Detection Method: Javascript analysis

JavaScript analysis inspects JavaScript code found in email messages, HTML attachments, and linked web pages to identify potential malicious behavior or suspicious patterns. It uses specialized techniques to spot obfuscated scripts, malicious functions, and known attack strategies.
JavaScript analysis can help you detect:
  • Obfuscated code designed to hide malicious intent
  • DOM manipulation attempts that lead to phishing or data theft
  • Event handlers that trigger actions when content is viewed
  • Suspicious API calls like document.write() or eval() that generate malicious content
  • Encoded strings that decode to payloads during runtime
For example, attackers often use obfuscated JavaScript to redirect you to phishing sites or to download malware. JavaScript analysis can uncover these threats even when the code is intentionally hidden.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: ICS with embedded Javascript in SVG file
14d ago
Jan 29th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-ics-with-embedded-javascript-in-svg-file-d5201a19
Attachment: HTML smuggling with atob and high entropy via calendar invite
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-html-smuggling-with-atob-and-high-entropy-via-calendar-invite-94d84614
Attachment: HTML smuggling with unescape
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-html-smuggling-with-unescape-0b0fed36
Attachment: File execution via Javascript
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-file-execution-via-javascript-627ae0b1
Request for Quote or Purchase (RFQ|RFP) with HTML smuggling attachment
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/request-for-quote-or-purchase-rfqorrfp-with-html-smuggling-attachment-a47a5755
Attachment: EML file contains HTML attachment with login portal indicators
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-eml-file-contains-html-attachment-with-login-portal-indicators-6e4df158
Attachment: HTML smuggling with eval and atob via calendar invite
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-html-smuggling-with-eval-and-atob-via-calendar-invite-597c2edd
Low reputation link to auto-downloaded HTML file with smuggling indicators
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/low-reputation-link-to-auto-downloaded-html-file-with-smuggling-indicators-339676c6
Attachment: HTML smuggling with ROT13
1mo ago
Jan 12th, 2026
@Kyle_Parrish_
/feeds/core/detection-rules/attachment-html-smuggling-with-rot13-6eacc4cf
Attachment: HTML attachment with login portal indicators
1mo ago
Jan 12th, 2026
@ajpc500
/feeds/core/detection-rules/attachment-html-attachment-with-login-portal-indicators-3aabf4a7
Attachment: HTML file with reference to recipient and suspicious patterns
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-html-file-with-reference-to-recipient-and-suspicious-patterns-5333493d
Attachment: HTML smuggling with atob and high entropy
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-html-smuggling-with-atob-and-high-entropy-03fcac11
Attachment: HTML smuggling with auto-downloaded file
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-html-smuggling-with-auto-downloaded-file-abf724f5
Attachment: HTML smuggling with eval and atob
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-html-smuggling-with-eval-and-atob-9f521ca2
Attachment: HTML smuggling with base64 encoded JavaScript function
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-html-smuggling-with-base64-encoded-javascript-function-4e8a12ec
Attachment: HTML smuggling with excessive line break obfuscation
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-html-smuggling-with-excessive-line-break-obfuscation-7e901440
Attachment: HTML smuggling Microsoft sign in
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-html-smuggling-microsoft-sign-in-878d6385
Attachment: HTML smuggling with RC4 decryption
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-html-smuggling-with-rc4-decryption-3a46d765
Attachment: HTML smuggling with setTimeout
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-html-smuggling-with-settimeout-4e0b2c32
Link: Multistage landing - JotForm abuse
2mo ago
Dec 1st, 2025
Sublime Security
/feeds/core/detection-rules/link-multistage-landing-jotform-abuse-5b64326f