Detection Method: File analysis

File analysis breaks down and inspects file contents, formats, and embedded elements to uncover hidden threats. This method goes beyond basic file attributes, deeply examining the inner structure of files to find potentially malicious content that looks legitimate on the surface.
File analysis helps detect:
  • Malicious macros in Office documents (Word, Excel, PowerPoint)
  • Obfuscated scripts hidden in PDFs or other document types
  • Executable code disguised in non-executable files
  • Hidden text content using encoding or steganography
  • Suspicious metadata or file properties suggesting tampering
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Extortion / sextortion in attachment from untrusted sender
22h ago
Aug 6th, 2026
Sublime Security
Callback phishing in body or attachment (untrusted sender)
2d ago
Aug 5th, 2026
Sublime Security
Attachment: Callback phishing solicitation via text-based file
2d ago
Aug 5th, 2026
Sublime Security
Attachment: Targeted DOCX with personalized recipient acknowledgement lure
3d ago
Aug 4th, 2026
Sublime Security
Brand impersonation: Sharepoint
4d ago
Aug 3rd, 2026
Sublime Security
Low reputation link to auto-downloaded HTML file with smuggling indicators
9d ago
Jul 29th, 2026
Sublime Security
Link: QuickBooks image lure with suspicious link
9d ago
Jul 29th, 2026
Sublime Security
Attachment: Encrypted PDF with credential theft body
9d ago
Jul 29th, 2026
Sublime Security
Attachment: EML with Sharepoint link likely unrelated to sender
9d ago
Jul 29th, 2026
Sublime Security
Attachment: Fictitious invoice using LinkedIn's address
9d ago
Jul 29th, 2026
Sublime Security
Brand impersonation: Microsoft fake sign-in alert
11d ago
Jul 27th, 2026
Sublime Security
Attachment: Callback phishing solicitation via pdf file
11d ago
Jul 27th, 2026
Sublime Security
Attachment: Microsoft 365 credential phishing
11d ago
Jul 27th, 2026
Sublime Security
Attachment: EML with link to credential phishing page
11d ago
Jul 27th, 2026
Sublime Security
Attachment: ICS calendar file with suspicious product identifier
11d ago
Jul 27th, 2026
Sublime Security
Brand Impersonation: PayPal
21d ago
Jul 17th, 2026
Sublime Security
Attachment: PDF with secure document acknowledgment prompt
21d ago
Jul 17th, 2026
Sublime Security
Attachment: ICS file with AWS Lambda URL
22d ago
Jul 16th, 2026
Sublime Security
Attachment: Microsoft SharePoint Impersonation via images in macro-enabled attachment
22d ago
Jul 16th, 2026
Sublime Security
Attachment: Single-page PDF with S3-hosted HTML link
22d ago
Jul 16th, 2026
Sublime Security