• Sublime Core Feed

Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Jan 23rd, 2026
Feed Source
Tactic or Technique is
Rule Name & Severity
Author
Last Updated
Labels
Brand impersonation: Evite
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/brand-impersonation-evite-9e867a2b
Brand impersonation: Exodus
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/brand-impersonation-exodus-40c77ecc
Brand impersonation: Fake DocuSign HTML table not linking to DocuSign domains
Sublime Security
1mo ago
Dec 10th, 2025
/feeds/core/detection-rules/brand-impersonation-fake-docusign-html-table-not-linking-to-docusign-domains-28923dde
Brand impersonation: Fake Fax
Sublime Security
2d ago
Jan 21st, 2026
/feeds/core/detection-rules/brand-impersonation-fake-fax-2a96b90a
Brand impersonation: Fastway
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/brand-impersonation-fastway-0170dbf2
Brand impersonation: FedEx
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/brand-impersonation-fedex-94a2b602
Brand impersonation: File sharing notification with template artifacts
Sublime Security
6h ago
Jan 23rd, 2026
/feeds/core/detection-rules/brand-impersonation-file-sharing-notification-with-template-artifacts-37d89611
Brand impersonation: FINRA
Sublime Security
3mo ago
Oct 3rd, 2025
/feeds/core/detection-rules/brand-impersonation-finra-15c81db4
Brand Impersonation: Gemini Trust Company
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/brand-impersonation-gemini-trust-company-99574c94
Brand impersonation: Github
Sublime Security
2mo ago
Nov 3rd, 2025
/feeds/core/detection-rules/brand-impersonation-github-9402f92b
Brand impersonation: GoDaddy
Sublime Security
4mo ago
Sep 17th, 2025
/feeds/core/detection-rules/brand-impersonation-godaddy-4130d555
Brand impersonation: Google Careers
Sublime Security
2mo ago
Nov 12th, 2025
/feeds/core/detection-rules/brand-impersonation-google-careers-cf2d97ad
Brand impersonation: Google Drive fake file share
Sublime Security
1mo ago
Dec 19th, 2025
/feeds/core/detection-rules/brand-impersonation-google-drive-fake-file-share-b424a941
Brand impersonation: Google fake sign-in warning
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/brand-impersonation-google-fake-sign-in-warning-2d998eee
Brand impersonation: Google using Microsoft Forms
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/brand-impersonation-google-using-microsoft-forms-1daac608
Brand impersonation: Google Workspace alert notification
Sublime Security
1mo ago
Dec 2nd, 2025
/feeds/core/detection-rules/brand-impersonation-google-workspace-alert-notification-143ffbc4
Brand impersonation: Greenvelope
Sublime Security
1mo ago
Dec 1st, 2025
/feeds/core/detection-rules/brand-impersonation-greenvelope-9cbbf9b8
Brand impersonation: Gusto
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/brand-impersonation-gusto-54025c1c
Brand impersonation: Hulu
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/brand-impersonation-hulu-6833de58
Brand impersonation: Interac
Sublime Security
2y ago
Sep 16th, 2024
/feeds/core/detection-rules/brand-impersonation-interac-50a883dc
Brand impersonation: Internal Revenue Service
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/brand-impersonation-internal-revenue-service-3c63f8e9
Brand impersonation: KnowBe4
Sublime Security
2y ago
Nov 25th, 2024
/feeds/core/detection-rules/brand-impersonation-knowbe4-7c798386
Brand impersonation: Ledger
Sublime Security
1y ago
Jan 3rd, 2025
/feeds/core/detection-rules/brand-impersonation-ledger-5f934755
Brand impersonation: LinkedIn
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/brand-impersonation-linkedin-1a0cde6d
Brand impersonation: Mailchimp
Sublime Security
4mo ago
Sep 22nd, 2025
/feeds/core/detection-rules/brand-impersonation-mailchimp-48b454c7
Brand impersonation: Meta and subsidiaries
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/brand-impersonation-meta-and-subsidiaries-e38f1e3b
Brand impersonation: MetaMask
Sublime Security
4mo ago
Sep 22nd, 2025
/feeds/core/detection-rules/brand-impersonation-metamask-ddb4c618
Brand impersonation: Microsoft
@amitchell516
3mo ago
Oct 9th, 2025
/feeds/core/detection-rules/brand-impersonation-microsoft-6e2f04e6
Brand impersonation: Microsoft fake sign-in alert
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/brand-impersonation-microsoft-fake-sign-in-alert-3f4c9e7a
Brand impersonation: Microsoft logo in HTML with fake quarantine release notification
Sublime Security
1mo ago
Dec 10th, 2025
/feeds/core/detection-rules/brand-impersonation-microsoft-logo-in-html-with-fake-quarantine-release-notification-f12c615c
Brand impersonation: Microsoft logo or suspicious language with open redirect
Sublime Security
2y ago
Mar 7th, 2024
/feeds/core/detection-rules/brand-impersonation-microsoft-logo-or-suspicious-language-with-open-redirect-27b8d8d8
Brand impersonation: Microsoft Planner with suspicious link
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/brand-impersonation-microsoft-planner-with-suspicious-link-ea363c08
Brand impersonation: Microsoft (QR code)
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/brand-impersonation-microsoft-qr-code-ed0f772a
Brand impersonation: Microsoft quarantine release notification in body
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/brand-impersonation-microsoft-quarantine-release-notification-in-body-6d19527c
Brand impersonation: Microsoft quarantine release notification in image attachment
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/brand-impersonation-microsoft-quarantine-release-notification-in-image-attachment-185db6b3
Brand impersonation: Microsoft Teams
Sublime Security
2y ago
Dec 3rd, 2024
/feeds/core/detection-rules/brand-impersonation-microsoft-teams-9cd53055
Brand impersonation: Microsoft Teams invitation
Sublime Security
1mo ago
Dec 15th, 2025
/feeds/core/detection-rules/brand-impersonation-microsoft-teams-invitation-46410ad8
Brand impersonation: Microsoft with embedded logo and credential theft language
Sublime Security
3mo ago
Oct 17th, 2025
/feeds/core/detection-rules/brand-impersonation-microsoft-with-embedded-logo-and-credential-theft-language-3ee9ef3d
Brand impersonation: Microsoft with low reputation links
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/brand-impersonation-microsoft-with-low-reputation-links-b59201b6
Brand impersonation: Navan
Sublime Security
4mo ago
Sep 22nd, 2025
/feeds/core/detection-rules/brand-impersonation-navan-3573e9a8
Brand impersonation: Netflix
min0k
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/brand-impersonation-netflix-9f39eea5
Brand impersonation: Norton
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/brand-impersonation-norton-32bd9efd
Brand impersonation: Office 365 mail service
Sublime Security
3mo ago
Oct 10th, 2025
/feeds/core/detection-rules/brand-impersonation-office-365-mail-service-51af3d4a
Brand impersonation: Okta
Sublime Security
4mo ago
Sep 23rd, 2025
/feeds/core/detection-rules/brand-impersonation-okta-b7a2989a
Brand impersonation: Outlook
Sublime Security
2y ago
May 29th, 2024
/feeds/core/detection-rules/brand-impersonation-outlook-1fe5bf7b
Brand Impersonation: PayPal
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/brand-impersonation-paypal-a6b2ceee
Brand impersonation: PNC
Sublime Security
3mo ago
Oct 9th, 2025
/feeds/core/detection-rules/brand-impersonation-pnc-1b5ae4fb
Brand Impersonation: Procore
Sublime Security
4mo ago
Sep 3rd, 2025
/feeds/core/detection-rules/brand-impersonation-procore-74baa1e5
Brand impersonation: Proofpoint secure messaging without legitimate indicators
Sublime Security
2mo ago
Nov 17th, 2025
/feeds/core/detection-rules/brand-impersonation-proofpoint-secure-messaging-without-legitimate-indicators-84b72d02
Brand impersonation: Punchbowl
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/brand-impersonation-punchbowl-58937ba0