Detection Method: Optical Character Recognition

OCR (Optical Character Recognition) helps systems read and analyze text in images, screenshots, and scanned documents. This method turns visual text into machine-readable content, allowing your security tools to catch things that would normally slip past text-based filters.
OCR can help you detect:
  • Phishing text hidden in images to bypass text-based filters
  • Suspicious language or instructions in scanned documents
  • QR codes with malicious links
  • Brand impersonation attempts using image-based logos or text
  • Requests for sensitive information disguised in images
For example, attackers often embed fake login prompts or instructions to call a "customer support" number in images. These tricks are designed to bypass traditional security filters, but OCR can extract and analyze the text to flag it as malicious before it reaches you.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: Suspicious PDF created with headless browser
5d ago
May 7th, 2026
Sublime Security
Callback phishing via Intuit service abuse
8d ago
May 4th, 2026
Sublime Security
Brand impersonation: SharePoint PDF attachment with credential theft language
8d ago
May 4th, 2026
Sublime Security
Callback phishing via Google Group abuse
8d ago
May 4th, 2026
Sublime Security
Attachment: Fake voicemail via PDF
12d ago
Apr 30th, 2026
Sublime Security
Brand impersonation: Fake Fax
12d ago
Apr 30th, 2026
Sublime Security
Adobe branded PDF file linking to a password-protected file from untrusted sender
13d ago
Apr 29th, 2026
Sublime Security
Cloud storage impersonation with credential theft indicators
19d ago
Apr 23rd, 2026
Sublime Security
Brand impersonation: Amazon with suspicious attachment
28d ago
Apr 14th, 2026
Sublime Security
Attachment: Compensation review lure with QR code
28d ago
Apr 14th, 2026
Sublime Security
Brand impersonation: Toronto-Dominion Bank
1mo ago
Apr 3rd, 2026
Sublime Security
Attachment: Legal themed message or PDF with suspicious indicators
1mo ago
Apr 3rd, 2026
Sublime Security
Attachment: PDF bid/proposal lure with credential theft indicators
1mo ago
Mar 27th, 2026
Sublime Security
Callback phishing in body or attachment (untrusted sender)
1mo ago
Mar 27th, 2026
Sublime Security
Attachment: PDF proposal with credential theft indicators
1mo ago
Mar 17th, 2026
Sublime Security
Brand impersonation: SendGrid
2mo ago
Mar 12th, 2026
Sublime Security
Link: Figma design deck with credential theft language
2mo ago
Mar 4th, 2026
Sublime Security
Impersonation: Recipient organization in sender display name with credential theft image
2mo ago
Feb 17th, 2026
Sublime Security
Brand impersonation: TikTok
2mo ago
Feb 12th, 2026
Sublime Security
Attachment: Office file with document sharing and browser instruction lures
3mo ago
Jan 29th, 2026
Sublime Security