Skip to main content
PPPhishPondPhishing Tradecraft Intelligence

Attack · Detection · Validation

CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe
CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe

Research Desk

PhishPond

Phishing tradecraft research desk covering campaign analysis, adversary infrastructure, detection engineering, and validation workflows.

High signal for security teams who need tradecraft, not recycled filler.

Navigate

  • Home
  • Newsroom
  • Research
  • Subscribe

Signals

  • editorial@phishpond.dev
  • Research Mission & Ethics
  • Intel Brief
  • RSS Feed
  • Submit Research Tip
© 2026 PhishPond. Authorized security research use only.

GitHub RadarBlue team tool

sublime-security/sublime-rules

Sublime rules for email attack detection, prevention, and threat hunting. Primary language: YAML. 364 stars.

YAML364 stars99 forkspushed Jun 12, 2026MIT

Project links:Open GitHub projectBack to radar

README Preview

Fetched from GitHub

<a href="https://sublimesecurity.com"><img src="https://user-images.githubusercontent.com/11003450/115128085-5805da00-9fa9-11eb-8c7a-dc8b708053ee.png" width="75px" alt="Sublime Logo" /></a>

Sublime Rules ========== by Sublime Security

This repo contains open-source rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Examples ----------

  • HTML smuggling
  • VIP / Executive impersonation
  • Malicious OneNote files
  • Malicious LNK files
  • Encrypted zips

Community Rule Feeds ----------

  • DelivrTo
  • vector-sec
  • amitchell516

Learn more ----------

  • Blog
  • Docs
  • Message Query Language (MQL) reference
  • Release log

Follow us on Twitter for updates on new rules and detection capabilities.