Detection Method: Optical Character Recognition

OCR (Optical Character Recognition) helps systems read and analyze text in images, screenshots, and scanned documents. This method turns visual text into machine-readable content, allowing your security tools to catch things that would normally slip past text-based filters.
OCR can help you detect:
  • Phishing text hidden in images to bypass text-based filters
  • Suspicious language or instructions in scanned documents
  • QR codes with malicious links
  • Brand impersonation attempts using image-based logos or text
  • Requests for sensitive information disguised in images
For example, attackers often embed fake login prompts or instructions to call a "customer support" number in images. These tricks are designed to bypass traditional security filters, but OCR can extract and analyze the text to flag it as malicious before it reaches you.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: Adobe image lure in body or attachment with suspicious link
21d ago
Dec 12th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-adobe-image-lure-in-body-or-attachment-with-suspicious-link-1d7add81
Attachment: Compensation review lure with QR code
23d ago
Dec 10th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-compensation-review-lure-with-qr-code-9fd8185c
Brand impersonation: Microsoft with low reputation links
23d ago
Dec 10th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-microsoft-with-low-reputation-links-b59201b6
Link: Microsoft Dynamics 365 form phishing
28d ago
Dec 5th, 2025
Sublime Security
/feeds/core/detection-rules/link-microsoft-dynamics-365-form-phishing-f72b9085
Attachment: Legal themed message or PDF with suspicious indicators
1mo ago
Dec 1st, 2025
Sublime Security
/feeds/core/detection-rules/attachment-legal-themed-message-or-pdf-with-suspicious-indicators-19133301
Compensation review with QR code in attached EML
1mo ago
Nov 26th, 2025
Sublime Security
/feeds/core/detection-rules/compensation-review-with-qr-code-in-attached-eml-98a2f03c
Callback phishing in body or attachment (untrusted sender)
1mo ago
Nov 19th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-in-body-or-attachment-untrusted-sender-b93c6f94
Credential phishing: DocuSign embedded image lure with no DocuSign domains in links
1mo ago
Nov 18th, 2025
Sublime Security
/feeds/core/detection-rules/credential-phishing-docusign-embedded-image-lure-with-no-docusign-domains-in-links-dfe8715e
Brand impersonation: SendGrid
1mo ago
Nov 17th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-sendgrid-d800124f
Brand impersonation: Fake Fax
1mo ago
Nov 13th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-fake-fax-2a96b90a
Brand impersonation: SharePoint PDF attachment with credential theft language
1mo ago
Nov 7th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-sharepoint-pdf-attachment-with-credential-theft-language-ae3756fa
Spam: Mastercard promotional content with image-based body
1mo ago
Nov 5th, 2025
Sublime Security
/feeds/core/detection-rules/spam-mastercard-promotional-content-with-image-based-body-5f2cb559
Callback phishing via extensionless rfc822 attachment
1mo ago
Nov 4th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-extensionless-rfc822-attachment-197722c4
Brand impersonation: TikTok
2mo ago
Oct 30th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-tiktok-aaacc8b7
Brand impersonation: Toronto-Dominion Bank
2mo ago
Oct 22nd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-toronto-dominion-bank-2dc16a55
Brand impersonation: DocuSign branded attachment lure with no DocuSign links
2mo ago
Oct 22nd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-docusign-branded-attachment-lure-with-no-docusign-links-814a5694
Brand impersonation: DocuSign PDF attachment with suspicious link
2mo ago
Oct 22nd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-docusign-pdf-attachment-with-suspicious-link-2601cbb7
Brand impersonation: Internal Revenue Service
2mo ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-internal-revenue-service-3c63f8e9
Callback phishing: Branded invoice from sender/reply-to domain less than 30 days old
2mo ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-branded-invoice-from-senderreply-to-domain-less-than-30-days-old-e6f4af53
Fake scan-to-email message
2mo ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/fake-scan-to-email-message-78851fbe