indicators
Sublime Security
15d ago
Jan 8th, 2026
/feeds/core/detection-rules/brand-impersonation-adobe-sign-with-suspicious-indicators-704d143a
Brand impersonation: Adobe with suspicious language and link
Sublime Security
2mo ago
Nov 24th, 2025
/feeds/core/detection-rules/brand-impersonation-adobe-with-suspicious-language-and-link-32cc8bf1
Brand impersonation: ADP
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/brand-impersonation-adp-bb9cf46b
Brand impersonation: AliExpress
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/brand-impersonation-aliexpress-b14703d8
Brand impersonation: Amazon
Sublime Security
2mo ago
Nov 4th, 2025
/feeds/core/detection-rules/brand-impersonation-amazon-13fc967d
Brand impersonation: Amazon Web Services (AWS)
Sublime Security
3mo ago
Oct 10th, 2025
/feeds/core/detection-rules/brand-impersonation-amazon-web-services-aws-31de94e0
Brand impersonation: Amazon with suspicious attachment
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/brand-impersonation-amazon-with-suspicious-attachment-5751dcb9
Brand impersonation: American Express (AMEX)
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/brand-impersonation-american-express-amex-992a9fa9
Brand impersonation: Apple
Sublime Security
3y ago
Aug 21st, 2023
/feeds/core/detection-rules/brand-impersonation-apple-0b17f2c2
Brand impersonation: Aquent
Sublime Security
3mo ago
Oct 9th, 2025
/feeds/core/detection-rules/brand-impersonation-aquent-5074459c
Brand impersonation: Aramco
Sublime Security
2mo ago
Nov 20th, 2025
/feeds/core/detection-rules/brand-impersonation-aramco-96e87699
Brand impersonation: AuthentiSign
Sublime Security
2d ago
Jan 21st, 2026
/feeds/core/detection-rules/brand-impersonation-authentisign-445a8c8b
Brand impersonation: Bank of America
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/brand-impersonation-bank-of-america-d2fc6ea1
Brand impersonation: Barracuda Networks
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/brand-impersonation-barracuda-networks-583fd5eb
Brand impersonation: Binance
Sublime Security
4mo ago
Sep 3rd, 2025
/feeds/core/detection-rules/brand-impersonation-binance-c3302a76
Brand impersonation: Blockchain[.]com
Sublime Security
2d ago
Jan 21st, 2026
/feeds/core/detection-rules/brand-impersonation-blockchaincom-0d85e555
Brand impersonation: Booking.com
Sublime Security
2mo ago
Nov 3rd, 2025
/feeds/core/detection-rules/brand-impersonation-bookingcom-d1d8882f
Brand impersonation: Box file sharing service
Sublime Security
4mo ago
Sep 23rd, 2025
/feeds/core/detection-rules/brand-impersonation-box-file-sharing-service-03da310c
Brand impersonation: Capital One
Sublime Security
2mo ago
Nov 17th, 2025
/feeds/core/detection-rules/brand-impersonation-capital-one-d53848e4
Brand impersonation: Charles Schwab
Sublime Security
4mo ago
Sep 3rd, 2025
/feeds/core/detection-rules/brand-impersonation-charles-schwab-7abde595
Brand impersonation: Chase Bank
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/brand-impersonation-chase-bank-c680f1e7
Brand impersonation: Chase bank with credential phishing indicators
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/brand-impersonation-chase-bank-with-credential-phishing-indicators-d9577856
Brand impersonation: Coinbase
Sublime Security
2mo ago
Nov 4th, 2025
/feeds/core/detection-rules/brand-impersonation-coinbase-3dca757a
Brand impersonation: Dashlane
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/brand-impersonation-dashlane-9e400937
Brand impersonation: DHL
Sublime Security
1mo ago
Dec 1st, 2025
/feeds/core/detection-rules/brand-impersonation-dhl-be4b4ae0
Brand impersonation: DigitalOcean
Sublime Security
4mo ago
Sep 18th, 2025
/feeds/core/detection-rules/brand-impersonation-digitalocean-7f2f0e97
Brand impersonation: Discord notification
Sublime Security
3mo ago
Oct 23rd, 2025
/feeds/core/detection-rules/brand-impersonation-discord-notification-97007826
Brand Impersonation: Disney
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/brand-impersonation-disney-bf90b8fb
Brand impersonation: DocSend
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/brand-impersonation-docsend-cd9a3f7a
Brand impersonation: DocuSign
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/brand-impersonation-docusign-4d29235c
Brand impersonation: DocuSign branded attachment lure with no DocuSign links
Sublime Security
3mo ago
Oct 22nd, 2025
/feeds/core/detection-rules/brand-impersonation-docusign-branded-attachment-lure-with-no-docusign-links-814a5694
Brand impersonation: DocuSign PDF attachment with suspicious link
Sublime Security
3mo ago
Oct 22nd, 2025
/feeds/core/detection-rules/brand-impersonation-docusign-pdf-attachment-with-suspicious-link-2601cbb7
Brand impersonation: DocuSign (QR code)
Sublime Security
3mo ago
Oct 15th, 2025
/feeds/core/detection-rules/brand-impersonation-docusign-qr-code-0b16c28a
Brand impersonation: DoorDash
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/brand-impersonation-doordash-b0aaaed5
Brand impersonation: Dotloop
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/brand-impersonation-dotloop-f997581a
Brand impersonation: Dropbox
Sublime Security
1d ago
Jan 22nd, 2026
/feeds/core/detection-rules/brand-impersonation-dropbox-61f11d12
Brand impersonation: Enbridge
Sublime Security
12mo ago
Jan 24th, 2025
/feeds/core/detection-rules/brand-impersonation-enbridge-203a6a28