• Sublime Core Feed

Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Dec 19th, 2025
Feed Source
Tactic or Technique is
Rule Name & Severity
Author
Last Updated
Labels
Attachment: Calendar invite with suspicious link leading to an open redirect
Sublime Security
5mo ago
Jul 16th, 2025
/feeds/core/detection-rules/attachment-calendar-invite-with-suspicious-link-leading-to-an-open-redirect-5d6294c7
Attachment: EML file with IPFS links
Sublime Security
1mo ago
Nov 4th, 2025
/feeds/core/detection-rules/attachment-eml-file-with-ipfs-links-1fe9d7e7
Attachment: EML with link to credential phishing page
Sublime Security
5mo ago
Jul 16th, 2025
/feeds/core/detection-rules/attachment-eml-with-link-to-credential-phishing-page-1df41cca
Attachment: HTML smuggling Microsoft sign in
Sublime Security
4mo ago
Aug 5th, 2025
/feeds/core/detection-rules/attachment-html-smuggling-microsoft-sign-in-878d6385
Attachment: HTML smuggling with raw array buffer
Sublime Security
2y ago
Aug 21st, 2023
/feeds/core/detection-rules/attachment-html-smuggling-with-raw-array-buffer-a0d5c3dc
Attachment: PDF with credential theft language and link to a free subdomain (unsolicited)
Sublime Security
5mo ago
Jul 16th, 2025
/feeds/core/detection-rules/attachment-pdf-with-credential-theft-language-and-link-to-a-free-subdomain-unsolicited-90f4ef4e
Brand impersonation: Coinbase with suspicious links
Sublime Security
3mo ago
Sep 22nd, 2025
/feeds/core/detection-rules/brand-impersonation-coinbase-with-suspicious-links-b61e2f8e
Brand impersonation: Fake Fax
Sublime Security
1mo ago
Nov 13th, 2025
/feeds/core/detection-rules/brand-impersonation-fake-fax-2a96b90a
ClickFunnels link infrastructure abuse
Sublime Security
1mo ago
Nov 4th, 2025
/feeds/core/detection-rules/clickfunnels-link-infrastructure-abuse-9192fbe9
Credential phishing: Engaging language with IPFS link
Sublime Security
1y ago
May 3rd, 2024
/feeds/core/detection-rules/credential-phishing-engaging-language-with-ipfs-link-996c4d83
Credential phishing: Onedrive impersonation
Sublime Security
3mo ago
Sep 22nd, 2025
/feeds/core/detection-rules/credential-phishing-onedrive-impersonation-1f990c92
Deceptive Dropbox mention
Sublime Security
6d ago
Dec 15th, 2025
/feeds/core/detection-rules/deceptive-dropbox-mention-58a107bc
Free subdomain link with credential theft indicators
Sublime Security
1y ago
Dec 12th, 2024
/feeds/core/detection-rules/free-subdomain-link-with-credential-theft-indicators-9187479c
Free subdomain link with login or captcha (untrusted sender)
Sublime Security
5mo ago
Jul 16th, 2025
/feeds/core/detection-rules/free-subdomain-link-with-login-or-captcha-untrusted-sender-93288f82
Invoicera infrastructure abuse
Sublime Security
1y ago
Mar 7th, 2024
/feeds/core/detection-rules/invoicera-infrastructure-abuse-1e56f310
Link: Abused Adobe Express
Sublime Security
5mo ago
Jul 23rd, 2025
/feeds/core/detection-rules/link-abused-adobe-express-c7d17bfd
Link: Credential phishing via WordPress
Sublime Security
4mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-credential-phishing-via-wordpress-db696058
Link: Cryptocurrency fraud with suspicious links
Sublime Security
20d ago
Dec 1st, 2025
/feeds/core/detection-rules/link-cryptocurrency-fraud-with-suspicious-links-d0da37ce
Link: File sharing impersonation with suspicious language and sending patterns
Sublime Security
1mo ago
Oct 31st, 2025
/feeds/core/detection-rules/link-file-sharing-impersonation-with-suspicious-language-and-sending-patterns-d3363041
Link: Free file hosting with undisclosed recipients
Sublime Security
3mo ago
Sep 11th, 2025
/feeds/core/detection-rules/link-free-file-hosting-with-undisclosed-recipients-b6281306
Link: Free subdomain host with undisclosed recipients
Sublime Security
4mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-free-subdomain-host-with-undisclosed-recipients-c23d979d
Link: IPFS
Sublime Security
5mo ago
Jul 16th, 2025
/feeds/core/detection-rules/link-ipfs-19fa6442
Link: Jensi file preview link from unsolicited sender
Sublime Security
4mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-jensi-file-preview-link-from-unsolicited-sender-122b39f3
Link: Multistage landing - Abused Docusign
Sublime Security
4mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-multistage-landing-abused-docusign-4189a645
Link: Tycoon2FA phishing kit (non-exhaustive)
Sublime Security
19d ago
Dec 2nd, 2025
/feeds/core/detection-rules/link-tycoon2fa-phishing-kit-non-exhaustive-a070d4e2
Link: Webflow link from unsolicited sender
Sublime Security
4mo ago
Aug 5th, 2025
/feeds/core/detection-rules/link-webflow-link-from-unsolicited-sender-d4f3b8cf
Low reputation link to auto-downloaded HTML file with smuggling indicators
Sublime Security
5mo ago
Jul 23rd, 2025
/feeds/core/detection-rules/low-reputation-link-to-auto-downloaded-html-file-with-smuggling-indicators-339676c6
Message traversed multiple onmicrosoft.com tenants
Sublime Security
4mo ago
Aug 5th, 2025
/feeds/core/detection-rules/message-traversed-multiple-onmicrosoftcom-tenants-9cf01c0d
Self-sent fake PDF attachment with misleading link
Sublime Security
5d ago
Dec 16th, 2025
/feeds/core/detection-rules/self-sent-fake-pdf-attachment-with-misleading-link-8a285d2e
Service abuse: Google application integration redirecting to suspicious hosts
Sublime Security
4d ago
Dec 17th, 2025
/feeds/core/detection-rules/service-abuse-google-application-integration-redirecting-to-suspicious-hosts-473d3247
Service abuse: Random Google Firebase sender address with suspicious content
Sublime Security
25d ago
Nov 26th, 2025
/feeds/core/detection-rules/service-abuse-random-google-firebase-sender-address-with-suspicious-content-9f8899a9
Shopify infrastructure abuse
Sublime Security
1y ago
Nov 13th, 2024
/feeds/core/detection-rules/shopify-infrastructure-abuse-844ff164
Spam: Link to blob.core.windows.net from new domain (<30d)
Sublime Security
5mo ago
Jul 16th, 2025
/feeds/core/detection-rules/spam-link-to-blobcorewindowsnet-from-new-domain-less30d-a09b3800
Spoofable internal domain with suspicious signals
Sublime Security
5mo ago
Jul 23rd, 2025
/feeds/core/detection-rules/spoofable-internal-domain-with-suspicious-signals-40089d69
Vendor compromise: GovDelivery message with suspicious link
Sublime Security
4mo ago
Aug 5th, 2025
/feeds/core/detection-rules/vendor-compromise-govdelivery-message-with-suspicious-link-0d2d5172
Zoom Events newsletter abuse
Sublime Security
3mo ago
Sep 22nd, 2025
/feeds/core/detection-rules/zoom-events-newsletter-abuse-c8fce846