- Home
- Email Security
- Email Security Platforms
- Sublime Security Sublime Rules
Sublime Security Sublime Rules
Open-source detection rules for email attacks like BEC, phishing, and malware

Sublime Security Sublime Rules
Open-source detection rules for email attacks like BEC, phishing, and malware
Sublime Security Sublime Rules Description
Sublime Rules is an open-source repository containing detection rules for the Sublime Security platform. The repository provides rules designed to identify and prevent various email-based attacks including business email compromise (BEC), credential phishing, and malware delivery. The repository is organized into multiple categories including detection rules, discovery rules, DLP discovery rules, automations, insights, and YARA rules. It includes specific detection capabilities for HTML smuggling, VIP and executive impersonation, malicious OneNote files, malicious LNK files, and encrypted zip attachments. The rules are written using Message Query Language (MQL), a query language specific to the Sublime platform for analyzing email messages. The repository contains over 3,000 commits and has contributions from 71 contributors, indicating active development and community involvement. The project is released under the MIT license, making it freely available for use and modification. The repository includes sample email files (EMLs), tutorial files, and scripts to support rule development and testing. Community members have also created additional rule feeds that complement the main repository.
Sublime Security Sublime Rules FAQ
Common questions about Sublime Security Sublime Rules including features, pricing, alternatives, and user reviews.
Sublime Security Sublime Rules is Open-source detection rules for email attacks like BEC, phishing, and malware developed by Sublime Security. It is a Email Security solution designed to help security teams with Community Driven, DLP, Detection Rules.
FEATURED
Cybercrime intelligence tools for searching compromised credentials from infostealers
Password manager with end-to-end encryption and identity protection features
VPN service providing encrypted internet connections and privacy protection
Fractional CISO services for B2B companies to build security programs
Stay Updated with Mandos Brief
Get the latest cybersecurity updates in your inbox
TRENDING CATEGORIES
POPULAR
A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.
AI security assurance platform for red-teaming, guardrails & compliance
Real-time OSINT monitoring for leaked credentials, data, and infrastructure