• Sublime Core Feed

Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Jan 23rd, 2026
Feed Source
Tactic or Technique is
Rule Name & Severity
Author
Last Updated
Labels
Link: chatbot.page platform abuse
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-chatbotpage-platform-abuse-bfd6a076
Link: Credential phishing traversing Russian infrastructure
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-credential-phishing-traversing-russian-infrastructure-a5203e3b
Link: Credential phishing via WordPress
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-credential-phishing-via-wordpress-db696058
Link: Cryptocurrency fraud with suspicious links
Sublime Security
1mo ago
Dec 1st, 2025
/feeds/core/detection-rules/link-cryptocurrency-fraud-with-suspicious-links-d0da37ce
Link: Direct link to Zoom Docs from non-Zoom sender
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-direct-link-to-zoom-docs-from-non-zoom-sender-5c6362db
Link: Direct POWR.io Form Builder with suspicious patterns
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-direct-powrio-form-builder-with-suspicious-patterns-fd37cc93
Link: Display text matches subject line
Sublime Security
2mo ago
Nov 14th, 2025
/feeds/core/detection-rules/link-display-text-matches-subject-line-ba722cf0
Link: Executable file download with suspicious message content
Sublime Security
3mo ago
Oct 16th, 2025
/feeds/core/detection-rules/link-executable-file-download-with-suspicious-message-content-ce9a4926
Link: Figma design deck with credential theft language
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-figma-design-deck-with-credential-theft-language-87601924
Link: File sharing impersonation with suspicious language and sending patterns
Sublime Security
2mo ago
Oct 31st, 2025
/feeds/core/detection-rules/link-file-sharing-impersonation-with-suspicious-language-and-sending-patterns-d3363041
Link: File sharing pretext with suspicious body and link
Sublime Security
3mo ago
Oct 10th, 2025
/feeds/core/detection-rules/link-file-sharing-pretext-with-suspicious-body-and-link-c5718a8e
Link: Google Calendar invite linking to an open redirect from an untrusted freemail sender
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/link-google-calendar-invite-linking-to-an-open-redirect-from-an-untrusted-freemail-sender-bb4f1ea9
Link: HR impersonation with suspicious domain indicators and credential theft
Sublime Security
1mo ago
Dec 3rd, 2025
/feeds/core/detection-rules/link-hr-impersonation-with-suspicious-domain-indicators-and-credential-theft-f31f8831
Link: /index.php enclosed in three asterisks
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-indexphp-enclosed-in-three-asterisks-aa4bbafc
Link: Intuit link abuse with file share context
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-intuit-link-abuse-with-file-share-context-cd15cc34
Link: Invoice or receipt from freemail sender with customer service number
@vector_sec
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-invoice-or-receipt-from-freemail-sender-with-customer-service-number-3825232d
Link: Mamba 2FA phishing kit
Sublime Security
1mo ago
Dec 16th, 2025
/feeds/core/detection-rules/link-mamba-2fa-phishing-kit-8d527c0f
Link: Microsoft impersonation using hosted png with suspicious link
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-microsoft-impersonation-using-hosted-png-with-suspicious-link-07c696d4
Link: Microsoft protected message with matching sender and recipient addresses
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-microsoft-protected-message-with-matching-sender-and-recipient-addresses-a5a2f75d
Link: Multistage landing - Abused Adobe Acrobat hosted PDF
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-multistage-landing-abused-adobe-acrobat-hosted-pdf-609081ef
Link: Multistage Landing - Abused Buildin.ai
Sublime Security
4mo ago
Sep 5th, 2025
/feeds/core/detection-rules/link-multistage-landing-abused-buildinai-e0a79ef5
Link: Multistage landing - FreshDesk knowledge base abuse
Sublime Security
5mo ago
Aug 21st, 2025
/feeds/core/detection-rules/link-multistage-landing-freshdesk-knowledge-base-abuse-edd6acf7
Link: Multistage landing - JotForm abuse
Sublime Security
1mo ago
Dec 1st, 2025
/feeds/core/detection-rules/link-multistage-landing-jotform-abuse-5b64326f
Link: Multistage landing - Ludus presentation
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-multistage-landing-ludus-presentation-a8b3c311
Link: Multistage landing - Microsoft Forms abuse
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-multistage-landing-microsoft-forms-abuse-85a2cd12
Link: Multistage landing - Published Google Doc
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-multistage-landing-published-google-doc-031e1ff8
Link: Multistage landing - Scribd document
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-multistage-landing-scribd-document-afa9807d
Link: Multistage landing - Trello board abuse
Sublime Security
5mo ago
Aug 20th, 2025
/feeds/core/detection-rules/link-multistage-landing-trello-board-abuse-14a5b23a
Link: MyActiveCampaign Link Abuse
Sublime Security
5mo ago
Aug 20th, 2025
/feeds/core/detection-rules/link-myactivecampaign-link-abuse-f5b91ce5
Link: .onion From Unsolicited Sender
Sublime Security
5mo ago
Jul 30th, 2025
/feeds/core/detection-rules/link-onion-from-unsolicited-sender-9ac0fc83
Link: PDF and financial display text to free file host
Sublime Security
4mo ago
Sep 24th, 2025
/feeds/core/detection-rules/link-pdf-and-financial-display-text-to-free-file-host-b010740b
Link: Personal SharePoint with invalid recipients and credential theft language
Sublime Security
13h ago
Jan 23rd, 2026
/feeds/core/detection-rules/link-personal-sharepoint-with-invalid-recipients-and-credential-theft-language-79d5403d
Link: QR code with phishing disposition in img or pdf
Sublime Security
5mo ago
Jul 30th, 2025
/feeds/core/detection-rules/link-qr-code-with-phishing-disposition-in-img-or-pdf-8e8949f6
Link: QR Code with suspicious language (untrusted sender)
Sublime Security
5mo ago
Jul 30th, 2025
/feeds/core/detection-rules/link-qr-code-with-suspicious-language-untrusted-sender-25a84d1c
Link: QuickBooks image lure with suspicious link
Sublime Security
6mo ago
Jul 23rd, 2025
/feeds/core/detection-rules/link-quickbooks-image-lure-with-suspicious-link-3826a923
Link: Romance/Sexual Language With Suspicious Link
Sublime Security
5mo ago
Aug 22nd, 2025
/feeds/core/detection-rules/link-romancesexual-language-with-suspicious-link-d5694cae
Link: ScreenConnect installer with suspicious relay domain
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-screenconnect-installer-with-suspicious-relay-domain-37d21eef
Link: Scribd fullscreen link from suspicious sender
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-scribd-fullscreen-link-from-suspicious-sender-9e9bc972
Link: Self-sender with sender org in subject and credential theft indicator
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-self-sender-with-sender-org-in-subject-and-credential-theft-indicator-bfa9aa08
Link: Self-sent message with quarterly document review request
Sublime Security
3d ago
Jan 21st, 2026
/feeds/core/detection-rules/link-self-sent-message-with-quarterly-document-review-request-3c42cec6
Link: SharePoint filename matches org name
Sublime Security
3mo ago
Sep 26th, 2025
/feeds/core/detection-rules/link-sharepoint-filename-matches-org-name-cb954726
Link: Squarespace infrastructure abuse
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-squarespace-infrastructure-abuse-a8fe9d30
Link: Suspicious URL with recipient targeting and special characters
Sublime Security
2d ago
Jan 22nd, 2026
/feeds/core/detection-rules/link-suspicious-url-with-recipient-targeting-and-special-characters-e808be3a
Link to auto-downloaded disk image in encrypted zip
@ajpc500
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-to-auto-downloaded-disk-image-in-encrypted-zip-b50f0cb1
Link to auto-downloaded DMG in encrypted zip
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/link-to-auto-downloaded-dmg-in-encrypted-zip-43af98d3
Link to auto-downloaded file with Adobe branding
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/link-to-auto-downloaded-file-with-adobe-branding-e826c2cf
Link to auto-downloaded file with Google Drive branding
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-to-auto-downloaded-file-with-google-drive-branding-4b5343be
Link to auto-download of a suspicious file type (unsolicited)
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-to-auto-download-of-a-suspicious-file-type-unsolicited-67ae2152
Link to Google Apps Script macro (unsolicited)
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-to-google-apps-script-macro-unsolicited-d10146df
Link to Google Apps Script macro via comment tagging
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-to-google-apps-script-macro-via-comment-tagging-66fecd30