logo

Using AI signals within malicious email for attack detection and threat hunting · Blog · Sublime Security

ID: 3f4402ab-7864-5c21-87a3-b7c7f3154d93

STIX ID: report--3f4402ab-7864-5c21-87a3-b7c7f3154d93

Feed Name: Sublime Security Blog

Threat Score
45/100

Date Published: 2026-05-18

Date Updated: 2026-07-22

...
...

This blog evaluates how GenAI/LLM artifacts can be used to augment detection and threat hunting for email-based credential-phishing campaigns: it documents Microsoft’s discovery of an LLM-generated, SVG-obfuscated phishing campaign, enumerates recurring AI-origin signals in HTML emails (comments, formatting quirks, placeholders, naming patterns, yellow highlights), discusses their ephemeral nature, and provides MQL examples to hunt for these signals while stressing they should be used as contributing—not sole—detection indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.