logo

[Test] Community Spotlight: Email Detection Rules built by the Sublime Community · Blog · Sublime Security

ID: 7d7bffce-c265-52f1-a60d-0bce9c25947e

STIX ID: report--7d7bffce-c265-52f1-a60d-0bce9c25947e

Feed Name: Sublime Security Blog

Threat Score
50/100

Date Published: 2026-03-18

Date Updated: 2026-05-01

...
...

This Sublime blog post highlights community-contributed email detection rules added to its Core Feed, detailing three detection use-cases: detecting Office documents with embedded malicious VSTO add-ins, identifying double Base64-encoded ZIP files smuggled in HTML attachments (used by QakBot), and spotting ROT13-based JavaScript obfuscation in HTML smuggling. The article explains the rule logic and how the community can share and iterate on rules to improve email security.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.