Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Jun 29th, 2026
Feed Source
Tactic or Technique is
Rule Name & Severity
Author
Last Updated
Labels
Attachment: Calendar invite with suspicious link leading to an open redirect
Sublime Security
2mo ago
Apr 28th, 2026
Attachment: EML file with IPFS links
Sublime Security
7mo ago
Nov 4th, 2025
Attachment: EML with link to credential phishing page
Sublime Security
11mo ago
Jul 16th, 2025
Attachment: HTML smuggling Microsoft sign in
Sublime Security
2mo ago
Apr 27th, 2026
Attachment: HTML smuggling with raw array buffer
Sublime Security
3y ago
Aug 21st, 2023
Attachment: PDF Attachment with links to workers.dev
Sublime Security
26d ago
Jun 4th, 2026
Attachment: PDF bid/proposal lure with credential theft indicators
Sublime Security
3mo ago
Mar 27th, 2026
Attachment: PDF with credential theft language and link to a free subdomain (unsolicited)
Sublime Security
5mo ago
Jan 12th, 2026
Attachment: PDF with multistage landing - ClickUp abuse
Sublime Security
4mo ago
Feb 27th, 2026
Brand impersonation: Coinbase with suspicious links
Sublime Security
9mo ago
Sep 22nd, 2025
Brand impersonation: Fake Fax
Sublime Security
13d ago
Jun 17th, 2026
ClickFunnels link infrastructure abuse
Sublime Security
25d ago
Jun 5th, 2026
Credential phishing: AWS Lambda URL with recipient targeting
Sublime Security
1mo ago
May 28th, 2026
Credential phishing: Engaging language with IPFS link
Sublime Security
2y ago
May 3rd, 2024
Credential phishing: Onedrive impersonation
Sublime Security
1mo ago
May 26th, 2026
Deceptive Dropbox mention
Sublime Security
5mo ago
Jan 12th, 2026
Free subdomain link with credential theft indicators
Sublime Security
2y ago
Dec 12th, 2024
Free subdomain link with login or captcha (untrusted sender)
Sublime Security
5mo ago
Jan 12th, 2026
Invoicera infrastructure abuse
Sublime Security
2y ago
Mar 7th, 2024
Link: Abused Adobe Express
Sublime Security
11mo ago
Jul 23rd, 2025
Link: Blogspot hosting explicit romance content
Sublime Security
3mo ago
Mar 9th, 2026
Link: Breely link masquerading as PDF
Sublime Security
5mo ago
Jan 16th, 2026
Link: Commonly Abused Web Service redirecting to ZIP file
Sublime Security
3mo ago
Mar 10th, 2026
Link: Credential phishing via WordPress
Sublime Security
10mo ago
Aug 5th, 2025
Link: Cryptocurrency fraud with suspicious links
Sublime Security
7mo ago
Dec 1st, 2025
Link: File sharing impersonation with suspicious language and sending patterns
Sublime Security
2mo ago
Apr 30th, 2026
Link: Financial account issue with suspicious indicators
Sublime Security
3mo ago
Mar 24th, 2026
Link: Flare-branded credential harvesting via Cloudflare tunnels
Sublime Security
18d ago
Jun 12th, 2026
Link: Free file hosting with undisclosed recipients
Sublime Security
3mo ago
Mar 19th, 2026
Link: Free subdomain host with undisclosed recipients
Sublime Security
5mo ago
Jan 12th, 2026
Link: IPFS
Sublime Security
5mo ago
Jan 12th, 2026
Link: Jensi file preview link from unsolicited sender
Sublime Security
5mo ago
Jan 12th, 2026
Link: Multistage landing - Abused Docusign
Sublime Security
10mo ago
Aug 5th, 2025
Link: Multistage landing - ClickUp abuse
Sublime Security
4mo ago
Feb 27th, 2026
Link: Tax document lure Portuguese/Spanish with suspicious domains
Sublime Security
2mo ago
Apr 14th, 2026
Link: Tycoon2FA phishing kit (non-exhaustive)
Sublime Security
5mo ago
Jan 23rd, 2026
Link: Webflow link from unsolicited sender
Sublime Security
10mo ago
Aug 5th, 2025
Link: WordPress login page with Blogspot Binance scam
Sublime Security
4mo ago
Feb 17th, 2026
Low reputation link to auto-downloaded HTML file with smuggling indicators
Sublime Security
5mo ago
Jan 12th, 2026
Message traversed multiple onmicrosoft.com tenants
Sublime Security
5mo ago
Jan 12th, 2026
Self-sender with copy/paste instructions and suspicious domains (French/Français)
Sublime Security
2mo ago
Apr 16th, 2026
Self-sent fake PDF attachment with misleading link
Sublime Security
5mo ago
Jan 12th, 2026
Service abuse: GitHub notification with excessive mentions and suspicious links
Sublime Security
2mo ago
Apr 7th, 2026
Service abuse: Google application integration redirecting to suspicious hosts
Sublime Security
6mo ago
Dec 17th, 2025
Service abuse: Google Firebase sender address with suspicious content
Sublime Security
12d ago
Jun 18th, 2026
Service abuse: Google OAuth with suspicious redirect destination
Sublime Security
1mo ago
May 27th, 2026
Service abuse: Outlook Groups with Google Sites link and evasion tag
Sublime Security
13d ago
Jun 17th, 2026
Service abuse: Suspicious Datadog alert
Sublime Security
19d ago
Jun 11th, 2026
Shopify infrastructure abuse
Sublime Security
2y ago
Nov 13th, 2024
Spam: Link to blob.core.windows.net from new domain (<30d)
Sublime Security
11mo ago
Jul 16th, 2025