11/12 free views
Tool
Framework
Email Security

sublime-rules

by sublime-security

334stars
80forks
19watchers
Updated 4 months ago
About

Sublime Rules offers open-source rules for detecting and preventing email attacks like phishing and malware.

Sublime rules for email attack detection, prevention, and threat hunting.

Primary Use Case

Sublime Rules is used by security professionals and organizations to enhance their email security by detecting and preventing various email threats such as BEC, malware, and credential phishing. It is particularly useful for threat hunting and intrusion detection in email communications.

Key Features
  • Detection of HTML smuggling attacks
  • Identification of VIP/executive impersonation
  • Detection of malicious OneNote files
  • Detection of malicious LNK files
  • Detection of encrypted zip files
Security Frameworks
Initial Access
Execution
Defense Evasion
Credential Access
Collection
Usage Insights
  • Repurposing: Beyond email security, Sublime Rules can be adapted to monitor internal communications for insider threats by detecting unusual patterns in message content and attachments.
  • Chaining: Combine Sublime Rules with a SIEM tool like Splunk to correlate email threat data with network traffic anomalies, enhancing detection capabilities for lateral movement post-email compromise.
  • Evasion/Detection: Attackers might use advanced obfuscation techniques or encrypted payloads to bypass detection. Implementing machine learning models to analyze email metadata and content patterns can enhance detection of such evasion tactics.
  • Data Fusion: Integrate Sublime Rules output with threat intelligence platforms to enrich email threat data with global threat actor profiles, improving context for incident response teams.
  • Automation: Use orchestration tools like SOAR to automate responses to detected threats by Sublime Rules, such as isolating affected accounts or blocking malicious IPs, streamlining SOC operations.

Docs Take 2 Hours. AI Takes 10 Seconds.

Ask anything about sublime-rules. Installation? Config? Troubleshooting? Get answers trained on real docs and GitHub issues—not generic ChatGPT fluff.

This tool hasn't been indexed yet. Request indexing to enable AI chat.

Admin will review your request within 24 hours

Security Profile
Red Team80%
Blue Team90%
Purple Team85%
Details
LicenseMIT License
LanguageYAML
Open Issues0
Topics
email-security
phishing
threat-hunting