• Sublime Core Feed

Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Jan 23rd, 2026
Feed Source
Tactic or Technique is
Rule Name & Severity
Author
Last Updated
Labels
Link: Multistage landing - JotForm abuse
Sublime Security
1mo ago
Dec 1st, 2025
/feeds/core/detection-rules/link-multistage-landing-jotform-abuse-5b64326f
Link: Multistage landing - Ludus presentation
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-multistage-landing-ludus-presentation-a8b3c311
Link: Multistage landing - Scribd document
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-multistage-landing-scribd-document-afa9807d
Link: Obfuscation via userinfo with excessive URL padding
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-obfuscation-via-userinfo-with-excessive-url-padding-806317a3
Link: .onion From Unsolicited Sender
Sublime Security
5mo ago
Jul 30th, 2025
/feeds/core/detection-rules/link-onion-from-unsolicited-sender-9ac0fc83
Link: QR code in EML attachment with credential phishing indicators
Sublime Security
1mo ago
Dec 2nd, 2025
/feeds/core/detection-rules/link-qr-code-in-eml-attachment-with-credential-phishing-indicators-9908ed3a
Link: Referrer anonymization service from untrusted sender
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-referrer-anonymization-service-from-untrusted-sender-9fab2e1e
Link: ScreenConnect installer with suspicious relay domain
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-screenconnect-installer-with-suspicious-relay-domain-37d21eef
Link: Scribd fullscreen link from suspicious sender
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-scribd-fullscreen-link-from-suspicious-sender-9e9bc972
Link: Secure SharePoint file share from new or unusual sender
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-secure-sharepoint-file-share-from-new-or-unusual-sender-74ed3020
Link: Self-sender with sender org in subject and credential theft indicator
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-self-sender-with-sender-org-in-subject-and-credential-theft-indicator-bfa9aa08
Link: Self-sent message with quarterly document review request
Sublime Security
2d ago
Jan 21st, 2026
/feeds/core/detection-rules/link-self-sent-message-with-quarterly-document-review-request-3c42cec6
Link: SharePoint files shared from GoDaddy federated tenants
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/link-sharepoint-files-shared-from-godaddy-federated-tenants-0e26cdd2
Link: Spam website with evasion indicators
Sublime Security
1mo ago
Nov 25th, 2025
/feeds/core/detection-rules/link-spam-website-with-evasion-indicators-08bcd353
Link: Suspicious SharePoint document name
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-suspicious-sharepoint-document-name-f95fee6e
Link: Suspicious Sharepoint folder share
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-suspicious-sharepoint-folder-share-6168a08c
Link: Suspicious URL with recipient targeting and special characters
Sublime Security
1d ago
Jan 22nd, 2026
/feeds/core/detection-rules/link-suspicious-url-with-recipient-targeting-and-special-characters-e808be3a
Link to a domain with punycode characters
@ajpc500
2mo ago
Nov 12th, 2025
/feeds/core/detection-rules/link-to-a-domain-with-punycode-characters-74b3698c
Link to auto-downloaded disk image in encrypted zip
@ajpc500
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-to-auto-downloaded-disk-image-in-encrypted-zip-b50f0cb1
Link to auto-downloaded DMG in archive
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/link-to-auto-downloaded-dmg-in-archive-dc04cdd8
Link to auto-downloaded DMG in encrypted zip
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/link-to-auto-downloaded-dmg-in-encrypted-zip-43af98d3
Link to auto-download of a suspicious file type (unsolicited)
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-to-auto-download-of-a-suspicious-file-type-unsolicited-67ae2152
Link: Tycoon2FA phishing kit (non-exhaustive)
Sublime Security
18h ago
Jan 23rd, 2026
/feeds/core/detection-rules/link-tycoon2fa-phishing-kit-non-exhaustive-a070d4e2
Link: URL scheme obfuscation via split HTML anchors
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-url-scheme-obfuscation-via-split-html-anchors-10375948
Low reputation link to auto-downloaded HTML file with smuggling indicators
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/low-reputation-link-to-auto-downloaded-html-file-with-smuggling-indicators-339676c6
Malformed URL prefix
Sublime Security
4mo ago
Sep 4th, 2025
/feeds/core/detection-rules/malformed-url-prefix-4e659d28
MalwareBazaar: Malicious attachment hash in archive (trusted reporters)
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/malwarebazaar-malicious-attachment-hash-in-archive-trusted-reporters-9d734281
Malware: Pikabot delivery via URL auto-download
Sublime Security
2y ago
Apr 25th, 2024
/feeds/core/detection-rules/malware-pikabot-delivery-via-url-auto-download-f4be4572
Message traversed multiple onmicrosoft.com tenants
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/message-traversed-multiple-onmicrosoftcom-tenants-9cf01c0d
Microsoft infrastructure abuse with suspicious patterns
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/microsoft-infrastructure-abuse-with-suspicious-patterns-cfe8e804
Non-RFC compliant calendar files from unsolicited sender
Sublime Security
3mo ago
Oct 1st, 2025
/feeds/core/detection-rules/non-rfc-compliant-calendar-files-from-unsolicited-sender-9859f100
Notion suspicious file share
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/notion-suspicious-file-share-f7307929
Open redirect: Cartoon Network
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/open-redirect-cartoon-network-7435e057
Open redirect: giving.lluh.org
Sublime Security
8mo ago
May 23rd, 2025
/feeds/core/detection-rules/open-redirect-givinglluhorg-a2bf1099
Open Redirect: Google domain with /url path and suspicious indicators
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/open-redirect-google-domain-with-url-path-and-suspicious-indicators-fc5adf74
Open redirect: Klaviyo
Sublime Security
2y ago
May 14th, 2024
/feeds/core/detection-rules/open-redirect-klaviyo-ce5a370a
Open redirect: marketing.edinburghairport.com
Sublime Security
8mo ago
May 23rd, 2025
/feeds/core/detection-rules/open-redirect-marketingedinburghairportcom-33a47565
Open redirect: next2.io
Sublime Security
8mo ago
May 23rd, 2025
/feeds/core/detection-rules/open-redirect-next2io-5085c422
Open redirect: people.anuneo.com
Sublime Security
8mo ago
May 23rd, 2025
/feeds/core/detection-rules/open-redirect-peopleanuneocom-2ae83b73
Open redirect: Shibboleth SSO Logout Return Parameter
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/open-redirect-shibboleth-sso-logout-return-parameter-374b7517
Open redirect: slubnaglowie.pl
Sublime Security
8mo ago
May 23rd, 2025
/feeds/core/detection-rules/open-redirect-slubnaglowiepl-2ec356d0
Open redirect: typedrawers.com
Sublime Security
8mo ago
May 23rd, 2025
/feeds/core/detection-rules/open-redirect-typedrawerscom-158d9e95
Open redirect: weblinkconnect.com
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/open-redirect-weblinkconnectcom-967f7a11
Open redirect: Xfinity CMP Redirection to Google AMP
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/open-redirect-xfinity-cmp-redirection-to-google-amp-c0805b80
Outlook hyperlink bypass: left-to-right mark (LRM) in base HTML tag
Sublime Security
1mo ago
Dec 10th, 2025
/feeds/core/detection-rules/outlook-hyperlink-bypass-left-to-right-mark-lrm-in-base-html-tag-160cc681
PayPal invoice abuse
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/paypal-invoice-abuse-0ff7a0d4
PhaaS: Impact Solutions (Impact Vector Suite)
Sublime Security
3h ago
Jan 23rd, 2026
/feeds/core/detection-rules/phaas-impact-solutions-impact-vector-suite-4d197faf
Potential prompt injection attack in body HTML
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/potential-prompt-injection-attack-in-body-html-5fb24736
Punycode sender domain
Sublime Security
3y ago
Aug 21st, 2023
/feeds/core/detection-rules/punycode-sender-domain-bc3d8db5
QR code to auto-download of a suspicious file type (unsolicited)
Sublime Security
3mo ago
Oct 17th, 2025
/feeds/core/detection-rules/qr-code-to-auto-download-of-a-suspicious-file-type-unsolicited-eed87ea2