Description

Catches messages with almost no visible body text and a single link, where an inline image doubles as both the message body and the link destination. The image is OCR'd and the extracted text is run through an NLU classifier to confirm credential-theft intent, matching lures such as fake voicemail transcripts, document-sharing notifications, and workflow addendum requests. Highly trusted sender domains that pass DMARC are excluded to reduce false positives.

References

No references.

Sublime Security
Created Sep 25th, 2026 • Last updated Oct 5th, 2026
Source
type.inbound
and regex.icount(coalesce(body.current_thread.text, ""), '[a-z0-9]') < 15
and length(body.current_thread.links) == 1
and length(filter(attachments,
                  .content_disposition == "inline"
                  and .file_type in $file_types_images
                  and beta.ocr(.).success
                  and regex.icount(beta.ocr(.).text, '[a-zA-Z]{2,}') >= 20
           )
) == 1
and any(attachments,
        any(html.xpath(body.html, '//a[not(text())]//img/@src').nodes,
            strings.iends_with(.raw, ..content_id)
        )
        and beta.ocr(.).success
        and regex.icount(beta.ocr(.).text, '[a-zA-Z]{2,}') >= 20
        and any(ml.nlu_classifier(beta.ocr(.).text).intents,
                .name == "cred_theft"
        )
)
and any(body.current_thread.links,
        .href_url.domain.root_domain != sender.email.domain.root_domain
)
and not (
  sender.email.domain.root_domain in $high_trust_sender_root_domains
  and coalesce(headers.auth_summary.dmarc.pass, false)
)
MQL Rule Console
•Docs•Learning Labs

Playground

Test against your own EMLs or sample data.

Share

Post about this on your socials.

Get Started. Today.

Managed or self-managed. No MX changes.

Deploy and integrate a free Sublime instance in minutes.
Get Started