• Sublime Core Feed

Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Mar 21st, 2025
Feed Source
GitHub
Tactic or Technique is
Rule Name & Severity
Author
Last Updated
Labels
Attachment with VBA macros from employee impersonation (unsolicited)
Sublime Security
1y ago
Feb 26th, 2024
Malware/Ransomware
Impersonation: Employee
Macros
Social engineering
Archive analysis
File analysis
Macro analysis
Sender analysis
/feeds/core/detection-rules/attachment-with-vba-macros-from-employee-impersonation-unsolicited-9b262123
BEC: Employee impersonation with subject manipulation
Sublime Security
1y ago
Jan 22nd, 2024
/feeds/core/detection-rules/bec-employee-impersonation-with-subject-manipulation-9adfc77b
Benefits Enrollment Impersonation
Sublime Security
1mo ago
Jan 30th, 2025
/feeds/core/detection-rules/benefits-enrollment-impersonation-5a6eb5a8
Corporate Services Impersonation Phishing
Sublime Security
24d ago
Feb 27th, 2025
/feeds/core/detection-rules/corporate-services-impersonation-phishing-3cd04f33
Employee Impersonation: Payroll Fraud
Sublime Security
3mo ago
Dec 16th, 2024
/feeds/core/detection-rules/employee-impersonation-payroll-fraud-2beb7d85
Employee impersonation with urgent request (untrusted sender)
Sublime Security
8mo ago
Jul 17th, 2024
/feeds/core/detection-rules/employee-impersonation-with-urgent-request-untrusted-sender-1ce9a146
Impersonation: Human Resources with link or attachment and engaging language
Sublime Security
3d ago
Mar 20th, 2025
/feeds/core/detection-rules/impersonation-human-resources-with-link-or-attachment-and-engaging-language-8c95a6a8
Sharepoint Link Likely Unrelated to Sender
Sublime Security
11d ago
Mar 12th, 2025
/feeds/core/detection-rules/sharepoint-link-likely-unrelated-to-sender-6870f489
Suspicious Request for Financial Information
Sublime Security
3mo ago
Nov 25th, 2024
/feeds/core/detection-rules/suspicious-request-for-financial-information-4ebdaa4d
VIP Impersonation via Google Group relay with suspicious indicators
Sublime Security
10mo ago
May 3rd, 2024
/feeds/core/detection-rules/vip-impersonation-via-google-group-relay-with-suspicious-indicators-57f9cd3b
VIP impersonation with charitable donation fraud
Sublime Security
5mo ago
Oct 8th, 2024
/feeds/core/detection-rules/vip-impersonation-with-charitable-donation-fraud-35a56b8e