Sublime Core Feed
This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.
Sublime Security
Last updated Mar 21st, 2025
Feed Source
Tactic or Technique is
Rule Name & Severity | Author | Last Updated | Labels | |
---|---|---|---|---|
Attachment: Calendar invite with suspicious link leading to an open redirect | Sublime Security | 11mo ago Apr 25th, 2024 | /feeds/core/detection-rules/attachment-calendar-invite-with-suspicious-link-leading-to-an-open-redirect-5d6294c7 | |
Attachment: EML file with IPFS links | Sublime Security | 11mo ago Apr 25th, 2024 | /feeds/core/detection-rules/attachment-eml-file-with-ipfs-links-1fe9d7e7 | |
Attachment: EML with link to credential phishing page | Sublime Security | 6mo ago Sep 13th, 2024 | /feeds/core/detection-rules/attachment-eml-with-link-to-credential-phishing-page-1df41cca | |
Attachment: HTML Smuggling Microsoft Sign In | Sublime Security | 1y ago Jan 31st, 2024 | /feeds/core/detection-rules/attachment-html-smuggling-microsoft-sign-in-878d6385 | |
Attachment: HTML smuggling with raw array buffer | Sublime Security | 2y ago Aug 21st, 2023 | /feeds/core/detection-rules/attachment-html-smuggling-with-raw-array-buffer-a0d5c3dc | |
Attachment: PDF with credential theft language and link to a free subdomain (unsolicited) | Sublime Security | 1y ago Jan 30th, 2024 | /feeds/core/detection-rules/attachment-pdf-with-credential-theft-language-and-link-to-a-free-subdomain-unsolicited-90f4ef4e | |
Brand Impersonation: Coinbase with suspicious links | Sublime Security | 2y ago Nov 18th, 2023 | /feeds/core/detection-rules/brand-impersonation-coinbase-with-suspicious-links-b61e2f8e | |
Brand impersonation: Fake fax | Sublime Security | 1y ago Feb 23rd, 2024 | /feeds/core/detection-rules/brand-impersonation-fake-fax-2a96b90a | |
ClickFunnels link infrastructure abuse | Sublime Security | 5mo ago Oct 8th, 2024 | /feeds/core/detection-rules/clickfunnels-link-infrastructure-abuse-9192fbe9 | |
Credential phishing: Engaging language with IPFS link | Sublime Security | 10mo ago May 3rd, 2024 | /feeds/core/detection-rules/credential-phishing-engaging-language-with-ipfs-link-996c4d83 | |
Credential phishing: Onedrive impersonation | Sublime Security | 1mo ago Feb 3rd, 2025 | /feeds/core/detection-rules/credential-phishing-onedrive-impersonation-1f990c92 | |
Free subdomain link with credential theft indicators | Sublime Security | 3mo ago Dec 12th, 2024 | /feeds/core/detection-rules/free-subdomain-link-with-credential-theft-indicators-9187479c | |
Free subdomain link with login or captcha (untrusted sender) | Sublime Security | 11mo ago Apr 25th, 2024 | /feeds/core/detection-rules/free-subdomain-link-with-login-or-captcha-untrusted-sender-93288f82 | |
Invoicera infrastructure abuse | Sublime Security | 1y ago Mar 7th, 2024 | /feeds/core/detection-rules/invoicera-infrastructure-abuse-1e56f310 | |
Link: Abused Adobe Express | Sublime Security | 3mo ago Dec 16th, 2024 | /feeds/core/detection-rules/link-abused-adobe-express-c7d17bfd | |
Link: Free Subdomain host with undisclosed recipients | Sublime Security | 8mo ago Jun 27th, 2024 | /feeds/core/detection-rules/link-free-subdomain-host-with-undisclosed-recipients-c23d979d | |
Link: IPFS | Sublime Security | 5mo ago Oct 16th, 2024 | /feeds/core/detection-rules/link-ipfs-19fa6442 | |
Link: Jensi File Preview Link from Unsolicited Sender | Sublime Security | 5mo ago Oct 2nd, 2024 | /feeds/core/detection-rules/link-jensi-file-preview-link-from-unsolicited-sender-122b39f3 | |
Link: Multistage Landing - Abused Docusign | Sublime Security | 2mo ago Jan 3rd, 2025 | /feeds/core/detection-rules/link-multistage-landing-abused-docusign-4189a645 | |
Link: Webflow Link from Unsolicited Sender | Sublime Security | 6mo ago Sep 16th, 2024 | /feeds/core/detection-rules/link-webflow-link-from-unsolicited-sender-d4f3b8cf | |
Low reputation link to auto-downloaded HTML file with smuggling indicators | Sublime Security | 10mo ago May 9th, 2024 | /feeds/core/detection-rules/low-reputation-link-to-auto-downloaded-html-file-with-smuggling-indicators-339676c6 | |
Message Traversed Multiple onmicrosoft.com Tenants | Sublime Security | 3mo ago Dec 18th, 2024 | /feeds/core/detection-rules/message-traversed-multiple-onmicrosoftcom-tenants-9cf01c0d | |
Shopify infrastructure abuse | Sublime Security | 4mo ago Nov 13th, 2024 | /feeds/core/detection-rules/shopify-infrastructure-abuse-844ff164 | |
Spam: Link to blob.core.windows.net from new domain (<30d) | Sublime Security | 10mo ago May 21st, 2024 | /feeds/core/detection-rules/spam-link-to-blobcorewindowsnet-from-new-domain-less30d-a09b3800 | |
Spoofable internal domain with suspicious signals | Sublime Security | 10mo ago May 3rd, 2024 | /feeds/core/detection-rules/spoofable-internal-domain-with-suspicious-signals-40089d69 |