• Sublime Core Feed

Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Jan 23rd, 2026
Feed Source
Tactic or Technique is
Rule Name & Severity
Author
Last Updated
Labels
Attachment: SFX archive containing commands
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/attachment-sfx-archive-containing-commands-343e6c8c
Attachment: Small text file with link containing recipient email address
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/attachment-small-text-file-with-link-containing-recipient-email-address-c0472c9d
Attachment: Suspicious employee policy update document lure
Sublime Security
28d ago
Dec 26th, 2025
/feeds/core/detection-rules/attachment-suspicious-employee-policy-update-document-lure-a8bf1fd1
Attachment: Suspicious PDF created with headless browser
Sublime Security
4mo ago
Sep 17th, 2025
/feeds/core/detection-rules/attachment-suspicious-pdf-created-with-headless-browser-8f3108d7
Attachment: SVG files with evasion elements
Sublime Security
5mo ago
Aug 8th, 2025
/feeds/core/detection-rules/attachment-svg-files-with-evasion-elements-5d2dbb60
Attachment: Web files with suspicious comments
Sublime Security
5mo ago
Aug 8th, 2025
/feeds/core/detection-rules/attachment-web-files-with-suspicious-comments-93061d17
Attachment: WinRAR CVE-2025-8088 exploitation
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/attachment-winrar-cve-2025-8088-exploitation-33b3a82b
Attachment with encrypted zip (unsolicited)
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/attachment-with-encrypted-zip-unsolicited-697c87ae
Attachment with macro calling executable
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/attachment-with-macro-calling-executable-5ee6a197
Attachment with unscannable encrypted zip (unsolicited)
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/attachment-with-unscannable-encrypted-zip-unsolicited-529d4a9a
Attachment: XLSX file with suspicious print titles metadata
Sublime Security
4mo ago
Sep 16th, 2025
/feeds/core/detection-rules/attachment-xlsx-file-with-suspicious-print-titles-metadata-4c265cbe
BEC with unusual reply-to or return-path mismatch
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/bec-with-unusual-reply-to-or-return-path-mismatch-83e5e2df
Benefits enrollment impersonation
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/benefits-enrollment-impersonation-5a6eb5a8
Body: Embedded email headers indicative of thread hijacking/abuse
Sublime Security
1mo ago
Dec 1st, 2025
/feeds/core/detection-rules/body-embedded-email-headers-indicative-of-thread-hijackingabuse-6e8eeebb
Body HTML: Recipient SLD in HTML class
Sublime Security
4mo ago
Sep 23rd, 2025
/feeds/core/detection-rules/body-html-recipient-sld-in-html-class-d395e41d
Brand impersonation: Coinbase with suspicious links
Sublime Security
4mo ago
Sep 22nd, 2025
/feeds/core/detection-rules/brand-impersonation-coinbase-with-suspicious-links-b61e2f8e
Brand impersonation: DocuSign with embedded QR code
Sublime Security
3mo ago
Oct 17th, 2025
/feeds/core/detection-rules/brand-impersonation-docusign-with-embedded-qr-code-f5cde463
Brand impersonation: File sharing notification with template artifacts
Sublime Security
3h ago
Jan 23rd, 2026
/feeds/core/detection-rules/brand-impersonation-file-sharing-notification-with-template-artifacts-37d89611
Brand impersonation: Microsoft logo in HTML with fake quarantine release notification
Sublime Security
1mo ago
Dec 10th, 2025
/feeds/core/detection-rules/brand-impersonation-microsoft-logo-in-html-with-fake-quarantine-release-notification-f12c615c
Brand impersonation: Microsoft Planner with suspicious link
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/brand-impersonation-microsoft-planner-with-suspicious-link-ea363c08
Brand impersonation: QuickBooks notification from Intuit themed company name
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/brand-impersonation-quickbooks-notification-from-intuit-themed-company-name-42058fc4
Brand Impersonation: ShareFile
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/brand-impersonation-sharefile-f8330307
Brand impersonation: SharePoint PDF attachment with credential theft language
Sublime Security
2mo ago
Nov 7th, 2025
/feeds/core/detection-rules/brand-impersonation-sharepoint-pdf-attachment-with-credential-theft-language-ae3756fa
Brand impersonation: Stripe notification
Sublime Security
3mo ago
Sep 26th, 2025
/feeds/core/detection-rules/brand-impersonation-stripe-notification-3ffd2b03
Brand impersonation: Zoom
Sublime Security
4mo ago
Sep 22nd, 2025
/feeds/core/detection-rules/brand-impersonation-zoom-5abad540
Business Email Compromise (BEC) attempt with masked recipients and reply-to mismatch (unsolicited)
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/business-email-compromise-bec-attempt-with-masked-recipients-and-reply-to-mismatch-unsolicited-682191bf
Callback phishing: Social Security Administration fraud
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/callback-phishing-social-security-administration-fraud-a9049d52
Callback phishing: SumUp infrastructure abuse
Sublime Security
4mo ago
Sep 5th, 2025
/feeds/core/detection-rules/callback-phishing-sumup-infrastructure-abuse-1c41649e
Callback phishing via Adobe Sign comment
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/callback-phishing-via-adobe-sign-comment-7eb4516d
Callback phishing via calendar invite
Sublime Security
1d ago
Jan 22nd, 2026
/feeds/core/detection-rules/callback-phishing-via-calendar-invite-95c84360
Callback phishing via DocuSign comment
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/callback-phishing-via-docusign-comment-48aec918
Callback phishing via Intuit service abuse
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/callback-phishing-via-intuit-service-abuse-f2fe1294
Callback phishing via Zelle Service Abuse
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/callback-phishing-via-zelle-service-abuse-08727484
Callback phishing via Zoho service abuse
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/callback-phishing-via-zoho-service-abuse-61e351ec
Canva design with suspicious embedded link
Sublime Security
3mo ago
Sep 29th, 2025
/feeds/core/detection-rules/canva-design-with-suspicious-embedded-link-02959e22
Credential phishing: Generic document sharing
Sublime Security
1mo ago
Dec 8th, 2025
/feeds/core/detection-rules/credential-phishing-generic-document-sharing-9f0e1d2c
Credential phishing: Hyper-linked image leading to free file host
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/credential-phishing-hyper-linked-image-leading-to-free-file-host-f5cb1eca
Credential phishing: Image as content, short or no body contents
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/credential-phishing-image-as-content-short-or-no-body-contents-01313f38
Credential Phishing: Suspicious language, link, recipients and other indicators
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/credential-phishing-suspicious-language-link-recipients-and-other-indicators-dcb39190
Credential Phishing via Dropbox comment abuse
Sublime Security
4mo ago
Sep 22nd, 2025
/feeds/core/detection-rules/credential-phishing-via-dropbox-comment-abuse-744d494d
Credential theft: Gophish abuse with hidden tracking image
Sublime Security
2mo ago
Nov 5th, 2025
/feeds/core/detection-rules/credential-theft-gophish-abuse-with-hidden-tracking-image-59915ceb
Credential theft with 'safe content' deception and social engineering topics
Sublime Security
18d ago
Jan 5th, 2026
/feeds/core/detection-rules/credential-theft-with-safe-content-deception-and-social-engineering-topics-22ceee0d
CVE-2023-5631 - Roundcube Webmail XSS via crafted SVG
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/cve-2023-5631-roundcube-webmail-xss-via-crafted-svg-8405d61b
Cyrillic vowel substitution in subject or display name from unknown sender
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/cyrillic-vowel-substitution-in-subject-or-display-name-from-unknown-sender-74bc0b0c
Cyrillic vowel substitutions with suspicious subject from unknown sender
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/cyrillic-vowel-substitutions-with-suspicious-subject-from-unknown-sender-10251c3c
Display Name Emoji with Financial Symbols
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/display-name-emoji-with-financial-symbols-f316f335
EML attachment with credential theft language (unknown sender)
Sublime Security
3mo ago
Oct 3rd, 2025
/feeds/core/detection-rules/eml-attachment-with-credential-theft-language-unknown-sender-00e06af1
Encrypted Microsoft Office files from untrusted sender
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/encrypted-microsoft-office-files-from-untrusted-sender-eb7b26e7
Fake shipping notification with suspicious language
Sublime Security
2y ago
May 3rd, 2024
/feeds/core/detection-rules/fake-shipping-notification-with-suspicious-language-67748b0a
Fake thread with suspicious indicators
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/fake-thread-with-suspicious-indicators-c2e18a57