-
Notifications
You must be signed in to change notification settings - Fork 93
Pull requests: sublime-security/sublime-rules
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
Update observed IOC rules - 2026-04-30
shared-samples:excluded:author_membership
test-rules:excluded:author_membership
#4427
opened Apr 30, 2026 by
github-actions
Bot
Loading…
Update impersonation_paypal.yml
in-test-rules
PR is in our testing suite to collect telemetry
#4426
opened Apr 30, 2026 by
JFarina5
Member
Loading…
Enhance UPS impersonation detection rules
in-test-rules
PR is in our testing suite to collect telemetry
#4425
opened Apr 29, 2026 by
peterdj45
Member
Loading…
Update body_extortion.yml
in-test-rules
PR is in our testing suite to collect telemetry
#4423
opened Apr 29, 2026 by
JFarina5
Member
Loading…
Update link_romance_suspicious.yml
in-test-rules
PR is in our testing suite to collect telemetry
#4422
opened Apr 29, 2026 by
JFarina5
Member
Loading…
Update impersonation_employee_payroll_fraud.yml
in-test-rules
PR is in our testing suite to collect telemetry
#4420
opened Apr 29, 2026 by
JFarina5
Member
Loading…
Update attachment_pdf_skia_headless.yml
in-test-rules
PR is in our testing suite to collect telemetry
#4418
opened Apr 29, 2026 by
markmsublime
Member
Loading…
Update attachment_sus_pdf_chrome.yml
in-test-rules
PR is in our testing suite to collect telemetry
#4417
opened Apr 29, 2026 by
markmsublime
Member
Loading…
Create impersonation_employee_initial_contact.yml
in-test-rules
PR is in our testing suite to collect telemetry
#4416
opened Apr 28, 2026 by
MSAdministrator
Member
Loading…
Update link_credential_phishing_cloud_service.yml
in-test-rules
PR is in our testing suite to collect telemetry
review-needed
Indicates that a PR is waiting for review
#4407
opened Apr 27, 2026 by
JFarina5
Member
Loading…
Update link_fake_zoom_invite.yml
hunting-required
Hunts needed to validate rule efficacy
test-rules:excluded:link_analysis
Link analysis in rule, excluding from test rules
#4402
opened Apr 27, 2026 by
IndiaAce
Member
Loading…
Create service_abuse_claude_console_from_freemailer.yml
#4397
opened Apr 24, 2026 by
IndiaAce
Member
Loading…
Add French language check to self sender rule
in-test-rules
PR is in our testing suite to collect telemetry
#4395
opened Apr 24, 2026 by
peterdj45
Member
Loading…
Create subject_fake_zoom_link.yml
in-test-rules
PR is in our testing suite to collect telemetry
review-needed
Indicates that a PR is waiting for review
#4394
opened Apr 23, 2026 by
D-Bolton
Member
Loading…
Update pencil rule to cover mismatched entities & missing unicode
in-test-rules
PR is in our testing suite to collect telemetry
#4391
opened Apr 23, 2026 by
missingn0pe
Member
Loading…
Update impersonation_microsoft_teams.yml
in-test-rules
PR is in our testing suite to collect telemetry
#4375
opened Apr 21, 2026 by
markmsublime
Member
Loading…
update impersonation SAA rule
in-test-rules
PR is in our testing suite to collect telemetry
#4373
opened Apr 20, 2026 by
cybher0808
Member
Loading…
Restructured "Attach: Sus Employee Lure" rule
in-test-rules
PR is in our testing suite to collect telemetry
#4369
opened Apr 17, 2026 by
missingn0pe
Member
Loading…
Create detection rule for invoice/inquiry current thread
in-test-rules
PR is in our testing suite to collect telemetry
review-needed
Indicates that a PR is waiting for review
#4368
opened Apr 17, 2026 by
cybher0808
Member
Loading…
Update headers_replyto_new_domain_nlu_request.yml
in-test-rules
PR is in our testing suite to collect telemetry
#4364
opened Apr 17, 2026 by
IndiaAce
Member
Loading…
Add YARA rule compilation validation to CI
#4357
opened Apr 15, 2026 by
aidenmitchell
Member
Loading…
1 of 2 tasks
Create attachment_pdf_base64_javascript_eval.yml
in-test-rules
PR is in our testing suite to collect telemetry
#4355
opened Apr 15, 2026 by
keaton-sublime
Member
•
Draft
Update brand_impersonation_robinhood.yml
in-test-rules
PR is in our testing suite to collect telemetry
#4319
opened Apr 6, 2026 by
cybher0808
Member
Loading…
Create body_html_hidden_conversation.yml
in-test-rules
PR is in our testing suite to collect telemetry
#4308
opened Apr 3, 2026 by
D-Bolton
Member
Loading…
Create body_ai_gen_credential_theft_suspect_indicators.yml
in-test-rules
PR is in our testing suite to collect telemetry
#4304
opened Apr 3, 2026 by
IndiaAce
Member
Loading…
Previous Next
ProTip!
Follow long discussions with comments:>50.