logo

Community Spotlight: Email Detection Rules built by the Sublime Community · Blog · Sublime Security

ID: 89777e67-1c77-5fac-8719-583274bc3d8f

STIX ID: report--89777e67-1c77-5fac-8719-583274bc3d8f

Feed Name: Sublime Security Blog

Date Published: 2026-01-08

Date Updated: 2026-05-01

...
...

A Sublime Security blog post highlighting community-contributed Message Query Language (MQL) detection rules for email threats, including rules to detect embedded VSTO add-ins, double Base64-encoded ZIP files used in HTML smuggling, and ROT13-based obfuscation in HTML/JavaScript; the post explains how rules are shared, reviewed, and added to the Core Feed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.