Tactic or Technique: Scripting

Attackers use scripting languages like JavaScript, VBScript, and PowerShell to run malicious code delivered through phishing emails or compromised websites. These scripts can load hidden content, redirect you to phishing pages, or silently steal data in the background.
To avoid detection, attackers often scramble the code using encryption, compression, or multiple layers of encoding. This makes it harder for both security tools and analysts to understand what the script is doing.
Scripting is flexible and often used to fingerprint your browser, deliver customized payloads, or create a connection to an attacker-controlled server. Once that connection is active, the script can pull down more malware, collect sensitive information, or give an attacker continued access to your device.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: HTML smuggling with atob and high entropy
9d ago
Nov 4th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-html-smuggling-with-atob-and-high-entropy-03fcac11
HTML smuggling containing recipient email address
9d ago
Nov 4th, 2025
Sublime Security
/feeds/core/detection-rules/html-smuggling-containing-recipient-email-address-af32ff2f
Attachment: HTML file with reference to recipient and suspicious patterns
9d ago
Nov 4th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-html-file-with-reference-to-recipient-and-suspicious-patterns-5333493d
Attachment: HTML file with excessive 'const' declarations and abnormally long timeouts
10d ago
Nov 3rd, 2025
Sublime Security
/feeds/core/detection-rules/attachment-html-file-with-excessive-const-declarations-and-abnormally-long-timeouts-66f8a07a
Attachment: Any .sap file (unsolicited)
17d ago
Oct 27th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-any-sap-file-unsolicited-220ed3de
HTML: Bidirectional (BIDI) HTML override with right to left obfuscation
27d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/html-bidirectional-bidi-html-override-with-right-to-left-obfuscation-f93940d2
Attachment: HTML with obfuscation and recipient's email in JavaScript strings
1mo ago
Sep 25th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-html-with-obfuscation-and-recipients-email-in-javascript-strings-1aff486b
Attachment: HTML smuggling with eval and atob via calendar invite
1mo ago
Sep 25th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-html-smuggling-with-eval-and-atob-via-calendar-invite-597c2edd
Suspected cross-site scripting (XSS) found in subject
2mo ago
Sep 4th, 2025
Sublime Security
/feeds/core/detection-rules/suspected-cross-site-scripting-xss-found-in-subject-8a946cfa
Attachment: EML with embedded Javascript in SVG file
3mo ago
Aug 8th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-eml-with-embedded-javascript-in-svg-file-dfafb78f
Attachment: SVG file execution
3mo ago
Aug 8th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-svg-file-execution-084b0cde
Attachment: Embedded Javascript in SVG file
3mo ago
Aug 8th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-embedded-javascript-in-svg-file-f70293bc
Attachment: HTML with emoji-to-character map
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-html-with-emoji-to-character-map-3119d086
Attachment: Office document with VSTO add-in
3mo ago
Aug 5th, 2025
@vector_sec
/feeds/core/detection-rules/attachment-office-document-with-vsto-add-in-27afa730
Attachment: Malicious OneNote commands
3mo ago
Aug 5th, 2025
@Kyle_Parrish_
/feeds/core/detection-rules/attachment-malicious-onenote-commands-7319f0eb
Attachment: HTML attachment with Javascript location
3mo ago
Aug 5th, 2025
@vector_sec
/feeds/core/detection-rules/attachment-html-attachment-with-javascript-location-e0611295
Attachment: HTML with JavaScript functions for HTTP requests
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-html-with-javascript-functions-for-http-requests-01e679fd
Attachment: HTML with hidden body
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-html-with-hidden-body-b059a781
Attachment: Double base64-encoded zip file in HTML smuggling attachment
3mo ago
Aug 5th, 2025
@ajpc500
/feeds/core/detection-rules/attachment-double-base64-encoded-zip-file-in-html-smuggling-attachment-61ebb07b
Attachment: Macro files containing MHT content
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-macro-files-containing-mht-content-4d54e40b