• Sublime Core Feed

Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Dec 26th, 2025
Feed Source
Tactic or Technique is
Rule Name & Severity
Author
Last Updated
Labels
Attachment: Archive containing HTML file with file scheme link
Sublime Security
5mo ago
Jul 16th, 2025
/feeds/core/detection-rules/attachment-archive-containing-html-file-with-file-scheme-link-edf6d0d9
Attachment: Archive contains DLL-loading macro
Sublime Security
3y ago
Dec 28th, 2023
/feeds/core/detection-rules/attachment-archive-contains-dll-loading-macro-3a193f5f
Attachment: CVE-2021-40444 - MSHTML Remote Code Execution Vulnerability
Sublime Security
3y ago
Dec 19th, 2023
/feeds/core/detection-rules/attachment-cve-2021-40444-mshtml-remote-code-execution-vulnerability-8cefcf7f
Attachment: CVE-2023-21716 - Microsoft Office Remote Code Execution Vulnerability
Sublime Security
3y ago
Dec 19th, 2023
/feeds/core/detection-rules/attachment-cve-2023-21716-microsoft-office-remote-code-execution-vulnerability-23714cca
Attachment: CVE-2025-24071 - Microsoft Windows File Explorer Spoofing Vulnerability
Sublime Security
9mo ago
Mar 21st, 2025
/feeds/core/detection-rules/attachment-cve-2025-24071-microsoft-windows-file-explorer-spoofing-vulnerability-2e69fa0b
Attachment: LNK with embedded content
@ajpc500
3y ago
Aug 21st, 2023
/feeds/core/detection-rules/attachment-lnk-with-embedded-content-41452f7a
Attachment: WinRAR CVE-2025-8088 exploitation
Sublime Security
4mo ago
Aug 12th, 2025
/feeds/core/detection-rules/attachment-winrar-cve-2025-8088-exploitation-33b3a82b
Callback Phishing via Signable E-Signature Request
Sublime Security
2mo ago
Oct 17th, 2025
/feeds/core/detection-rules/callback-phishing-via-signable-e-signature-request-4599575d
Callback phishing via SignFree e-signature request
Sublime Security
2mo ago
Oct 17th, 2025
/feeds/core/detection-rules/callback-phishing-via-signfree-e-signature-request-21381c37
Callback phishing via Xodo Sign comment
Sublime Security
2mo ago
Oct 17th, 2025
/feeds/core/detection-rules/callback-phishing-via-xodo-sign-comment-6f722c5d
CVE-2023-5631 - Roundcube Webmail XSS via crafted SVG
Sublime Security
2y ago
Feb 23rd, 2024
/feeds/core/detection-rules/cve-2023-5631-roundcube-webmail-xss-via-crafted-svg-8405d61b
Link: CVE-2024-21413 Microsoft Outlook Remote Code Execution Vulnerability
Sublime Security
2y ago
Feb 15th, 2024
/feeds/core/detection-rules/link-cve-2024-21413-microsoft-outlook-remote-code-execution-vulnerability-e8151426
Mass campaign: Cross Site Scripting (XSS) attempt
Sublime Security
5mo ago
Jul 16th, 2025
/feeds/core/detection-rules/mass-campaign-cross-site-scripting-xss-attempt-6cbb7124
Open redirect: City of Calgary
Sublime Security
7mo ago
May 23rd, 2025
/feeds/core/detection-rules/open-redirect-city-of-calgary-00321858
Outlook hyperlink bypass: left-to-right mark (LRM) in base HTML tag
Sublime Security
23d ago
Dec 10th, 2025
/feeds/core/detection-rules/outlook-hyperlink-bypass-left-to-right-mark-lrm-in-base-html-tag-160cc681