Tactic or Technique: Scripting

Attackers use scripting languages like JavaScript, VBScript, and PowerShell to run malicious code delivered through phishing emails or compromised websites. These scripts can load hidden content, redirect you to phishing pages, or silently steal data in the background.
To avoid detection, attackers often scramble the code using encryption, compression, or multiple layers of encoding. This makes it harder for both security tools and analysts to understand what the script is doing.
Scripting is flexible and often used to fingerprint your browser, deliver customized payloads, or create a connection to an attacker-controlled server. Once that connection is active, the script can pull down more malware, collect sensitive information, or give an attacker continued access to your device.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: HTML smuggling with dynamically constructed redirect URL
7d ago
Sep 29th, 2026
Sublime Security
Attachment: Embedded Javascript in SVG file
8d ago
Sep 28th, 2026
Sublime Security
Attachment: ICS calendar with suspicious link Leading to minimal JS landing page
8d ago
Sep 28th, 2026
Sublime Security
Suspected cross-site scripting (XSS) found in subject
8d ago
Sep 28th, 2026
Sublime Security
Mass campaign: Cross Site Scripting (XSS) attempt
8d ago
Sep 28th, 2026
Sublime Security
Link: Credential phishing with visit-tracking script
11d ago
Sep 25th, 2026
Sublime Security
Attachment: HTML smuggling with decimal encoding
13d ago
Sep 23rd, 2026
Sublime Security
Attachment: HTML with hidden body
13d ago
Sep 23rd, 2026
Sublime Security
Attachment: HTML attachment with login portal indicators
13d ago
Sep 23rd, 2026
@ajpc500
Attachment: HTML with emoji-to-character map
13d ago
Sep 23rd, 2026
Sublime Security
Attachment: HTML with JavaScript functions for HTTP requests
13d ago
Sep 23rd, 2026
Sublime Security
Attachment: Microsoft impersonation via PDF with link and suspicious language
13d ago
Sep 23rd, 2026
Sublime Security
Attachment: Any .sap file (unsolicited)
13d ago
Sep 23rd, 2026
Sublime Security
Attachment: HTML smuggling with atob and high entropy via calendar invite
13d ago
Sep 23rd, 2026
Sublime Security
Attachment: HTML smuggling with atob and high entropy
13d ago
Sep 23rd, 2026
Sublime Security
Link: Suspicious TLD hosting client.js with cf beacon
25d ago
Sep 11th, 2026
Sublime Security
Body: CVE-2026-42897 Exchange OWA stored XSS
27d ago
Sep 9th, 2026
Sublime Security
HTML: Bidirectional (BIDI) HTML override with right to left obfuscation
1mo ago
Aug 31st, 2026
Sublime Security
ClickFix: Clipboard hijack lure with copy-paste-to-terminal instruction
1mo ago
Aug 26th, 2026
Sublime Security
Link: Credential phishing with obfuscated JavaScript redirect
1mo ago
Aug 21st, 2026
Sublime Security