• Sublime Core Feed

Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Mar 13th, 2026
Feed Source
Tactic or Technique is
Rule Name & Severity
Author
Last Updated
Labels
Attachment: Calendar invite with suspicious link leading to an open redirect
Sublime Security
8mo ago
Jul 16th, 2025
Attachment: EML file with IPFS links
Sublime Security
4mo ago
Nov 4th, 2025
Attachment: EML with link to credential phishing page
Sublime Security
8mo ago
Jul 16th, 2025
Attachment: Fake scan-to-email
Sublime Security
5mo ago
Sep 22nd, 2025
Attachment: PDF with multistage landing - ClickUp abuse
Sublime Security
15d ago
Feb 27th, 2026
Brand impersonation: Fake Fax
Sublime Security
1mo ago
Feb 5th, 2026
Brand impersonation: Microsoft quarantine release notification in image attachment
Sublime Security
8mo ago
Jul 16th, 2025
Brand impersonation: Microsoft with low reputation links
Sublime Security
2mo ago
Jan 12th, 2026
Canva design with suspicious embedded link
Sublime Security
5mo ago
Sep 29th, 2025
Catbox.moe link from untrusted source
Sublime Security
7mo ago
Aug 5th, 2025
Cloud storage impersonation with credential theft indicators
Sublime Security
22h ago
Mar 13th, 2026
Credential phishing: Engaging language with IPFS link
Sublime Security
2y ago
May 3rd, 2024
Credential phishing: Hyper-linked image leading to free file host
Sublime Security
7mo ago
Aug 5th, 2025
Deceptive Dropbox mention
Sublime Security
2mo ago
Jan 12th, 2026
DocuSign impersonation via CloudHQ links
Sublime Security
7mo ago
Aug 5th, 2025
Fake scan-to-email message
Sublime Security
2mo ago
Jan 12th, 2026
Fake shipping notification with link to free file hosting
Sublime Security
2y ago
Jul 10th, 2024
File sharing link from suspicious sender domain
Sublime Security
29d ago
Feb 13th, 2026
File sharing link with a suspicious subject
Sublime Security
25d ago
Feb 17th, 2026
Google Drive abuse: Credential phishing link
Sublime Security
2y ago
Jul 31st, 2024
Google Drive direct download link from unsolicited sender
Sublime Security
8mo ago
Jul 16th, 2025
Google share notification with suspicious comments
Sublime Security
2mo ago
Jan 12th, 2026
Invoicera infrastructure abuse
Sublime Security
2y ago
Mar 7th, 2024
Issuu document with suspicious embedded link
Sublime Security
2mo ago
Jan 12th, 2026
Link: Abused Adobe Express
Sublime Security
7mo ago
Jul 23rd, 2025
Link: Adobe share from unsolicited sender
Sublime Security
2mo ago
Jan 12th, 2026
Link: Adobe share with suspicious indicators
Sublime Security
2mo ago
Jan 12th, 2026
Link: Commonly Abused Web Service redirecting to ZIP file
Sublime Security
4d ago
Mar 10th, 2026
Link: Direct link to gamma.app document with mode parameter
Sublime Security
7mo ago
Aug 5th, 2025
Link: Direct link to keap.app contact-us page
Sublime Security
7mo ago
Aug 5th, 2025
Link: Direct link to limewire hosted file
Sublime Security
6mo ago
Aug 18th, 2025
Link: Direct link to riddle.com hosted showcase
Sublime Security
2mo ago
Jan 12th, 2026
Link: Figma design deck with credential theft language
Sublime Security
10d ago
Mar 4th, 2026
Link: Free file hosting with undisclosed recipients
Sublime Security
19d ago
Feb 23rd, 2026
Link: Google Calendar invite linking to an open redirect from an untrusted freemail sender
Sublime Security
8mo ago
Jul 16th, 2025
Link: IPFS
Sublime Security
2mo ago
Jan 12th, 2026
Link: Jensi file preview link from unsolicited sender
Sublime Security
2mo ago
Jan 12th, 2026
Link: Multistage landing - Abused Adobe frame.io
Sublime Security
7mo ago
Aug 5th, 2025
Link: Multistage Landing - Abused Buildin.ai
Sublime Security
6mo ago
Sep 5th, 2025
Link: Multistage landing - Abused Docusign
Sublime Security
7mo ago
Aug 5th, 2025
Link: Multistage landing - Abused Google Drive
Sublime Security
7mo ago
Aug 5th, 2025
Link: Multistage landing - ClickUp abuse
Sublime Security
15d ago
Feb 27th, 2026
Link: Multistage landing - Published Google Doc
Sublime Security
7mo ago
Aug 5th, 2025
Link: Multistage landing - Scribd document
Sublime Security
2mo ago
Jan 12th, 2026
Link: Multistage landing - Trello board abuse
Sublime Security
6mo ago
Aug 20th, 2025
Link: PDF and financial display text to free file host
Sublime Security
5mo ago
Sep 24th, 2025
Link: Scribd fullscreen link from suspicious sender
Sublime Security
7mo ago
Aug 5th, 2025
Link: Secure SharePoint file share from new or unusual sender
Sublime Security
2mo ago
Jan 12th, 2026
Link: SharePoint OneNote or PDF link with self sender behavior
Sublime Security
15d ago
Feb 27th, 2026
Link: Suspicious SharePoint document name
Sublime Security
29d ago
Feb 13th, 2026