Detection Method: Optical Character Recognition

OCR (Optical Character Recognition) helps systems read and analyze text in images, screenshots, and scanned documents. This method turns visual text into machine-readable content, allowing your security tools to catch things that would normally slip past text-based filters.
OCR can help you detect:
  • Phishing text hidden in images to bypass text-based filters
  • Suspicious language or instructions in scanned documents
  • QR codes with malicious links
  • Brand impersonation attempts using image-based logos or text
  • Requests for sensitive information disguised in images
For example, attackers often embed fake login prompts or instructions to call a "customer support" number in images. These tricks are designed to bypass traditional security filters, but OCR can extract and analyze the text to flag it as malicious before it reaches you.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Callback phishing in body or attachment (untrusted sender)
4d ago
Nov 8th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-in-body-or-attachment-untrusted-sender-b93c6f94
Brand impersonation: Microsoft with low reputation links
4d ago
Nov 8th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-microsoft-with-low-reputation-links-b59201b6
Brand impersonation: SendGrid
5d ago
Nov 7th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-sendgrid-d800124f
Brand impersonation: SharePoint PDF attachment with credential theft language
5d ago
Nov 7th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-sharepoint-pdf-attachment-with-credential-theft-language-ae3756fa
Compensation review with QR code in attached EML
7d ago
Nov 5th, 2025
Sublime Security
/feeds/core/detection-rules/compensation-review-with-qr-code-in-attached-eml-98a2f03c
Spam: Mastercard promotional content with image-based body
7d ago
Nov 5th, 2025
Sublime Security
/feeds/core/detection-rules/spam-mastercard-promotional-content-with-image-based-body-5f2cb559
Callback phishing via extensionless rfc822 attachment
8d ago
Nov 4th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-extensionless-rfc822-attachment-197722c4
Brand impersonation: TikTok
13d ago
Oct 30th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-tiktok-aaacc8b7
Attachment: Compensation review lure with QR code
14d ago
Oct 29th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-compensation-review-lure-with-qr-code-9fd8185c
Brand impersonation: Toronto-Dominion Bank
21d ago
Oct 22nd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-toronto-dominion-bank-2dc16a55
Brand impersonation: DocuSign branded attachment lure with no DocuSign links
21d ago
Oct 22nd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-docusign-branded-attachment-lure-with-no-docusign-links-814a5694
Brand impersonation: DocuSign PDF attachment with suspicious link
21d ago
Oct 22nd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-docusign-pdf-attachment-with-suspicious-link-2601cbb7
Brand impersonation: Internal Revenue Service
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-internal-revenue-service-3c63f8e9
Credential phishing: DocuSign embedded image lure with no DocuSign domains in links
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/credential-phishing-docusign-embedded-image-lure-with-no-docusign-domains-in-links-dfe8715e
Callback phishing via e-signature service
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-e-signature-service-ed37b4fd
Callback phishing: Branded invoice from sender/reply-to domain less than 30 days old
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-branded-invoice-from-senderreply-to-domain-less-than-30-days-old-e6f4af53
Fake scan-to-email message
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/fake-scan-to-email-message-78851fbe
Attachment: Office file with document sharing and browser instruction lures
27d ago
Oct 16th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-office-file-with-document-sharing-and-browser-instruction-lures-b1250a4b
Brand impersonation: Square
27d ago
Oct 16th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-square-63f9b449
Brand Impersonation: Shein
28d ago
Oct 15th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-shein-b5843f22