Detection Method: Exif analysis

Exif analysis looks at embedded metadata in files to uncover suspicious details that could indicate malicious activity. By extracting and analyzing Exif data from images, documents, PDFs, and other attachments, this method can help spot hidden threats that would normally go undetected.
Exif analysis can detect:
  • Document timestamps that don’t match the claimed origin
  • Authorship info that conflicts with the sender’s identity
  • Signs of image or document manipulation
  • Suspicious tools used to create the file
  • Geographical data that’s inconsistent with the expected origin
For example, a phishing email claiming to be an invoice might have metadata showing it was created with unauthorized tools, edited recently, or authored by someone outside the company it’s pretending to be from.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: PDF with a suspicious string and single URL
2h ago
Sep 16th, 2026
Sublime Security
Attachment: Legal themed message or PDF with suspicious indicators
1d ago
Sep 15th, 2026
Sublime Security
Attachment: Excel file with hyperlinks to suspicious domains
5d ago
Sep 11th, 2026
Sublime Security
Attachment: Encrypted PDF with credential theft body
12d ago
Sep 4th, 2026
Sublime Security
Attachment: Encrypted PDF with credential theft language in EML
12d ago
Sep 4th, 2026
Sublime Security
Attachment: PDF credential phishing via wkhtmltopdf/Qt with suspicious link
14d ago
Sep 2nd, 2026
Sublime Security
Link: Credential harvesting with excess padding evasion
19d ago
Aug 28th, 2026
Sublime Security
Attachment: Invoice and W-9 PDFs with suspicious creators
22d ago
Aug 25th, 2026
Sublime Security
Attachment: PDF with suspicious HeadlessChrome metadata
23d ago
Aug 24th, 2026
Sublime Security
Brand impersonation: Microsoft logo image linking to free file host
26d ago
Aug 21st, 2026
Sublime Security
Attachment: Fictitious invoice using LinkedIn's address
1mo ago
Jul 29th, 2026
Sublime Security
Attachment: Callback phishing solicitation via pdf file
1mo ago
Jul 27th, 2026
Sublime Security
Attachment: Single-page PDF with S3-hosted HTML link
2mo ago
Jul 16th, 2026
Sublime Security
Attachment: Suspicious PDF created with headless browser
2mo ago
Jul 1st, 2026
Sublime Security
Attachment: PDF with localhost IP in EXIF title metadata
2mo ago
Jun 29th, 2026
Sublime Security
Attachment: JPEG with gd-jpeg creator and suspicious file name
3mo ago
Jun 12th, 2026
Sublime Security
Attachment: MS OOXML file created by Administrator with zero edit time
3mo ago
Jun 12th, 2026
Sublime Security
Attachment: PDF with self-service platform links with self sender or blank recipients
3mo ago
Jun 10th, 2026
Sublime Security
Attachment: Canva PDF with susupicious author metadata
3mo ago
Jun 5th, 2026
Sublime Security
Attachment: PDF Attachment with links to workers.dev
3mo ago
Jun 4th, 2026
Sublime Security