Detection Method: File analysis

File analysis breaks down and inspects file contents, formats, and embedded elements to uncover hidden threats. This method goes beyond basic file attributes, deeply examining the inner structure of files to find potentially malicious content that looks legitimate on the surface.
File analysis helps detect:
  • Malicious macros in Office documents (Word, Excel, PowerPoint)
  • Obfuscated scripts hidden in PDFs or other document types
  • Executable code disguised in non-executable files
  • Hidden text content using encoding or steganography
  • Suspicious metadata or file properties suggesting tampering
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: PDF Link With Valueless Base64 Query Parameter
4h ago
Oct 6th, 2026
Sublime Security
Attachment: Excel file with hyperlinks to suspicious domains
6h ago
Oct 6th, 2026
Sublime Security
Attachment: PDF teal SharePoint lure
1d ago
Oct 5th, 2026
Sublime Security
Attachment: Microsoft OAuth credential harvesting via EML with embedded malicious links
2d ago
Oct 4th, 2026
Sublime Security
Attachment: ICS with Suspicious Office 365 app authorization (OAuth) link
2d ago
Oct 4th, 2026
Sublime Security
Attachment: Fictitious invoice using LinkedIn's address
5d ago
Oct 1st, 2026
Sublime Security
Attachment: PDF with specific blurred lure
5d ago
Oct 1st, 2026
Sublime Security
Attachment: PDF including a Microsoft lure with specific signature
5d ago
Oct 1st, 2026
Sublime Security
Attachment: PDF Object Hash - Generic MSFT lure
5d ago
Oct 1st, 2026
Sublime Security
Attachment: PDF credential phishing via wkhtmltopdf/Qt with suspicious link
5d ago
Oct 1st, 2026
Sublime Security
Brand Impersonation: PayPal
5d ago
Oct 1st, 2026
Sublime Security
Service abuse: Monday.com infrastructure with phishing intent
6d ago
Sep 30th, 2026
Sublime Security
Attachment: ICS calendar file with suspicious UID domain
7d ago
Sep 29th, 2026
Sublime Security
Attachment: RFC822 containing suspicious file sharing language with links from untrusted sender
7d ago
Sep 29th, 2026
Sublime Security
Attachment: HTML smuggling with dynamically constructed redirect URL
7d ago
Sep 29th, 2026
Sublime Security
Attachment: Mobileconfig profile with mismatched embedded email
7d ago
Sep 29th, 2026
Sublime Security
Attachment: Malformed mobileconfig file
7d ago
Sep 29th, 2026
Sublime Security
Attachment: Malicious mobileconfig profile
7d ago
Sep 29th, 2026
Sublime Security
Attachment: Oversized guest-list calendar invite with purchase order lure
8d ago
Sep 28th, 2026
Sublime Security
Attachment: ICS calendar invite with BEC intent
8d ago
Sep 28th, 2026
Sublime Security