Detection Method: HTML analysis

HTML analysis looks at the HTML code in emails, web pages, or attachments to spot potentially malicious elements or deceptive structures. It examines both what’s visible and hidden in the HTML to uncover tactics often used in phishing or malware attacks.
HTML analysis can help you detect:
  • Hidden scripts or iframes that might run harmful code
  • Obfuscated JavaScript designed to avoid detection
  • Misleading hyperlinks where the displayed text doesn’t match the real URL
  • Forms made to steal credentials or sensitive data
  • Suspicious HTML comments with hidden instructions
  • CSS tricks used to hide malicious content
For example, phishing emails often use HTML to replicate trusted login pages. HTML analysis can catch the hidden forms and scripts trying to steal your credentials.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Link: Fake Cloudflare verification landing page
5d ago
Sep 11th, 2026
Sublime Security
Impersonation: SAM/SBA federal registration
5d ago
Sep 11th, 2026
Sublime Security
Service abuse: Self-service platform redirecting to newly registered suspicious domain
6d ago
Sep 10th, 2026
Sublime Security
Link: Fake webmail hosting
7d ago
Sep 9th, 2026
Sublime Security
Body: CVE-2026-42897 Exchange OWA stored XSS
7d ago
Sep 9th, 2026
Sublime Security
Attachment: PDF with bolded passcode
8d ago
Sep 8th, 2026
Sublime Security
Attachment: Word document with hyperlink and fraud language
12d ago
Sep 4th, 2026
Sublime Security
Credential phishing: Suspicious e-sign agreement document notification
12d ago
Sep 4th, 2026
Sublime Security
Attachment: Gzip-archived with nested HTML file containing image and button link
13d ago
Sep 3rd, 2026
Sublime Security
Body: CSS Hidden text via table-column
13d ago
Sep 3rd, 2026
Sublime Security
Link: Gmail phishkit with suspicious recipient
14d ago
Sep 2nd, 2026
Sublime Security
Attachment: GZ archive with credential theft content
14d ago
Sep 2nd, 2026
Sublime Security
Body: CSS clamp() font obfuscation
15d ago
Sep 1st, 2026
Sublime Security
Body HTML: Comment with 24-character hex token
15d ago
Sep 1st, 2026
Sublime Security
Evasion: Hidden text using CSS-obscured HTML option labels
15d ago
Sep 1st, 2026
Sublime Security
Brand impersonation: Paperless Post
16d ago
Aug 31st, 2026
Sublime Security
Service abuse: EventCreate links to newly registered domains
16d ago
Aug 31st, 2026
Sublime Security
HTML: Bidirectional (BIDI) HTML override with right to left obfuscation
16d ago
Aug 31st, 2026
Sublime Security
Link: Credential harvesting with excess padding evasion
19d ago
Aug 28th, 2026
Sublime Security
Body: HTML whitespace stuffing with short initial message
19d ago
Aug 28th, 2026
Sublime Security