Detection Method: File analysis

File analysis breaks down and inspects file contents, formats, and embedded elements to uncover hidden threats. This method goes beyond basic file attributes, deeply examining the inner structure of files to find potentially malicious content that looks legitimate on the surface.
File analysis helps detect:
  • Malicious macros in Office documents (Word, Excel, PowerPoint)
  • Obfuscated scripts hidden in PDFs or other document types
  • Executable code disguised in non-executable files
  • Hidden text content using encoding or steganography
  • Suspicious metadata or file properties suggesting tampering
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: SVG files with evasion elements
4d ago
May 8th, 2026
Sublime Security
Attachment: Suspicious PDF created with headless browser
5d ago
May 7th, 2026
Sublime Security
Brand Impersonation: PayPal
5d ago
May 7th, 2026
Sublime Security
Callback phishing via calendar invite
6d ago
May 6th, 2026
Sublime Security
Callback phishing via Google Group abuse
8d ago
May 4th, 2026
Sublime Security
Callback phishing: AOL senders with suspicious HTML template or PDF attachment
8d ago
May 4th, 2026
Sublime Security
Brand impersonation: SharePoint PDF attachment with credential theft language
8d ago
May 4th, 2026
Sublime Security
Brand impersonation: Sharepoint
8d ago
May 4th, 2026
Sublime Security
Attachment: PDF with suspicious HeadlessChrome metadata
11d ago
May 1st, 2026
Sublime Security
Attachment with unscannable encrypted zip
12d ago
Apr 30th, 2026
Sublime Security
Attachment: QR code with userinfo portion
12d ago
Apr 30th, 2026
Sublime Security
Attachment: Fake voicemail via PDF
12d ago
Apr 30th, 2026
Sublime Security
Adobe branded PDF file linking to a password-protected file from untrusted sender
13d ago
Apr 29th, 2026
Sublime Security
Attachment: Decoy PDF author (Julie P.)
13d ago
Apr 29th, 2026
Sublime Security
Attachment: QR code link with base64-encoded recipient address
13d ago
Apr 29th, 2026
Sublime Security
MalwareBazaar: Malicious attachment hash in archive (trusted reporters)
13d ago
Apr 29th, 2026
Sublime Security
Attachment: Link to Doubleclick.net open redirect
13d ago
Apr 29th, 2026
Sublime Security
Attachment: ICS file with AWS Lambda URL
14d ago
Apr 28th, 2026
Sublime Security
Non-RFC compliant calendar files from unsolicited sender
14d ago
Apr 28th, 2026
Sublime Security
Attachment: ICS with embedded document
14d ago
Apr 28th, 2026
Sublime Security