Sublime rules
Sublime rules for email attack detection, prevention, and threat hunting.
This repo contains open-source rules for [Sublime](https://github.com/sublime-security/sublime-platform), a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing. The project is written primarily in YAML, distributed under the MIT License license, first published in 2021. Key topics include: email-security, phishing, threat-hunting.
<a href="https://sublimesecurity.com"><img src="https://user-images.githubusercontent.com/11003450/115128085-5805da00-9fa9-11eb-8c7a-dc8b708053ee.png" width="75px" alt="Sublime Logo" /></a>
Sublime Rules
by Sublime Security
This repo contains open-source rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.
Examples
- HTML smuggling
- VIP / Executive impersonation
- Malicious OneNote files
- Malicious LNK files
- Encrypted zips
Community Rule Feeds
Learn more
Follow us on Twitter for updates on new rules and detection capabilities.
Contributors
Showing top 12 contributors by commit count.
