Detection Method: HTML analysis

HTML analysis looks at the HTML code in emails, web pages, or attachments to spot potentially malicious elements or deceptive structures. It examines both what’s visible and hidden in the HTML to uncover tactics often used in phishing or malware attacks.
HTML analysis can help you detect:
  • Hidden scripts or iframes that might run harmful code
  • Obfuscated JavaScript designed to avoid detection
  • Misleading hyperlinks where the displayed text doesn’t match the real URL
  • Forms made to steal credentials or sensitive data
  • Suspicious HTML comments with hidden instructions
  • CSS tricks used to hide malicious content
For example, phishing emails often use HTML to replicate trusted login pages. HTML analysis can catch the hidden forms and scripts trying to steal your credentials.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Impersonation: SAM/SBA federal registration
18m ago
Aug 27th, 2026
Sublime Security
Body: HTML whitespace stuffing with short initial message
2h ago
Aug 27th, 2026
Sublime Security
Body: CSS clamp() font obfuscation with suspicious URL
20h ago
Aug 26th, 2026
Sublime Security
Attachment: Risk assessment PDF with inline image
2d ago
Aug 25th, 2026
Sublime Security
Link: Credential harvesting with excess padding evasion
2d ago
Aug 25th, 2026
Sublime Security
Body: AI-generated invoice template artifacts
5d ago
Aug 22nd, 2026
Sublime Security
Brand impersonation: Microsoft logo image linking to free file host
6d ago
Aug 21st, 2026
Sublime Security
Link: RTL text reversal with recipient email in URL
7d ago
Aug 20th, 2026
Sublime Security
Link: Mismatched Shopify template button href
7d ago
Aug 20th, 2026
Sublime Security
Brand impersonation: Aramco
7d ago
Aug 20th, 2026
Sublime Security
Brand impersonation: Greetings Island
9d ago
Aug 18th, 2026
Sublime Security
Service abuse: Soundestlink.com Microsoft impersonation
10d ago
Aug 17th, 2026
Sublime Security
Attachment: RTF with link to free-hosted Cloudflare Pages
14d ago
Aug 13th, 2026
Sublime Security
Link: URL fragmented by hidden spans
14d ago
Aug 13th, 2026
Sublime Security
Service abuse: Soundestlink redirect with suspicious indicators
16d ago
Aug 11th, 2026
Sublime Security
Callback phishing: Zero-width character obfuscation from freemail sender
22d ago
Aug 5th, 2026
Sublime Security
Body: CSS Hidden text via clip-path
22d ago
Aug 5th, 2026
Sublime Security
Body: CSS zero-value calc() obfuscation
22d ago
Aug 5th, 2026
Sublime Security
Service abuse: Wufoo credential theft
22d ago
Aug 5th, 2026
Sublime Security
HTML: Template placeholders or recipient email in element class attributes
22d ago
Aug 5th, 2026
Sublime Security