Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Jun 19th, 2026
Feed Source
Tactic or Technique is
Rule Name & Severity
Author
Last Updated
Labels
Adobe branded PDF file linking to a password-protected file from untrusted sender
Sublime Security
1mo ago
Apr 29th, 2026
Attachment: Base64 encoded bash command in filename
@vector_sec
9mo ago
Sep 5th, 2025
Attachment: EML with Encrypted ZIP
Sublime Security
5mo ago
Jan 12th, 2026
Attachment: Encrypted Microsoft Office file (unsolicited)
Sublime Security
5mo ago
Jan 12th, 2026
Attachment: Encrypted PDF With Credential Harvesting Indicators
Sublime Security
16d ago
Jun 5th, 2026
Attachment: Encrypted PDF with credential theft body
Sublime Security
4d ago
Jun 17th, 2026
Attachment: Encrypted ZIP containing VHDX file
Sublime Security
2mo ago
Apr 3rd, 2026
Attachment: Encrypted zip file with payment-related lure
Sublime Security
6mo ago
Nov 25th, 2025
Attachment: HTML smuggling with excessive line break obfuscation
Sublime Security
5mo ago
Jan 12th, 2026
Attachment: HTML smuggling with RC4 decryption
Sublime Security
5mo ago
Jan 12th, 2026
Attachment: HTML smuggling with ROT13
@Kyle_Parrish_
5mo ago
Jan 12th, 2026
Attachment: Password-protected PDF with fake document indicators
Sublime Security
5mo ago
Jan 21st, 2026
Attachment: PDF with password in filename matching body text
Sublime Security
4mo ago
Feb 19th, 2026
Attachment: PDF with recipient email in link
Sublime Security
11d ago
Jun 10th, 2026
Attachment with encrypted zip (unsolicited)
Sublime Security
11mo ago
Jul 16th, 2025
Attachment with unscannable encrypted zip
Sublime Security
1mo ago
Apr 30th, 2026
Encrypted Microsoft Office files from untrusted sender
Sublime Security
10mo ago
Aug 5th, 2025
Link: Base64 encoded recipient address in URL fragment with subject hash
Sublime Security
5mo ago
Jan 12th, 2026
Link: Excessive URL rewrite encoders
Sublime Security
5mo ago
Jan 21st, 2026
Link: Suspicious Family fragment parameter with encoded recipient data
Sublime Security
1mo ago
Apr 27th, 2026
Link to auto-downloaded disk image in encrypted zip
@ajpc500
5mo ago
Jan 12th, 2026
Link to auto-downloaded DMG in encrypted zip
Sublime Security
11mo ago
Jul 16th, 2025
Link to auto-download of a suspicious file type (unsolicited)
Sublime Security
5mo ago
Jan 12th, 2026