Detection Method: HTML analysis

HTML analysis looks at the HTML code in emails, web pages, or attachments to spot potentially malicious elements or deceptive structures. It examines both what’s visible and hidden in the HTML to uncover tactics often used in phishing or malware attacks.
HTML analysis can help you detect:
  • Hidden scripts or iframes that might run harmful code
  • Obfuscated JavaScript designed to avoid detection
  • Misleading hyperlinks where the displayed text doesn’t match the real URL
  • Forms made to steal credentials or sensitive data
  • Suspicious HTML comments with hidden instructions
  • CSS tricks used to hide malicious content
For example, phishing emails often use HTML to replicate trusted login pages. HTML analysis can catch the hidden forms and scripts trying to steal your credentials.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Spoofing: Hidden Outlook headers in self-addressed forwards
4h ago
Oct 6th, 2026
Sublime Security
Service abuse: Lovable-hosted redirect to external phishing page
6h ago
Oct 6th, 2026
Sublime Security
Attachment: Fake email body embedded in inline image
1d ago
Oct 5th, 2026
Sublime Security
Attachment: Suspicious use of Unicode tag characters in ICS File
2d ago
Oct 4th, 2026
Sublime Security
Evasion: Suspicious use of Unicode tag characters
2d ago
Oct 4th, 2026
Sublime Security
Body: Bid solicitation PDF lure
4d ago
Oct 2nd, 2026
Sublime Security
Service abuse: Self-service platform redirecting to newly registered suspicious domain
5d ago
Oct 1st, 2026
Sublime Security
Attachment: HTML smuggling with dynamically constructed redirect URL
7d ago
Sep 29th, 2026
Sublime Security
Credential phishing: Suspicious e-sign agreement document notification
8d ago
Sep 28th, 2026
Sublime Security
Brand impersonation: Microsoft logo in HTML with fake quarantine release notification
8d ago
Sep 28th, 2026
Sublime Security
Brand impersonation: Fake DocuSign HTML table not linking to DocuSign domains
8d ago
Sep 28th, 2026
Sublime Security
Link: Credential phishing with visit-tracking script
11d ago
Sep 25th, 2026
Sublime Security
Sharepoint link likely unrelated to sender
13d ago
Sep 23rd, 2026
Sublime Security
Link: Common hidden directory observed
13d ago
Sep 23rd, 2026
Sublime Security
Brand impersonation: Microsoft Teams invitation
13d ago
Sep 23rd, 2026
Sublime Security
Attachment: HTML smuggling with atob and high entropy via calendar invite
13d ago
Sep 23rd, 2026
Sublime Security
Attachment: HTML smuggling with atob and high entropy
13d ago
Sep 23rd, 2026
Sublime Security
Potential prompt injection attack in body HTML
13d ago
Sep 23rd, 2026
Sublime Security
Image as content with a link to an open redirect
13d ago
Sep 23rd, 2026
Sublime Security
Link: Multistage landing - Scribd document
13d ago
Sep 23rd, 2026
Sublime Security