Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Jul 25th, 2026
Feed Source
Tactic or Technique is
Rule Name & Severity
Author
Last Updated
Labels
Attachment: Calendar invite with suspicious link leading to an open redirect
Sublime Security
2mo ago
Apr 28th, 2026
Attachment: EML file with IPFS links
Sublime Security
8mo ago
Nov 4th, 2025
Attachment: EML with link to credential phishing page
Sublime Security
1y ago
Jul 16th, 2025
Attachment: Fake scan-to-email
Sublime Security
10mo ago
Sep 22nd, 2025
Attachment: ICS file with AWS Lambda URL
Sublime Security
10d ago
Jul 16th, 2026
Attachment: PDF bid/proposal lure with credential theft indicators
Sublime Security
4mo ago
Mar 27th, 2026
Attachment: PDF with multistage landing - ClickUp abuse
Sublime Security
4mo ago
Feb 27th, 2026
Attachment: PDF with self-service platform links with self sender or blank recipients
Sublime Security
1mo ago
Jun 10th, 2026
Attachment: Romance scam with image lure and advance-fee or suspicious link indicators
Sublime Security
25d ago
Jul 1st, 2026
Attachment: Single-page PDF with S3-hosted HTML link
Sublime Security
10d ago
Jul 16th, 2026
Brand impersonation: Fake Fax
Sublime Security
1mo ago
Jun 17th, 2026
Brand impersonation: Microsoft quarantine release notification in image attachment
Sublime Security
1y ago
Jul 16th, 2025
Brand impersonation: Microsoft with low reputation links
Sublime Security
1mo ago
Jun 5th, 2026
Canva design with suspicious embedded link
Sublime Security
9mo ago
Sep 29th, 2025
Catbox.moe link from untrusted source
Sublime Security
11mo ago
Aug 5th, 2025
Cloud storage impersonation with credential theft indicators
Sublime Security
26d ago
Jun 30th, 2026
Credential phishing: Engaging language with IPFS link
Sublime Security
2y ago
May 3rd, 2024
Credential phishing: Hyper-linked image leading to free file host
Sublime Security
11mo ago
Aug 5th, 2025
Deceptive Dropbox mention
Sublime Security
6mo ago
Jan 12th, 2026
DocuSign impersonation via CloudHQ links
Sublime Security
11mo ago
Aug 5th, 2025
Fake scan-to-email message
Sublime Security
6mo ago
Jan 12th, 2026
Fake shipping notification with link to free file hosting
Sublime Security
2y ago
Jul 10th, 2024
File sharing link from suspicious sender domain
Sublime Security
5mo ago
Feb 13th, 2026
File sharing link with a suspicious subject
Sublime Security
5mo ago
Feb 17th, 2026
Google Drive abuse: Credential phishing link
Sublime Security
2y ago
Jul 31st, 2024
Google Drive direct download link from unsolicited sender
Sublime Security
1y ago
Jul 16th, 2025
Google share notification with suspicious comments
Sublime Security
6mo ago
Jan 12th, 2026
Impersonation: Fake product discount promotion
Sublime Security
1mo ago
Jun 16th, 2026
Invoicera infrastructure abuse
Sublime Security
2y ago
Mar 7th, 2024
Issuu document with suspicious embedded link
Sublime Security
6mo ago
Jan 12th, 2026
Link: Abused Adobe Express
Sublime Security
1y ago
Jul 23rd, 2025
Link: Adobe share from unsolicited sender
Sublime Security
6mo ago
Jan 12th, 2026
Link: Adobe share with suspicious indicators
Sublime Security
6mo ago
Jan 12th, 2026
Link: Commonly Abused Web Service redirecting to ZIP file
Sublime Security
4mo ago
Mar 10th, 2026
Link: Direct link to gamma.app document with mode parameter
Sublime Security
11mo ago
Aug 5th, 2025
Link: Direct link to keap.app contact-us page
Sublime Security
11mo ago
Aug 5th, 2025
Link: Direct link to limewire hosted file
Sublime Security
11mo ago
Aug 18th, 2025
Link: Direct link to riddle.com hosted showcase
Sublime Security
6mo ago
Jan 12th, 2026
Link: Document sharing invitation template
Sublime Security
1mo ago
Jun 12th, 2026
Link: Figma design deck with credential theft language
Sublime Security
4mo ago
Mar 4th, 2026
Link: Financial account issue with suspicious indicators
Sublime Security
4mo ago
Mar 24th, 2026
Link: Free file hosting with undisclosed recipients
Sublime Security
4mo ago
Mar 19th, 2026
Link: Free file host links from suspicious support sender with credential theft language
Sublime Security
1mo ago
Jun 25th, 2026
Link: Free file host link with 'Important Viewing Note' lure
Sublime Security
11d ago
Jul 15th, 2026
Link: Google Calendar invite linking to an open redirect from an untrusted freemail sender
Sublime Security
2mo ago
Apr 28th, 2026
Link: Google Cloud Storage hosted credential harvesting page
Sublime Security
26d ago
Jun 30th, 2026
Link: Google Cloud Storage impersonating with googledrive in URL path
Sublime Security
2mo ago
May 26th, 2026
Link: Google Cloud Storage link with index.php in URL
Sublime Security
26d ago
Jun 30th, 2026
Link: Google Cloud Storage link with redirect.html in URL
Sublime Security
26d ago
Jun 30th, 2026
Link: Google Cloud Storage redirect to external domain
Sublime Security
26d ago
Jun 30th, 2026