• Sublime Core Feed

Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Jan 23rd, 2026
Feed Source
Tactic or Technique is
Rule Name & Severity
Author
Last Updated
Labels
Attachment: Calendar invite with suspicious link leading to an open redirect
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/attachment-calendar-invite-with-suspicious-link-leading-to-an-open-redirect-5d6294c7
Attachment: EML file with IPFS links
Sublime Security
2mo ago
Nov 4th, 2025
/feeds/core/detection-rules/attachment-eml-file-with-ipfs-links-1fe9d7e7
Attachment: EML with link to credential phishing page
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/attachment-eml-with-link-to-credential-phishing-page-1df41cca
Attachment: Fake scan-to-email
Sublime Security
4mo ago
Sep 22nd, 2025
/feeds/core/detection-rules/attachment-fake-scan-to-email-ea850cc1
Brand impersonation: Fake Fax
Sublime Security
2d ago
Jan 21st, 2026
/feeds/core/detection-rules/brand-impersonation-fake-fax-2a96b90a
Brand impersonation: Microsoft quarantine release notification in image attachment
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/brand-impersonation-microsoft-quarantine-release-notification-in-image-attachment-185db6b3
Brand impersonation: Microsoft with low reputation links
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/brand-impersonation-microsoft-with-low-reputation-links-b59201b6
Canva design with suspicious embedded link
Sublime Security
3mo ago
Sep 29th, 2025
/feeds/core/detection-rules/canva-design-with-suspicious-embedded-link-02959e22
Catbox.moe link from untrusted source
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/catboxmoe-link-from-untrusted-source-d6041a8b
Cloud storage impersonation with credential theft indicators
Sublime Security
4mo ago
Sep 22nd, 2025
/feeds/core/detection-rules/cloud-storage-impersonation-with-credential-theft-indicators-4c20f72c
Credential phishing: Engaging language with IPFS link
Sublime Security
2y ago
May 3rd, 2024
/feeds/core/detection-rules/credential-phishing-engaging-language-with-ipfs-link-996c4d83
Credential phishing: Hyper-linked image leading to free file host
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/credential-phishing-hyper-linked-image-leading-to-free-file-host-f5cb1eca
Deceptive Dropbox mention
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/deceptive-dropbox-mention-58a107bc
DocuSign impersonation via CloudHQ links
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/docusign-impersonation-via-cloudhq-links-44ba2fee
Fake scan-to-email message
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/fake-scan-to-email-message-78851fbe
Fake shipping notification with link to free file hosting
Sublime Security
2y ago
Jul 10th, 2024
/feeds/core/detection-rules/fake-shipping-notification-with-link-to-free-file-hosting-6d3fe05e
File sharing link from suspicious sender domain
Sublime Security
4mo ago
Aug 27th, 2025
/feeds/core/detection-rules/file-sharing-link-from-suspicious-sender-domain-95f20354
File sharing link with a suspicious subject
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/file-sharing-link-with-a-suspicious-subject-a306e2a6
Google Drive abuse: Credential phishing link
Sublime Security
2y ago
Jul 31st, 2024
/feeds/core/detection-rules/google-drive-abuse-credential-phishing-link-c74aece0
Google Drive direct download link from unsolicited sender
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/google-drive-direct-download-link-from-unsolicited-sender-78a19343
Google share notification with suspicious comments
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/google-share-notification-with-suspicious-comments-c69c9924
Invoicera infrastructure abuse
Sublime Security
2y ago
Mar 7th, 2024
/feeds/core/detection-rules/invoicera-infrastructure-abuse-1e56f310
Issuu document with suspicious embedded link
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/issuu-document-with-suspicious-embedded-link-0d73f43d
Link: Abused Adobe Express
Sublime Security
6mo ago
Jul 23rd, 2025
/feeds/core/detection-rules/link-abused-adobe-express-c7d17bfd
Link: Adobe share from unsolicited sender
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-adobe-share-from-unsolicited-sender-8e29ab33
Link: Adobe share with suspicious indicators
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-adobe-share-with-suspicious-indicators-b33cae80
Link: Direct link to gamma.app document with mode parameter
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-direct-link-to-gammaapp-document-with-mode-parameter-080ab581
Link: Direct link to keap.app contact-us page
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-direct-link-to-keapapp-contact-us-page-a7a69267
Link: Direct link to limewire hosted file
Sublime Security
5mo ago
Aug 18th, 2025
/feeds/core/detection-rules/link-direct-link-to-limewire-hosted-file-70840d00
Link: Direct link to riddle.com hosted showcase
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-direct-link-to-riddlecom-hosted-showcase-cca7d2f5
Link: Figma design deck with credential theft language
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-figma-design-deck-with-credential-theft-language-87601924
Link: Free file hosting with undisclosed recipients
Sublime Security
4mo ago
Sep 11th, 2025
/feeds/core/detection-rules/link-free-file-hosting-with-undisclosed-recipients-b6281306
Link: Google Calendar invite linking to an open redirect from an untrusted freemail sender
Sublime Security
6mo ago
Jul 16th, 2025
/feeds/core/detection-rules/link-google-calendar-invite-linking-to-an-open-redirect-from-an-untrusted-freemail-sender-bb4f1ea9
Link: IPFS
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-ipfs-19fa6442
Link: Jensi file preview link from unsolicited sender
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-jensi-file-preview-link-from-unsolicited-sender-122b39f3
Link: Multistage landing - Abused Adobe frame.io
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-multistage-landing-abused-adobe-frameio-a6c457c5
Link: Multistage Landing - Abused Buildin.ai
Sublime Security
4mo ago
Sep 5th, 2025
/feeds/core/detection-rules/link-multistage-landing-abused-buildinai-e0a79ef5
Link: Multistage landing - Abused Docusign
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-multistage-landing-abused-docusign-4189a645
Link: Multistage landing - Abused Google Drive
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-multistage-landing-abused-google-drive-c86288b4
Link: Multistage landing - Published Google Doc
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-multistage-landing-published-google-doc-031e1ff8
Link: Multistage landing - Scribd document
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-multistage-landing-scribd-document-afa9807d
Link: Multistage landing - Trello board abuse
Sublime Security
5mo ago
Aug 20th, 2025
/feeds/core/detection-rules/link-multistage-landing-trello-board-abuse-14a5b23a
Link: PDF and financial display text to free file host
Sublime Security
4mo ago
Sep 24th, 2025
/feeds/core/detection-rules/link-pdf-and-financial-display-text-to-free-file-host-b010740b
Link: Scribd fullscreen link from suspicious sender
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-scribd-fullscreen-link-from-suspicious-sender-9e9bc972
Link: Secure SharePoint file share from new or unusual sender
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-secure-sharepoint-file-share-from-new-or-unusual-sender-74ed3020
Link: Suspicious SharePoint document name
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/link-suspicious-sharepoint-document-name-f95fee6e
Link: Suspicious Sharepoint folder share
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-suspicious-sharepoint-folder-share-6168a08c
Link: Webflow link from unsolicited sender
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-webflow-link-from-unsolicited-sender-d4f3b8cf
Link: Zoho form link from unsolicited sender
Sublime Security
5mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-zoho-form-link-from-unsolicited-sender-eb04a9f2
Low reputation link to auto-downloaded HTML file with smuggling indicators
Sublime Security
11d ago
Jan 12th, 2026
/feeds/core/detection-rules/low-reputation-link-to-auto-downloaded-html-file-with-smuggling-indicators-339676c6