-
Notifications
You must be signed in to change notification settings - Fork 94
Pull requests: sublime-security/sublime-rules
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
Update link_credential_phishing_secure_message.yml
hunting-required
Hunts needed to validate rule efficacy
test-rules:excluded:link_analysis
Link analysis in rule, excluding from test rules
#4363
opened Apr 16, 2026 by
markmsublime
Member
Loading…
Create attachment_ics_file_new_link_domain.yml
in-test-rules
PR is in our testing suite to collect telemetry
#4362
opened Apr 16, 2026 by
markmsublime
Member
Loading…
Update credential_phishing_suspicious_subject_nlu_financial_urgent.yml
in-test-rules
PR is in our testing suite to collect telemetry
#4360
opened Apr 16, 2026 by
JFarina5
Member
Loading…
Add YARA rule compilation validation to CI
#4357
opened Apr 15, 2026 by
aidenmitchell
Member
Loading…
1 of 2 tasks
Create attachment_pdf_base64_javascript_eval.yml
#4355
opened Apr 15, 2026 by
keaton-sublime
Member
•
Draft
Create impersonation_openai_payment_issues.yml
in-test-rules
PR is in our testing suite to collect telemetry
#4354
opened Apr 15, 2026 by
hadojae
Member
Loading…
Create attachment_pdf_CVE_2026_34621_lures.yml
#4352
opened Apr 15, 2026 by
keaton-sublime
Member
•
Draft
Create attachment_pdf_with_jsfck_yara.yml
#4351
opened Apr 15, 2026 by
keaton-sublime
Member
•
Draft
Update observed IOC rules - 2026-04-15
shared-samples:excluded:author_membership
test-rules:excluded:author_membership
#4350
opened Apr 15, 2026 by
github-actions
bot
•
Draft
3 tasks
Add "ICS Phishing" attack type to calendar/ICS rules
shared-samples:excluded:bulk_rules
test-rules:excluded:bulk_rules
Bulk rule update, excluded from test rules
#4344
opened Apr 14, 2026 by
aidenmitchell
Member
Loading…
Update brand_impersonation_robinhood.yml
in-test-rules
PR is in our testing suite to collect telemetry
#4319
opened Apr 6, 2026 by
cybher0808
Member
Loading…
Create body_spouse_fake_call.yml
in-test-rules
PR is in our testing suite to collect telemetry
#4317
opened Apr 6, 2026 by
keaton-sublime
Member
•
Draft
Create credential_theft_new_domain.yml
in-test-rules
PR is in our testing suite to collect telemetry
#4311
opened Apr 3, 2026 by
cybher0808
Member
Loading…
Create body_html_hidden_conversation.yml
in-test-rules
PR is in our testing suite to collect telemetry
#4308
opened Apr 3, 2026 by
D-Bolton
Member
Loading…
Create body_ai_gen_credential_theft_suspect_indicators.yml
in-test-rules
PR is in our testing suite to collect telemetry
#4304
opened Apr 3, 2026 by
IndiaAce
Member
Loading…
Update qr_code_suspicious_indicators.yml
hunting-required
Hunts needed to validate rule efficacy
test-rules:excluded:link_analysis
Link analysis in rule, excluding from test rules
#4301
opened Apr 2, 2026 by
hadojae
Member
Loading…
Create callback_scam_file_extensions.yml
in-test-rules
PR is in our testing suite to collect telemetry
#4300
opened Apr 2, 2026 by
cybher0808
Member
Loading…
Update fake_thread_suspicious_indicators.yml
in-test-rules
PR is in our testing suite to collect telemetry
#4289
opened Apr 1, 2026 by
IndiaAce
Member
Loading…
Refactor exclusion logic for low reputation links
in-test-rules
PR is in our testing suite to collect telemetry
#4281
opened Mar 31, 2026 by
peterdj45
Member
Loading…
Refine detection rules for SharePoint fake file shares
in-test-rules
PR is in our testing suite to collect telemetry
#4280
opened Mar 31, 2026 by
peterdj45
Member
Loading…
Create impersonate_hubspot_suspicious_content.yml
in-test-rules
PR is in our testing suite to collect telemetry
#4277
opened Mar 30, 2026 by
IndiaAce
Member
Loading…
Negate SharePoint shares with Mimecast rewrites
in-test-rules
PR is in our testing suite to collect telemetry
#4276
opened Mar 30, 2026 by
peterdj45
Member
Loading…
Negate SharePoint file shares with Mimecast rewrites
in-test-rules
PR is in our testing suite to collect telemetry
#4275
opened Mar 30, 2026 by
peterdj45
Member
Loading…
Create service_abuse_suspicious_soundestlink_redirect.yml
in-test-rules
PR is in our testing suite to collect telemetry
#4264
opened Mar 25, 2026 by
keaton-sublime
Member
•
Draft
Previous Next
ProTip!
Type g i on any issue or pull request to go back to the issue listing page.