Tactic or Technique: Evasion

Evasion techniques help attackers sneak past email security filters by hiding or disguising malicious content. These tactics are designed to fool both traditional scanners and newer AI-based systems by changing how the message is structured or displayed.
You might see phishing content buried under blocks of harmless-looking text, or important details shown as images so they can't be scanned. Some messages break up keywords using hidden HTML or use misspelled words and lookalike characters to trick you into missing the signs.
More advanced versions use JavaScript that reveals the payload only after the message has passed through security checks. Others try to confuse AI systems with prompt injection or strange formatting.
These techniques create gaps in protection and give attackers a better chance of reaching your inbox. Spotting them early is key. The more familiar you are with how these tricks work, the easier it is to catch them before they do damage.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Spoofing: Hidden Outlook headers in self-addressed forwards
4h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage with echo-tail od= tracking token
4h ago
Oct 6th, 2026
Sublime Security
Attachment: PDF Link With Valueless Base64 Query Parameter
4h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage with suspicious URL pattern
4h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage with zipper-interleaved tracking token
5h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage with suffixed unsubscribe bucket
5h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage with prefixed base64 dash-record fragment
5h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage with base64 go/sub-ID fragment
5h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage with case-striped tracking token in fragment
5h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage with short-path link delivery
5h ago
Oct 6th, 2026
Sublime Security
Link: Observed URL path (lht) with recipient email address
5h ago
Oct 6th, 2026
Sublime Security
Spamhaus: Mail transiting a DROP listed network
6h ago
Oct 6th, 2026
Sublime Security
Spamhaus: Mail transiting an ASN-DROP listed network
6h ago
Oct 6th, 2026
Sublime Security
Observed IOC: Mail transiting OFAC-sanctioned bulletproof host Aeza Group
6h ago
Oct 6th, 2026
Sublime Security
Observed IOC: Malicious domains in body links
6h ago
Oct 6th, 2026
Sublime Security
Attachment: Fake email body embedded in inline image
1d ago
Oct 5th, 2026
Sublime Security
Observed IOC: Malicious root domains in body links
1d ago
Oct 5th, 2026
Sublime Security
Credential phishing: Generic document sharing
2d ago
Oct 4th, 2026
Sublime Security
Attachment: Microsoft OAuth credential harvesting via EML with embedded malicious links
2d ago
Oct 4th, 2026
Sublime Security
Attachment: ICS with Suspicious Office 365 app authorization (OAuth) link
2d ago
Oct 4th, 2026
Sublime Security