Suspicious file delivery via HTML smuggling

Detects suspicious file delivery via HTML smuggling, a phishing technique where malicious payloads are embedded inside HTML files and reconstructed on the victim system using browser-side JavaScript. Adversaries abuse spearphishing attachments for initial access while bypassing traditional email and network-based security controls.

Back to all rules