Tactic or Technique: Evasion

Evasion techniques help attackers sneak past email security filters by hiding or disguising malicious content. These tactics are designed to fool both traditional scanners and newer AI-based systems by changing how the message is structured or displayed.
You might see phishing content buried under blocks of harmless-looking text, or important details shown as images so they can't be scanned. Some messages break up keywords using hidden HTML or use misspelled words and lookalike characters to trick you into missing the signs.
More advanced versions use JavaScript that reveals the payload only after the message has passed through security checks. Others try to confuse AI systems with prompt injection or strange formatting.
These techniques create gaps in protection and give attackers a better chance of reaching your inbox. Spotting them early is key. The more familiar you are with how these tricks work, the easier it is to catch them before they do damage.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Link: Fake forwarded message with suspicious URL in plain text
17h ago
Jul 20th, 2026
Sublime Security
Service abuse: Zoom Clips with unregistered reply-to domain
4d ago
Jul 17th, 2026
Sublime Security
Cyrillic vowel substitutions with suspicious subject from unknown sender
4d ago
Jul 17th, 2026
Sublime Security
Link: Suspicious wp-admin path from mismatched sender domain
4d ago
Jul 17th, 2026
Sublime Security
Attachment: PDF with secure document acknowledgment prompt
4d ago
Jul 17th, 2026
Sublime Security
Attachment: ICS file with AWS Lambda URL
5d ago
Jul 16th, 2026
Sublime Security
Link: Invalid reply-to with recipient details in subject, body, and encoded link
5d ago
Jul 16th, 2026
Sublime Security
Spam: Fake photo share
5d ago
Jul 16th, 2026
Sublime Security
Attachment: Single-page PDF with S3-hosted HTML link
5d ago
Jul 16th, 2026
Sublime Security
Credential phishing: Generic document share with unicode and proceedural greeting template
7d ago
Jul 14th, 2026
Sublime Security
Link: Self-sender with IP geolocation check and suspicious link behavior
7d ago
Jul 14th, 2026
Sublime Security
Malformed URL prefix
7d ago
Jul 14th, 2026
Sublime Security
Attachment: Encrypted PDF with credential theft language in EML
8d ago
Jul 13th, 2026
Sublime Security
Link: Generic financial document with proceedural timeline template
11d ago
Jul 10th, 2026
Sublime Security
VIP impersonation: Fabricated thread history with fake VIP recipients
13d ago
Jul 8th, 2026
Sublime Security
VIP impersonation: Fake forwarded indicator with VIP recipient impersonation
14d ago
Jul 7th, 2026
Sublime Security
VIP impersonation: VIP recipient of previous thread with HTML generator
14d ago
Jul 7th, 2026
Sublime Security
Attachment: PDF Object Hash associated with a fake invoice and a W-9
19d ago
Jul 2nd, 2026
Sublime Security
Open redirect: JustPaste.it
19d ago
Jul 2nd, 2026
Sublime Security
Attachment: Suspicious PDF created with headless browser
20d ago
Jul 1st, 2026
Sublime Security