
Eine Heimat für Erkennungsinhalte, entwickelt vom delivr.to-Team.
Dieses Repository beherbergt Erkennungsinhalte, die vom delivr.to-Team entwickelt wurden.
Alle in diesem Repository vorhandenen Regeln verfügen über entsprechende Payloads (in den Referenzen verlinkt und unten aufgeführt), mit denen die Erkennungsinhalte getestet werden können.
Das Repository enthält derzeit die folgenden Arten von Erkennungen:
Nachfolgend finden Sie die Liste der Regeln für Sublime Security, aufgeteilt in die spezifischen Ordner General und Threat Intel.
Sie können delivr.to auch direkt in Sublime integrieren, wie hier erwähnt und hier dokumentiert.

| Regelname | Typ | Payload |
|---|---|---|
| Attachment: Archive with Directory Traversal CVE-2025-6218 (Unsolicited) | Threat Intel | ![]() |
| Attachment: Nested 7-Zip Archives CVE-2025-0411 (Unsolicited) | Threat Intel | ![]() |
| Attachment: RTF with Embedded OLE Object (Unsolicited) | Threat Intel | ![]() |
| Body: Img Element Exploiting CVE-2024-38021 (Unsolicited) | Threat Intel | ![]() |
| Link: PIF File from Suspicious Source (AgentTesla) | Threat Intel | ![]() |
Nachfolgend finden Sie die Liste der Yara-Regeln im Repository.
Nachfolgend finden Sie die Liste der Sigma-Regeln im Repository.
| Regelname | Typ | Payload |
|---|---|---|
| PDF HTML Smuggling | Threat Intel | ![]() |
| Attachment: HTML with search-ms URI protocol handler (DarkGate) |
| Threat Intel |
![]() |
| Attachment: HTML with Meta Tag Refresh and File Protocol Handler (Pikabot) | Threat Intel | ![]() |
| Attachment: PDF Link with Microsoft OneDrive Branding (Pikabot) | Threat Intel | ![]() |
| Attachment: ZIP Containing LNK Minimized One-Liner (Unsolicited) | Threat Intel | ![]() |
| Attachment: HTML Smuggling of Zip File with Evasion Indicators (Unsolicited) | Threat Intel | ![]() |
| Attachment: PDF with embedded MHT using ActiveMime objects (Unsolicited) | Threat Intel | ![]() |
| Attachment: Zip Exploiting CVE-2023-38831 (Unsolicited) | Threat Intel | ![]() |
| Attachment: PDF with Auto-Open Embedded Smuggling File | Threat Intel | ![]() |
| Attachment: OneNote file with Suspicious Strings | Threat Intel | ![]() |
| Link: Zipped OneNote file with Document Download Lure (QakBot) | Threat Intel | ![]() |
| Attachment: OneNote containing HTA with VBScript and JavaScript content (QakBot) | Threat Intel | ![]() |
| Attachment: WSF File With Certificate Content (QakBot) | Threat Intel | ![]() |
| Attachment: PDF with Document Download Lure | Threat Intel | ![]() |
| Attachment: PDF with Embedded Google Firebase Storage Link (Bumblebee) | Threat Intel | ![]() |
| Attachment: Office Document with Embedded RTF Referencing Remote Resources CVE-2023-36884 (Unsolicited) | Threat Intel |
| Attachment: HTML with Clipboard Copy | Threat Intel | ![]() |
| Attachment: FileJacking Indicators (Unsolicited) | General | ![]() |
| Link: FileJacking Indicators (Unsolicited) | General | ![]() |
| Attachment: HTML smuggling with Google Web Toolkit (GWT) | General | ![]() |
| Attachment: HTML smuggling with WebAssembly (Wasm) | General | ![]() |
| Attachment: ZPAQ Archive (Unsolicited) | General | ![]() |
| Attachment: Microsoft-branded HTML File (Unsolicited) | General | ![]() |
| Attachment: HTML file without HTML element (Unsolicited) | General | ![]() |
| Attachment: SVG file with Onerror or Onload (Unsolicited) | General | ![]() |
| Attachment: SVG file with Script Tags (Unsolicited) | General | ![]() |
| Attachment: HTML file with eval function and long byte string (Unsolicited) | General | ![]() |
| Attachment: HTML File Containing Recipient Email Address (Unsolicited) | General | ![]() |
| Attachment: Extended HTML File Format (Unsolicited) | General | ![]() |
| Attachment: Microsoft Script Encoding Content | General | ![]() |
| Link: Zipped OneNote file | General | ![]() |
| Link: OneNote file | General | ![]() |
| Link: Brand Impersonation Phishing Site | General | ![]() |
| Link: Zipped Script File (Unsolicited) | General | ![]() |
| Attachment: Remote Template Injection | General | ![]() |
| Attachment: HTML Smuggling with msSaveOrOpenBlob | General | ![]() |
| Attachment: AutoIt Script File (Unsolicited) | General | ![]() |
| Attachment: Microsoft Word SMB-hosted Remote Template Injection | General | ![]() |
| Attachment: Office Stylesheet Scripting | General | ![]() |
| Regelname | Typ | Payload |
|---|
| SUSP_archive_CVE_2025_6218_Jul25 | Threat Intel | ![]() |
| SUSP_ZIP_Smuggling_Jun01 | General | ![]() |
| SUSP_ZIP_Smuggling_Egg_Jun01 | General | ![]() |
| SUSP_HTML_WASM_Smuggling | General | ![]() |
| SUSP_HTML_B64_WASM_Blob | General | ![]() |
| SUSP_ZPAQ_Archive_Nov23 | General | ![]() |
| SUSP_PDF_MHT_ActiveMime_Sept23 | General | ![]() |
| SUSP_SVG_Onload_Onerror_Jul23 | General | ![]() |
| SUSP_OneNote_Repeated_FileDataReference_Feb23 | Threat Intel | ![]() |
| SUSP_OneNote_RTLO_Character_Feb23 | Threat Intel | ![]() |
| SUSP_OneNote_Win_Script_Encoding_Feb23 | Threat Intel | ![]() |
| SUSP_msg_CVE_2023_23397_Mar23 | Threat Intel | ![]() |
| SUSP_CONCAT_ZIP_Nov24 | Threat Intel | ![]() |
| SUSP_SVG_ForeignObject_Nov24 | Threat Intel | ![]() |