Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Sep 9th, 2026
Feed Source
Tactic or Technique is
Rule Name & Severity
Author
Last Updated
Labels
VIP impersonation: Fake thread with VIPs missing email metadata
Sublime Security
30d ago
Aug 11th, 2026
VIP Impersonation via Google Group relay with suspicious indicators
Sublime Security
1mo ago
Aug 5th, 2026
VIP Impersonation: VIP handoff with fake forwarded invoice thread
Sublime Security
24d ago
Aug 17th, 2026
VIP impersonation: VIP name within a delimited subject with fake previous threads
Sublime Security
2mo ago
Jul 8th, 2026
VIP local_part impersonation from unsolicited sender
Sublime Security
1mo ago
Jul 29th, 2026