Tactic or Technique: Evasion

Evasion techniques help attackers sneak past email security filters by hiding or disguising malicious content. These tactics are designed to fool both traditional scanners and newer AI-based systems by changing how the message is structured or displayed.
You might see phishing content buried under blocks of harmless-looking text, or important details shown as images so they can't be scanned. Some messages break up keywords using hidden HTML or use misspelled words and lookalike characters to trick you into missing the signs.
More advanced versions use JavaScript that reveals the payload only after the message has passed through security checks. Others try to confuse AI systems with prompt injection or strange formatting.
These techniques create gaps in protection and give attackers a better chance of reaching your inbox. Spotting them early is key. The more familiar you are with how these tricks work, the easier it is to catch them before they do damage.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Service abuse: DocSend share from an unsolicited reply-to address
5d ago
Jun 18th, 2026
Sublime Security
Link: Mamba 2FA phishing kit
5d ago
Jun 18th, 2026
Sublime Security
Body: Fake secure email portal with HTML obfuscation
5d ago
Jun 18th, 2026
Sublime Security
Service abuse: Outlook Groups with Google Sites link and evasion tag
6d ago
Jun 17th, 2026
Sublime Security
Attachment: PDF with a suspicious string and single URL
6d ago
Jun 17th, 2026
Sublime Security
Evasion: Hidden content divs from freemail sender
6d ago
Jun 17th, 2026
Sublime Security
Attachment: PDF Object Hash associated with fake Canada Revenue Agency documents
6d ago
Jun 17th, 2026
Sublime Security
Attachment: Encrypted PDF with credential theft body
6d ago
Jun 17th, 2026
Sublime Security
Fake thread with suspicious indicators
6d ago
Jun 17th, 2026
Sublime Security
Self-impersonation: Sender matches recipient with bolded name and suspicious link
7d ago
Jun 16th, 2026
Sublime Security
HTML content with print styling and credential theft language
7d ago
Jun 16th, 2026
Sublime Security
Fake Zoom meeting invite with suspicious link
7d ago
Jun 16th, 2026
Sublime Security
Body: Yellow highlighted text markers
7d ago
Jun 16th, 2026
Sublime Security
Link: Credential harvesting with excess padding evasion
8d ago
Jun 15th, 2026
Sublime Security
Credential phishing: Generic document sharing
8d ago
Jun 15th, 2026
Sublime Security
Attachment: JPEG with gd-jpeg creator and suspicious file name
11d ago
Jun 12th, 2026
Sublime Security
Link: Concatenated display text concealing duplicate URLs with PDF reference
11d ago
Jun 12th, 2026
Sublime Security
Link: SVG with embedded recipient data
11d ago
Jun 12th, 2026
Sublime Security
Attachment: MS OOXML file created by Administrator with zero edit time
11d ago
Jun 12th, 2026
Sublime Security
Service abuse: Suspicious Datadog alert
12d ago
Jun 11th, 2026
Sublime Security