← All detection heuristics · HTML
critical
HTML_THIRD_PARTY_CREDENTIAL_HARVEST
What it means
A branded page submits email credentials to a generic form collector and redirects to a trusted decoy.
Why it fires
The rule requires email and password fields, scripted submission, a third-party collection endpoint, and a trusted-brand decoy redirect.
Other HTML heuristics
HTML_HTA_VBSCRIPT_DOM_EXECUTE HTML_ACTIVEX_OBJECT HTML_WINDOWS_SCRIPTING_OBJECT HTML_VBSCRIPT HTML_CREDENTIAL_PHISH_DYNDNS HTML_SCRIPTED_COM_EXECUTION HTML_SMUGGLED_PAYLOAD HTML_XOR_BASE64_EVAL_INJECTION HTML_LONG_BASE64_SCRIPT_PAYLOAD HTML_OBFUSCATED_STRING_BUILDER HTML_AD_FRAUD_CLOAKING HTML_BASE64_PAYLOAD_URL