Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Jul 20th, 2026
Feed Source
Attack Type is
Rule Name & Severity
Author
Last Updated
Labels
Advance Fee Fraud (AFF) from freemail provider or suspicious TLD
Sublime Security
1mo ago
Jun 15th, 2026
AnonymousFox indicators
Sublime Security
13d ago
Jul 8th, 2026
Attachment: Calendar file with invisible Unicode characters
Sublime Security
2mo ago
Apr 28th, 2026
Attachment: Calendar invite with Google redirect and invoice request
Sublime Security
2mo ago
Apr 28th, 2026
Attachment: Canva PDF with susupicious author metadata
Sublime Security
1mo ago
Jun 5th, 2026
Attachment: Credit card application with WhatsApp contact
Sublime Security
8mo ago
Nov 20th, 2025
Attachment: Duplicated header pages in fraudulent multi-page PDF Request for Quotation
Sublime Security
26d ago
Jun 25th, 2026
Attachment: EML with Sharepoint link likely unrelated to sender
Sublime Security
10mo ago
Sep 23rd, 2025
Attachment: Encrypted zip file with payment-related lure
Sublime Security
7mo ago
Nov 25th, 2025
Attachment: Fake lawyer & sports agent identities
Sublime Security
5mo ago
Jan 26th, 2026
Attachment: Fictitious invoice using LinkedIn's address
Sublime Security
10mo ago
Sep 3rd, 2025
Attachment: ICS calendar file with suspicious UID domain
Sublime Security
19d ago
Jul 2nd, 2026
Attachment: ICS file with meeting prefix
Sublime Security
2mo ago
Apr 28th, 2026
Attachment: ICS with employee policy review lure
Sublime Security
2mo ago
Apr 28th, 2026
Attachment: Invoice and W-9 PDFs with suspicious creators
Sublime Security
25d ago
Jun 26th, 2026
Attachment: Legal themed message or PDF with suspicious indicators
Sublime Security
3mo ago
Apr 3rd, 2026
Attachment: Link to Doubleclick.net open redirect
Sublime Security
2mo ago
Apr 29th, 2026
Attachment: PDF bid/proposal lure with credential theft indicators
Sublime Security
3mo ago
Mar 27th, 2026
Attachment: PDF contains W9 or invoice YARA signatures
Sublime Security
4mo ago
Mar 18th, 2026
Attachment: PDF file with link to fake Bitcoin exchange
Sublime Security
6mo ago
Jan 12th, 2026
Attachment: PDF file with recipient domain and ATT eCheckRun pattern
Sublime Security
1mo ago
Jun 16th, 2026
Attachment: PDF generated with wkhtmltopdf tool and default title
Sublime Security
7mo ago
Dec 19th, 2025
Attachment: PDF Object Hash associated with a fake invoice and a W-9
Sublime Security
19d ago
Jul 2nd, 2026
Attachment: PDF with fake invoice using suspicious font sizing
Sublime Security
1mo ago
Jun 9th, 2026
Attachment: PDF with self-service platform links with self sender or blank recipients
Sublime Security
1mo ago
Jun 10th, 2026
Attachment: PDF with specific W-9 lure
Sublime Security
20d ago
Jul 1st, 2026
Attachment: PDF with suspicious internal object reference identifier
Sublime Security
22d ago
Jun 29th, 2026
Attachment: PDF with W-9 form indicators
Sublime Security
25d ago
Jun 26th, 2026
Attachment: RFP/RFQ impersonating government entities
Sublime Security
2y ago
Jan 30th, 2024
Attachment: Romance scam with image lure and advance-fee or suspicious link indicators
Sublime Security
20d ago
Jul 1st, 2026
Attachment: USDA bid invitation impersonation
Sublime Security
11mo ago
Aug 5th, 2025
BEC: Employee impersonation with subject manipulation
Sublime Security
6mo ago
Jan 16th, 2026
BEC: Executive coaching vendor impersonation
Sublime Security
20d ago
Jul 1st, 2026
BEC: Financial fraud from newly registered sender domain
Sublime Security
26d ago
Jun 25th, 2026
BEC/Fraud: Fake investment outreach from suspicious TLD
Sublime Security
1mo ago
Jun 15th, 2026
BEC/Fraud: Generic scam attempt to undisclosed recipients
Sublime Security
2mo ago
Apr 30th, 2026
BEC/Fraud: Job scam fake thread or plaintext pivot to freemail
Sublime Security
1mo ago
Jun 5th, 2026
BEC/Fraud: Penpal scam
Sublime Security
1mo ago
Jun 5th, 2026
BEC/Fraud: Reply-chain manipulation with urgent keywords and self-reply
Sublime Security
4mo ago
Mar 11th, 2026
BEC/Fraud: Romance scam
Sublime Security
4mo ago
Mar 9th, 2026
BEC/Fraud: Scam lure with freemail pivot
Sublime Security
2mo ago
Apr 30th, 2026
BEC/Fraud: Student loan callback phishing
Sublime Security
2mo ago
May 4th, 2026
BEC/Fraud: Unsolicited business acquisition offer
Sublime Security
15d ago
Jul 6th, 2026
BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns
Sublime Security
3mo ago
Apr 17th, 2026
BEC with unusual reply-to or return-path mismatch
Sublime Security
1mo ago
Jun 5th, 2026
Body: Embedded email headers indicative of thread hijacking/abuse
Sublime Security
7mo ago
Dec 1st, 2025
Body: Invisible Unicode obfuscation student loan callback phishing
Sublime Security
26d ago
Jun 25th, 2026
Body: PayApp transaction reference pattern
Sublime Security
3mo ago
Apr 7th, 2026
Body: Yellow highlighted text markers
Sublime Security
1mo ago
Jun 16th, 2026
Brand impersonation: AARP
Sublime Security
12d ago
Jul 9th, 2026