Detection Method: Computer Vision

Computer Vision uses image recognition to analyze visual elements in messages, attachments, and web content to detect threats or impersonation attempts. It examines logos, screenshots, and HTML to find signs of phishing or fraud.
Computer Vision can detect:
  • Brand impersonation with fake logos (e.g., Microsoft, PayPal)
  • Visual elements of phishing pages, like login forms
  • CAPTCHAs used to bypass security systems
  • Malicious content disguised as legitimate visuals
For example, attackers often create fake login pages mimicking trusted brands, and Computer Vision can detect these attempts by recognizing misused logos with high confidence.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Link: Figma design deck with credential theft language
12h ago
Mar 4th, 2026
Sublime Security
/feeds/core/detection-rules/link-figma-design-deck-with-credential-theft-language-87601924
Brand Impersonation: Disney
16h ago
Mar 4th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-disney-bf90b8fb
Attachment: QR code with recipient targeting and special characters
12d ago
Feb 21st, 2026
Sublime Security
/feeds/core/detection-rules/attachment-qr-code-with-recipient-targeting-and-special-characters-fc9e1c09
Cloud storage impersonation with credential theft indicators
13d ago
Feb 20th, 2026
Sublime Security
/feeds/core/detection-rules/cloud-storage-impersonation-with-credential-theft-indicators-4c20f72c
Brand impersonation: Gusto
15d ago
Feb 18th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-gusto-54025c1c
Impersonation: Recipient organization in sender display name with credential theft image
16d ago
Feb 17th, 2026
Sublime Security
/feeds/core/detection-rules/impersonation-recipient-organization-in-sender-display-name-with-credential-theft-image-6abfb20e
Brand Impersonation: PayPal
20d ago
Feb 13th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-paypal-a6b2ceee
Brand impersonation: USPS
20d ago
Feb 13th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-usps-28b9130a
Brand impersonation: TikTok
21d ago
Feb 12th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-tiktok-aaacc8b7
Callback Phishing via Zoom comment
22d ago
Feb 11th, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-zoom-comment-8ec30881
Brand impersonation: Fake Fax
28d ago
Feb 5th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-fake-fax-2a96b90a
Brand impersonation: File sharing notification with template artifacts
1mo ago
Jan 23rd, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-file-sharing-notification-with-template-artifacts-37d89611
Brand impersonation: Quickbooks
1mo ago
Jan 15th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-quickbooks-4fd791d1
Callback phishing via e-signature service
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-e-signature-service-ed37b4fd
Attachment: QR code with credential phishing indicators
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-qr-code-with-credential-phishing-indicators-9f1681e1
QR Code with suspicious indicators
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/qr-code-with-suspicious-indicators-04f5c34f
Suspicious invoice reference with missing or image-only attachments
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/suspicious-invoice-reference-with-missing-or-image-only-attachments-466c1680
Credential phishing: DocuSign embedded image lure with no DocuSign domains in links
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/credential-phishing-docusign-embedded-image-lure-with-no-docusign-domains-in-links-dfe8715e
Callback phishing via Adobe Sign comment
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-adobe-sign-comment-7eb4516d
Attachment: HTML smuggling - QR Code with suspicious links
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-html-smuggling-qr-code-with-suspicious-links-010e757d