Detection Method: Computer Vision

Computer Vision uses image recognition to analyze visual elements in messages, attachments, and web content to detect threats or impersonation attempts. It examines logos, screenshots, and HTML to find signs of phishing or fraud.
Computer Vision can detect:
  • Brand impersonation with fake logos (e.g., Microsoft, PayPal)
  • Visual elements of phishing pages, like login forms
  • CAPTCHAs used to bypass security systems
  • Malicious content disguised as legitimate visuals
For example, attackers often create fake login pages mimicking trusted brands, and Computer Vision can detect these attempts by recognizing misused logos with high confidence.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Service abuse: Formester with suspicious link behavior
14d ago
Dec 19th, 2025
Sublime Security
/feeds/core/detection-rules/service-abuse-formester-with-suspicious-link-behavior-e4b74fd4
Brand impersonation: Google Drive fake file share
14d ago
Dec 19th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-google-drive-fake-file-share-b424a941
Credential phishing content and link (untrusted sender)
16d ago
Dec 17th, 2025
Sublime Security
/feeds/core/detection-rules/credential-phishing-content-and-link-untrusted-sender-f0c95bb7
Attachment: Adobe image lure in body or attachment with suspicious link
21d ago
Dec 12th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-adobe-image-lure-in-body-or-attachment-with-suspicious-link-1d7add81
QR Code with suspicious indicators
21d ago
Dec 12th, 2025
Sublime Security
/feeds/core/detection-rules/qr-code-with-suspicious-indicators-04f5c34f
Brand impersonation: Sharepoint fake file share
23d ago
Dec 10th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-sharepoint-fake-file-share-ff8b296b
Brand impersonation: Microsoft with low reputation links
23d ago
Dec 10th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-microsoft-with-low-reputation-links-b59201b6
Link: HR impersonation with suspicious domain indicators and credential theft
30d ago
Dec 3rd, 2025
Sublime Security
/feeds/core/detection-rules/link-hr-impersonation-with-suspicious-domain-indicators-and-credential-theft-f31f8831
Link: QR code in EML attachment with credential phishing indicators
1mo ago
Dec 2nd, 2025
Sublime Security
/feeds/core/detection-rules/link-qr-code-in-eml-attachment-with-credential-phishing-indicators-9908ed3a
Suspicious invoice reference with missing or image-only attachments
1mo ago
Dec 2nd, 2025
Sublime Security
/feeds/core/detection-rules/suspicious-invoice-reference-with-missing-or-image-only-attachments-466c1680
Compensation review with QR code in attached EML
1mo ago
Nov 26th, 2025
Sublime Security
/feeds/core/detection-rules/compensation-review-with-qr-code-in-attached-eml-98a2f03c
Brand impersonation: Sharepoint
1mo ago
Nov 24th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-sharepoint-284b1b70
Brand impersonation: Adobe with suspicious language and link
1mo ago
Nov 24th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-adobe-with-suspicious-language-and-link-32cc8bf1
Credential phishing: DocuSign embedded image lure with no DocuSign domains in links
1mo ago
Nov 18th, 2025
Sublime Security
/feeds/core/detection-rules/credential-phishing-docusign-embedded-image-lure-with-no-docusign-domains-in-links-dfe8715e
Brand impersonation: Capital One
1mo ago
Nov 17th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-capital-one-d53848e4
Brand impersonation: Quickbooks
1mo ago
Nov 14th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-quickbooks-4fd791d1
Brand impersonation: Fake Fax
1mo ago
Nov 13th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-fake-fax-2a96b90a
Brand impersonation: SharePoint PDF attachment with credential theft language
1mo ago
Nov 7th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-sharepoint-pdf-attachment-with-credential-theft-language-ae3756fa
Brand impersonation: USPS
1mo ago
Nov 5th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-usps-28b9130a
Spam: Mastercard promotional content with image-based body
1mo ago
Nov 5th, 2025
Sublime Security
/feeds/core/detection-rules/spam-mastercard-promotional-content-with-image-based-body-5f2cb559