• Sublime Core Feed

Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Mar 27th, 2026
Feed Source
Tactic or Technique is
Rule Name & Severity
Author
Last Updated
Labels
Attachment: Calendar invite with suspicious link leading to an open redirect
Sublime Security
8mo ago
Jul 16th, 2025
Attachment: EML file with IPFS links
Sublime Security
4mo ago
Nov 4th, 2025
Attachment: EML with link to credential phishing page
Sublime Security
8mo ago
Jul 16th, 2025
Attachment: HTML smuggling Microsoft sign in
Sublime Security
2mo ago
Jan 12th, 2026
Attachment: HTML smuggling with raw array buffer
Sublime Security
3y ago
Aug 21st, 2023
Attachment: PDF bid/proposal lure with credential theft indicators
Sublime Security
3d ago
Mar 27th, 2026
Attachment: PDF with credential theft language and link to a free subdomain (unsolicited)
Sublime Security
2mo ago
Jan 12th, 2026
Attachment: PDF with multistage landing - ClickUp abuse
Sublime Security
1mo ago
Feb 27th, 2026
Brand impersonation: Coinbase with suspicious links
Sublime Security
6mo ago
Sep 22nd, 2025
Brand impersonation: Fake Fax
Sublime Security
1mo ago
Feb 5th, 2026
ClickFunnels link infrastructure abuse
Sublime Security
1mo ago
Feb 5th, 2026
Credential phishing: Engaging language with IPFS link
Sublime Security
2y ago
May 3rd, 2024
Credential phishing: Onedrive impersonation
Sublime Security
2mo ago
Jan 12th, 2026
Deceptive Dropbox mention
Sublime Security
2mo ago
Jan 12th, 2026
Free subdomain link with credential theft indicators
Sublime Security
2y ago
Dec 12th, 2024
Free subdomain link with login or captcha (untrusted sender)
Sublime Security
2mo ago
Jan 12th, 2026
Invoicera infrastructure abuse
Sublime Security
2y ago
Mar 7th, 2024
Link: Abused Adobe Express
Sublime Security
8mo ago
Jul 23rd, 2025
Link: Blogspot hosting explicit romance content
Sublime Security
21d ago
Mar 9th, 2026
Link: Breely link masquerading as PDF
Sublime Security
2mo ago
Jan 16th, 2026
Link: Commonly Abused Web Service redirecting to ZIP file
Sublime Security
20d ago
Mar 10th, 2026
Link: Credential phishing via WordPress
Sublime Security
7mo ago
Aug 5th, 2025
Link: Cryptocurrency fraud with suspicious links
Sublime Security
3mo ago
Dec 1st, 2025
Link: File sharing impersonation with suspicious language and sending patterns
Sublime Security
4mo ago
Oct 31st, 2025
Link: Financial account issue with suspicious indicators
Sublime Security
6d ago
Mar 24th, 2026
Link: Free file hosting with undisclosed recipients
Sublime Security
11d ago
Mar 19th, 2026
Link: Free subdomain host with undisclosed recipients
Sublime Security
2mo ago
Jan 12th, 2026
Link: IPFS
Sublime Security
2mo ago
Jan 12th, 2026
Link: Jensi file preview link from unsolicited sender
Sublime Security
2mo ago
Jan 12th, 2026
Link: Multistage landing - Abused Docusign
Sublime Security
7mo ago
Aug 5th, 2025
Link: Multistage landing - ClickUp abuse
Sublime Security
1mo ago
Feb 27th, 2026
Link: Tycoon2FA phishing kit (non-exhaustive)
Sublime Security
2mo ago
Jan 23rd, 2026
Link: Webflow link from unsolicited sender
Sublime Security
7mo ago
Aug 5th, 2025
Link: WordPress login page with Blogspot Binance scam
Sublime Security
1mo ago
Feb 17th, 2026
Low reputation link to auto-downloaded HTML file with smuggling indicators
Sublime Security
2mo ago
Jan 12th, 2026
Message traversed multiple onmicrosoft.com tenants
Sublime Security
2mo ago
Jan 12th, 2026
Self-sent fake PDF attachment with misleading link
Sublime Security
2mo ago
Jan 12th, 2026
Service abuse: Google application integration redirecting to suspicious hosts
Sublime Security
3mo ago
Dec 17th, 2025
Service abuse: Google Firebase sender address with suspicious content
Sublime Security
18d ago
Mar 12th, 2026
Service abuse: Google OAuth with suspicious redirect destination
Sublime Security
18d ago
Mar 12th, 2026
Shopify infrastructure abuse
Sublime Security
2y ago
Nov 13th, 2024
Spam: Link to blob.core.windows.net from new domain (<30d)
Sublime Security
8mo ago
Jul 16th, 2025
Spoofable internal domain with suspicious signals
Sublime Security
8mo ago
Jul 23rd, 2025
Vendor compromise: GovDelivery message with suspicious link
Sublime Security
7mo ago
Aug 5th, 2025
Zoom Events newsletter abuse
Sublime Security
2mo ago
Jan 12th, 2026