• Sublime Core Feed

Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Jan 23rd, 2026
Feed Source
Tactic or Technique is
Rule Name & Severity
Author
Last Updated
Labels
Link: Uncommon SharePoint document type with sender's display name
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-uncommon-sharepoint-document-type-with-senders-display-name-02d290b2
Link: URL scheme obfuscation via split HTML anchors
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-url-scheme-obfuscation-via-split-html-anchors-10375948
Lookalike sender domain (untrusted sender)
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/lookalike-sender-domain-untrusted-sender-67721993
Low reputation link to auto-downloaded HTML file with smuggling indicators
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/low-reputation-link-to-auto-downloaded-html-file-with-smuggling-indicators-339676c6
Mass campaign: Cross Site Scripting (XSS) attempt
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/mass-campaign-cross-site-scripting-xss-attempt-6cbb7124
Mass campaign: recipient address in subject, body, and link (untrusted sender)
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/mass-campaign-recipient-address-in-subject-body-and-link-untrusted-sender-599dabf5
Microsoft device code phishing
@ajpc500
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/microsoft-device-code-phishing-61f3ae67
Microsoft infrastructure abuse with suspicious patterns
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/microsoft-infrastructure-abuse-with-suspicious-patterns-cfe8e804
Mismatched links: Free file share with urgent language
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/mismatched-links-free-file-share-with-urgent-language-478334c8
Newly registered sender or reply-to domain with newly registered linked domain
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/newly-registered-sender-or-reply-to-domain-with-newly-registered-linked-domain-e5b6a81f
Non-RFC compliant calendar files from unsolicited sender
Sublime Security
3mo ago
Oct 1st, 2025
/feeds/core/detection-rules/non-rfc-compliant-calendar-files-from-unsolicited-sender-9859f100
Open redirect: City of Calgary
Sublime Security
8mo ago
May 23rd, 2025
/feeds/core/detection-rules/open-redirect-city-of-calgary-00321858
Open redirect: giving.lluh.org
Sublime Security
8mo ago
May 23rd, 2025
/feeds/core/detection-rules/open-redirect-givinglluhorg-a2bf1099
Open redirect: Klaviyo
Sublime Security
2y ago
May 14th, 2024
/feeds/core/detection-rules/open-redirect-klaviyo-ce5a370a
Open redirect: marketing.edinburghairport.com
Sublime Security
8mo ago
May 23rd, 2025
/feeds/core/detection-rules/open-redirect-marketingedinburghairportcom-33a47565
Open redirect: next2.io
Sublime Security
8mo ago
May 23rd, 2025
/feeds/core/detection-rules/open-redirect-next2io-5085c422
Open redirect: people.anuneo.com
Sublime Security
8mo ago
May 23rd, 2025
/feeds/core/detection-rules/open-redirect-peopleanuneocom-2ae83b73
Open redirect: queue.swytchbike.com
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/open-redirect-queueswytchbikecom-916003d1
Open redirect: slubnaglowie.pl
Sublime Security
8mo ago
May 23rd, 2025
/feeds/core/detection-rules/open-redirect-slubnaglowiepl-2ec356d0
Open redirect: typedrawers.com
Sublime Security
8mo ago
May 23rd, 2025
/feeds/core/detection-rules/open-redirect-typedrawerscom-158d9e95
PayPal invoice abuse
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/paypal-invoice-abuse-0ff7a0d4
Potential prompt injection attack in body HTML
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/potential-prompt-injection-attack-in-body-html-5fb24736
Punycode sender domain
Sublime Security
3y ago
Aug 21st, 2023
/feeds/core/detection-rules/punycode-sender-domain-bc3d8db5
QR code to auto-download of a suspicious file type (unsolicited)
Sublime Security
3mo ago
Oct 17th, 2025
/feeds/core/detection-rules/qr-code-to-auto-download-of-a-suspicious-file-type-unsolicited-eed87ea2
QR Code with suspicious indicators
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/qr-code-with-suspicious-indicators-04f5c34f
Reconnaissance: Email address harvesting attempt
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/reconnaissance-email-address-harvesting-attempt-bb31efbc
Reconnaissance: Short generic greeting message
Sublime Security
1mo ago
Dec 2nd, 2025
/feeds/core/detection-rules/reconnaissance-short-generic-greeting-message-c67dedab
Recruitee Infrastructure Abuse
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/recruitee-infrastructure-abuse-31cab83d
Salesforce infrastructure abuse
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/salesforce-infrastructure-abuse-78a77c70
Self-sent fake PDF attachment with misleading link
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/self-sent-fake-pdf-attachment-with-misleading-link-8a285d2e
Sendgrid voicemail phish
Sublime Security
2mo ago
Nov 24th, 2025
/feeds/core/detection-rules/sendgrid-voicemail-phish-21cad89c
Service abuse: Adobe Creative Cloud share from an unsolicited sender address
Sublime Security
3mo ago
Oct 22nd, 2025
/feeds/core/detection-rules/service-abuse-adobe-creative-cloud-share-from-an-unsolicited-sender-address-47e42ca1
Service abuse: Adobe legitimate domain with document approval language
Sublime Security
1d ago
Jan 23rd, 2026
/feeds/core/detection-rules/service-abuse-adobe-legitimate-domain-with-document-approval-language-237f4da4
Service abuse: Adobe Sign notification from an unsolicited reply-to address
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/service-abuse-adobe-sign-notification-from-an-unsolicited-reply-to-address-d00893ba
Service abuse: AppSheet infrastructure with suspicious indicators
Sublime Security
3mo ago
Oct 6th, 2025
/feeds/core/detection-rules/service-abuse-appsheet-infrastructure-with-suspicious-indicators-5937646a
Service Abuse: Box file sharing with credential phishing intent
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/service-abuse-box-file-sharing-with-credential-phishing-intent-5bd0cb25
Service abuse: Callback phishing via Microsoft Teams invite
Sublime Security
1mo ago
Dec 12th, 2025
/feeds/core/detection-rules/service-abuse-callback-phishing-via-microsoft-teams-invite-13e35e5f
Service abuse: Cisco secure email service with financial request
Sublime Security
3mo ago
Oct 1st, 2025
/feeds/core/detection-rules/service-abuse-cisco-secure-email-service-with-financial-request-43a6daa8
Service abuse: DocSend share from an unsolicited reply-to address
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/service-abuse-docsend-share-from-an-unsolicited-reply-to-address-b377e64c
Service abuse: DocSend share from newly registered domain
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/service-abuse-docsend-share-from-newly-registered-domain-3bc152f2
Service abuse: DocuSign notification with suspicious sender or document name
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/service-abuse-docusign-notification-with-suspicious-sender-or-document-name-5e4707cd
Service abuse: DocuSign share from an unsolicited reply-to address
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/service-abuse-docusign-share-from-an-unsolicited-reply-to-address-2f12d616
Service abuse: Dropbox share from an unsolicited reply-to address
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/service-abuse-dropbox-share-from-an-unsolicited-reply-to-address-50a1499f
Service abuse: Dropbox share from new domain
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/service-abuse-dropbox-share-from-new-domain-0e664bd9
Service abuse: Dropbox share with suspicious sender or document name
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/service-abuse-dropbox-share-with-suspicious-sender-or-document-name-27007c9f
Service Abuse: ExactTarget with suspicious sender indicators
Sublime Security
2mo ago
Nov 8th, 2025
/feeds/core/detection-rules/service-abuse-exacttarget-with-suspicious-sender-indicators-6154f197
Service abuse: Facebook business with action required subject
Sublime Security
2mo ago
Nov 17th, 2025
/feeds/core/detection-rules/service-abuse-facebook-business-with-action-required-subject-64297d2f
Service abuse: FlipHTML5 with attachment deception and credential theft language
Sublime Security
12d ago
Jan 12th, 2026
/feeds/core/detection-rules/service-abuse-fliphtml5-with-attachment-deception-and-credential-theft-language-02464799
Service abuse: Formester with suspicious link behavior
Sublime Security
1mo ago
Dec 19th, 2025
/feeds/core/detection-rules/service-abuse-formester-with-suspicious-link-behavior-e4b74fd4
Service abuse: GetAccept callback scam content
Sublime Security
8d ago
Jan 16th, 2026
/feeds/core/detection-rules/service-abuse-getaccept-callback-scam-content-7ec2f70b