Detection Method: Archive analysis

Archive analysis is the process of unpacking compressed files like ZIPs, RARs, or TARs to find threats hidden inside. Attackers often bury malicious payloads in multiple layers of archives to bypass basic scanning. This method digs into those layers to expose what’s really inside.
Security systems use recursive unpacking to detect things like:
  • Scripts or executables hidden in nested ZIPs
  • Macro-enabled documents disguised inside archive chains
  • Encrypted files used to evade detection
For example, an attacker might send a ZIP file that contains another ZIP, which holds a Word document with malicious macros. Archive analysis unpacks each layer and inspects the contents individually.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: PDF file with low reputation link to ZIP file (unsolicited)
11d ago
Jan 12th, 2026
Michael Tingle
/feeds/core/detection-rules/attachment-pdf-file-with-low-reputation-link-to-zip-file-unsolicited-d1ee2859
Attachment soliciting user to enable macros
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-soliciting-user-to-enable-macros-e9d75515
Attachment: Embedded Javascript in SVG file
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-embedded-javascript-in-svg-file-f70293bc
Attachment: Malicious OneNote commands
11d ago
Jan 12th, 2026
@Kyle_Parrish_
/feeds/core/detection-rules/attachment-malicious-onenote-commands-7319f0eb
Attachment: Embedded VBScript in MHT file (unsolicited)
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-embedded-vbscript-in-mht-file-unsolicited-b30353a6
Attachment: Office file with credential phishing URLs
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-office-file-with-credential-phishing-urls-b2cae98d
Attachment: Office document with VSTO add-in
11d ago
Jan 12th, 2026
@vector_sec
/feeds/core/detection-rules/attachment-office-document-with-vsto-add-in-27afa730
Attachment: Office document loads remote document template
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-office-document-loads-remote-document-template-d9601104
Attachment: Office file with suspicious function calls or downloaded file path
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-office-file-with-suspicious-function-calls-or-downloaded-file-path-4c78b969
Attachment: PDF with link to DMG file download
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-pdf-with-link-to-dmg-file-download-2c486fe0
Attachment: PDF with link to zip containing a wsf file
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-pdf-with-link-to-zip-containing-a-wsf-file-93bc7db4
Attachment: PDF file with low reputation links to suspicious filetypes (unsolicited)
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-pdf-file-with-low-reputation-links-to-suspicious-filetypes-unsolicited-6144f880
Attachment: WinRAR CVE-2025-8088 exploitation
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-winrar-cve-2025-8088-exploitation-33b3a82b
Attachment: HTML smuggling with ROT13
11d ago
Jan 12th, 2026
@Kyle_Parrish_
/feeds/core/detection-rules/attachment-html-smuggling-with-rot13-6eacc4cf
Link to auto-download of a suspicious file type (unsolicited)
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/link-to-auto-download-of-a-suspicious-file-type-unsolicited-67ae2152
Attachment: 7z Archive Containing RAR File
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-7z-archive-containing-rar-file-1a629bb4
Attachment: Office file with document sharing and browser instruction lures
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-office-file-with-document-sharing-and-browser-instruction-lures-b1250a4b
Attachment: EML with Encrypted ZIP
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-eml-with-encrypted-zip-6897a8f7
Link to auto-downloaded disk image in encrypted zip
11d ago
Jan 12th, 2026
@ajpc500
/feeds/core/detection-rules/link-to-auto-downloaded-disk-image-in-encrypted-zip-b50f0cb1
Attachment: CVE-2021-40444 - MSHTML Remote Code Execution Vulnerability
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-cve-2021-40444-mshtml-remote-code-execution-vulnerability-8cefcf7f