Skip to content

Sublime detection rules and queries for phishing defense, DLP, and compliance.

License

Notifications You must be signed in to change notification settings

itsojon/sublime-rules

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Sublime Logo

Sublime Rules

by Sublime Security

This repo contains open-source detection rules and queries for the Sublime Platform.

Common phishing defense rules

  • CEO, executive, brand, vendor, and contact impersonation
  • Lookalike and homoglyph attacks
  • Suspicious HTML attachments
  • Mass mailer abuse (eg Sendgrid, Constant Contact)
  • Blocking IOCs (sender emails, domains, hashes)

Learn more

Follow us on Twitter for updates on new rules and detection capabilities.

Sublime Platform is currently in early access, which means it's not publicly available yet. You can request early access here.

About

Sublime detection rules and queries for phishing defense, DLP, and compliance.

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published