-
Notifications
You must be signed in to change notification settings - Fork 86
Pull requests: sublime-security/sublime-rules
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
Add detection rule for Zendesk callback phishing
in-test-rules
PR is in our testing suite to collect telemetry
#3913
opened Jan 31, 2026 by
peterdj45
Loading…
Update paypal_invoice_abuse.yml
in-test-rules
PR is in our testing suite to collect telemetry
#3912
opened Jan 30, 2026 by
markmsublime
Loading…
Create impersonation_missing_headers.yml
in-test-rules
PR is in our testing suite to collect telemetry
#3911
opened Jan 30, 2026 by
MSAdministrator
Loading…
Create attachment_pdf_view_prompt.yml
in-test-rules
PR is in our testing suite to collect telemetry
review-needed
Indicates that a PR is waiting for review
#3910
opened Jan 30, 2026 by
D-Bolton
Loading…
Update impersonation_microsoft.yml
in-test-rules
PR is in our testing suite to collect telemetry
#3909
opened Jan 30, 2026 by
markmsublime
Loading…
Add detection rule for Anthropic Claude magic strings
review-needed
Indicates that a PR is waiting for review
test-rules:excluded:author_membership
#3908
opened Jan 30, 2026 by
vector-sec
Loading…
[senderprofile] Update recon_email_address_harvesting_attempt.yml
in-test-rules
PR is in our testing suite to collect telemetry
#3907
opened Jan 30, 2026 by
MSAdministrator
Loading…
[senderprofile] Update attachment_vba_macro_high_risk.yml
in-test-rules
PR is in our testing suite to collect telemetry
#3906
opened Jan 30, 2026 by
MSAdministrator
Loading…
[senderprofile] Update callback_phishing_nlu_body_or_attachments.yml
in-test-rules
PR is in our testing suite to collect telemetry
#3905
opened Jan 30, 2026 by
MSAdministrator
Loading…
[senderprofile] Update qr_code_suspicious_indicators.yml
hunting-required
Hunts needed to validate rule efficacy
test-rules:excluded:link_analysis
Link analysis in rule, excluding from test rules
#3904
opened Jan 30, 2026 by
MSAdministrator
Loading…
[senderprofile] Update recon_short_generic_greeting.yml
in-test-rules
PR is in our testing suite to collect telemetry
#3903
opened Jan 30, 2026 by
MSAdministrator
Loading…
Create link_hotel_url_redirect.yml
in-test-rules
PR is in our testing suite to collect telemetry
#3902
opened Jan 29, 2026 by
JFarina5
Loading…
Create detection rule for Anthropic Magic String
in-test-rules
PR is in our testing suite to collect telemetry
#3901
opened Jan 29, 2026 by
IndiaAce
Loading…
Update Trello board invitation with VIP impersonation
in-test-rules
PR is in our testing suite to collect telemetry
#3900
opened Jan 29, 2026 by
IndiaAce
Loading…
Update impersonation_dropbox.yml
in-test-rules
PR is in our testing suite to collect telemetry
#3899
opened Jan 29, 2026 by
markmsublime
Loading…
Update vip_impersonation.yml
in-test-rules
PR is in our testing suite to collect telemetry
#3898
opened Jan 29, 2026 by
zoomequipd
Loading…
Add detection rule for Behance deceptive project names
hunting-required
Hunts needed to validate rule efficacy
test-rules:excluded:link_analysis
Link analysis in rule, excluding from test rules
#3897
opened Jan 29, 2026 by
IndiaAce
Loading…
Add detection rule for MSG files with VBA macros
in-test-rules
PR is in our testing suite to collect telemetry
#3896
opened Jan 29, 2026 by
peterdj45
Loading…
Add detection rule for CMD file attachments
in-test-rules
PR is in our testing suite to collect telemetry
#3894
opened Jan 28, 2026 by
peterdj45
Loading…
Add detection rule for BAT file attachments
in-test-rules
PR is in our testing suite to collect telemetry
#3893
opened Jan 28, 2026 by
peterdj45
Loading…
Create suspicious_relocation_theme.yml
in-test-rules
PR is in our testing suite to collect telemetry
#3891
opened Jan 28, 2026 by
keaton-sublime
•
Draft
Create attachment_pdf_w9_invoice_lure.yml
in-test-rules
PR is in our testing suite to collect telemetry
review-needed
Indicates that a PR is waiting for review
#3890
opened Jan 28, 2026 by
keaton-sublime
Loading…
Create attachment_pdf_view_doc.yml
in-test-rules
PR is in our testing suite to collect telemetry
#3889
opened Jan 28, 2026 by
keaton-sublime
•
Draft
Create callback_scam_with_alternate_contact_method.yml
in-test-rules
PR is in our testing suite to collect telemetry
#3888
opened Jan 28, 2026 by
hadojae
Loading…
Previous Next
ProTip!
Type g p on any issue or pull request to go back to the pull request listing page.