Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Sep 30th, 2026
Feed Source
Tactic or Technique is
Rule Name & Severity
Author
Last Updated
Labels
Attachment: Calendar file with invisible Unicode characters
Sublime Security
5mo ago
Apr 28th, 2026
Attachment: Calendar invite from recently registered domain
Sublime Security
5mo ago
Apr 28th, 2026
Attachment: Calendar invite with Google redirect and invoice request
Sublime Security
5mo ago
Apr 28th, 2026
Attachment: Calendar invite with suspicious link leading to an open redirect
Sublime Security
2d ago
Sep 28th, 2026
Attachment: HTML smuggling with atob and high entropy via calendar invite
Sublime Security
7d ago
Sep 23rd, 2026
Attachment: HTML smuggling with eval and atob via calendar invite
Sublime Security
5mo ago
Apr 28th, 2026
Attachment: ICS calendar file with base64 encoded recipient address in URL parameters
Sublime Security
4mo ago
May 12th, 2026
Attachment: ICS calendar file with legal language
Sublime Security
2d ago
Sep 28th, 2026
Attachment: ICS calendar file with suspicious product identifier
Sublime Security
2mo ago
Jul 27th, 2026
Attachment: ICS calendar file with suspicious UID domain
Sublime Security
1d ago
Sep 29th, 2026
Attachment: ICS calendar invite hiding credential theft
Sublime Security
2d ago
Sep 28th, 2026
Attachment: ICS calendar invite with bid/RFP lure and suspicious link
Sublime Security
2d ago
Sep 28th, 2026
Attachment: ICS calendar invite with hex-encoded recipient in link
Sublime Security
2d ago
Sep 28th, 2026
Attachment: ICS calendar with embedded file from internal sender with SPF failure
Sublime Security
5mo ago
Apr 28th, 2026
Attachment: ICS calendar with suspicious link Leading to minimal JS landing page
Sublime Security
2d ago
Sep 28th, 2026
Attachment: ICS file with AWS Lambda URL
Sublime Security
2mo ago
Jul 16th, 2026
Attachment: ICS file with credential theft indicators
Sublime Security
2d ago
Sep 28th, 2026
Attachment: ICS file with excessive custom properties
Sublime Security
26d ago
Sep 4th, 2026
Attachment: ICS file with meeting prefix
Sublime Security
5mo ago
Apr 28th, 2026
Attachment: ICS file with non-Gregorian calendar scale
Sublime Security
5mo ago
Apr 28th, 2026
Attachment: ICS invite meeting lure
Sublime Security
2d ago
Sep 28th, 2026
Attachment: ICS link with valueless base64 query parameter
Sublime Security
2d ago
Sep 28th, 2026
Attachment: ICS voicemail lure with suspicious link
Sublime Security
2d ago
Sep 28th, 2026
Attachment: ICS with embedded document
Sublime Security
5mo ago
Apr 28th, 2026
Attachment: ICS with embedded Javascript in SVG file
Sublime Security
5mo ago
Apr 28th, 2026
Attachment: ICS with employee policy review lure
Sublime Security
5mo ago
Apr 28th, 2026
Attachment: ICS with Suspicious Office 365 app authorization (OAuth) link
Sublime Security
2d ago
Sep 28th, 2026
Attachment: Oversized guest-list calendar invite with purchase order lure
Sublime Security
2d ago
Sep 28th, 2026
Attachment: Oversized guest-list calendar invite with voicemail lure
Sublime Security
2d ago
Sep 28th, 2026
Callback phishing via calendar invite
Sublime Security
1mo ago
Aug 7th, 2026
Link: Google Calendar invite linking to an open redirect from an untrusted freemail sender
Sublime Security
2d ago
Sep 28th, 2026
Non-RFC compliant calendar files from unsolicited sender
Sublime Security
5mo ago
Apr 28th, 2026
Service abuse: Google Calendar notification with callback scam language
Sublime Security
5mo ago
Apr 28th, 2026