Using AI signals within malicious email for attack detection and threat hunting · Blog · Sublime Security
ID: 3f4402ab-7864-5c21-87a3-b7c7f3154d93
STIX ID: report--3f4402ab-7864-5c21-87a3-b7c7f3154d93
Feed Name: Sublime Security Blog
This blog evaluates how GenAI/LLM artifacts can be used to augment detection and threat hunting for email-based credential-phishing campaigns: it documents Microsoft’s discovery of an LLM-generated, SVG-obfuscated phishing campaign, enumerates recurring AI-origin signals in HTML emails (comments, formatting quirks, placeholders, naming patterns, yellow highlights), discusses their ephemeral nature, and provides MQL examples to hunt for these signals while stressing they should be used as contributing—not sole—detection indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
