• Sublime Core Feed

Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Feb 14th, 2025
Feed Source
GitHub
Detection Method is
Rule Name & Severity
Author
Last Updated
Labels
Attachment: Adobe image lure in body or attachment with suspicious link
Sublime Security
10d ago
Feb 7th, 2025
Credential Phishing
Image as content
Impersonation: Brand
Content analysis
Computer Vision
Optical Character Recognition
Sender analysis
URL analysis
/feeds/core/detection-rules/attachment-adobe-image-lure-in-body-or-attachment-with-suspicious-link-1d7add81
Attachment: Callback Phishing solicitation via image file
@vector_sec
3mo ago
Nov 4th, 2024
/feeds/core/detection-rules/attachment-callback-phishing-solicitation-via-image-file-60acbb36
Attachment: DocuSign Impersonation (PDF) linking to New Domain <=3d
Sublime Security
9mo ago
Apr 25th, 2024
/feeds/core/detection-rules/attachment-docusign-impersonation-pdf-linking-to-new-domain-less3d-f0c96282
Attachment: EML with link to credential phishing page
Sublime Security
5mo ago
Sep 13th, 2024
/feeds/core/detection-rules/attachment-eml-with-link-to-credential-phishing-page-1df41cca
Attachment: Fake Slack installer
Sublime Security
2y ago
Nov 29th, 2023
/feeds/core/detection-rules/attachment-fake-slack-installer-cded2d2f
Attachment: Fake Zoom installer
Sublime Security
2y ago
Nov 29th, 2023
/feeds/core/detection-rules/attachment-fake-zoom-installer-840a12a6
Attachment: HTML smuggling - QR Code with suspicious links
Sublime Security
9mo ago
Apr 25th, 2024
/feeds/core/detection-rules/attachment-html-smuggling-qr-code-with-suspicious-links-010e757d
Attachment: Microsoft impersonation via PDF with link and suspicious language
Sublime Security
9mo ago
May 2nd, 2024
/feeds/core/detection-rules/attachment-microsoft-impersonation-via-pdf-with-link-and-suspicious-language-70d41c7f
Attachment: QR code with credential phishing indicators
Sublime Security
6mo ago
Jul 29th, 2024
/feeds/core/detection-rules/attachment-qr-code-with-credential-phishing-indicators-9f1681e1
Brand impersonation: Adobe (QR code)
Sublime Security
2mo ago
Dec 2nd, 2024
/feeds/core/detection-rules/brand-impersonation-adobe-qr-code-2fc36c6d
Brand impersonation: Adobe with suspicious language and link
Sublime Security
5mo ago
Sep 19th, 2024
/feeds/core/detection-rules/brand-impersonation-adobe-with-suspicious-language-and-link-32cc8bf1
Brand impersonation: Amazon with suspicious attachment
Sublime Security
9mo ago
May 3rd, 2024
/feeds/core/detection-rules/brand-impersonation-amazon-with-suspicious-attachment-5751dcb9
Brand Impersonation: Capital One
Sublime Security
6d ago
Feb 11th, 2025
/feeds/core/detection-rules/brand-impersonation-capital-one-d53848e4
Brand Impersonation: Chase bank with credential phishing indicators
Sublime Security
9mo ago
Apr 25th, 2024
/feeds/core/detection-rules/brand-impersonation-chase-bank-with-credential-phishing-indicators-d9577856
Brand Impersonation: Coinbase with suspicious links
Sublime Security
2y ago
Nov 18th, 2023
/feeds/core/detection-rules/brand-impersonation-coinbase-with-suspicious-links-b61e2f8e
Brand impersonation: DocuSign branded attachment lure with no DocuSign links
Sublime Security
2mo ago
Dec 18th, 2024
/feeds/core/detection-rules/brand-impersonation-docusign-branded-attachment-lure-with-no-docusign-links-814a5694
Brand impersonation: DocuSign (QR code)
Sublime Security
8mo ago
Jun 12th, 2024
/feeds/core/detection-rules/brand-impersonation-docusign-qr-code-0b16c28a
Brand Impersonation: DocuSign with embedded QR code
Sublime Security
9mo ago
May 2nd, 2024
/feeds/core/detection-rules/brand-impersonation-docusign-with-embedded-qr-code-f5cde463
Brand impersonation: Fake fax
Sublime Security
11mo ago
Feb 23rd, 2024
/feeds/core/detection-rules/brand-impersonation-fake-fax-2a96b90a
Brand impersonation: Google fake sign-in warning
Sublime Security
2y ago
Aug 21st, 2023
/feeds/core/detection-rules/brand-impersonation-google-fake-sign-in-warning-2d998eee
Brand Impersonation: Google (QR Code)
Sublime Security
10mo ago
Apr 3rd, 2024
/feeds/core/detection-rules/brand-impersonation-google-qr-code-7ffd184c
Brand impersonation: Gusto
Sublime Security
9mo ago
Apr 23rd, 2024
/feeds/core/detection-rules/brand-impersonation-gusto-54025c1c
Brand impersonation: Hulu
Sublime Security
13d ago
Feb 4th, 2025
/feeds/core/detection-rules/brand-impersonation-hulu-6833de58
Brand impersonation: KnowBe4
Sublime Security
2mo ago
Nov 25th, 2024
/feeds/core/detection-rules/brand-impersonation-knowbe4-7c798386
Brand impersonation: Microsoft fake sign-in alert
Sublime Security
9mo ago
Apr 25th, 2024
/feeds/core/detection-rules/brand-impersonation-microsoft-fake-sign-in-alert-3f4c9e7a
Brand impersonation: Microsoft logo or suspicious language with open redirect
Sublime Security
11mo ago
Mar 7th, 2024
/feeds/core/detection-rules/brand-impersonation-microsoft-logo-or-suspicious-language-with-open-redirect-27b8d8d8
Brand impersonation: Microsoft (QR code)
Sublime Security
6mo ago
Aug 9th, 2024
/feeds/core/detection-rules/brand-impersonation-microsoft-qr-code-ed0f772a
Brand impersonation: Microsoft quarantine release notification in body
Sublime Security
7mo ago
Jun 27th, 2024
/feeds/core/detection-rules/brand-impersonation-microsoft-quarantine-release-notification-in-body-6d19527c
Brand impersonation: Microsoft quarantine release notification in image attachment
Sublime Security
7mo ago
Jun 27th, 2024
/feeds/core/detection-rules/brand-impersonation-microsoft-quarantine-release-notification-in-image-attachment-185db6b3
Brand impersonation: Microsoft with embedded logo and credential theft language
Sublime Security
1mo ago
Jan 10th, 2025
/feeds/core/detection-rules/brand-impersonation-microsoft-with-embedded-logo-and-credential-theft-language-3ee9ef3d
Brand impersonation: Microsoft with low reputation links
Sublime Security
2mo ago
Dec 18th, 2024
/feeds/core/detection-rules/brand-impersonation-microsoft-with-low-reputation-links-b59201b6
Brand impersonation: Okta
Sublime Security
9mo ago
Apr 23rd, 2024