Detection Method: Optical Character Recognition

OCR (Optical Character Recognition) helps systems read and analyze text in images, screenshots, and scanned documents. This method turns visual text into machine-readable content, allowing your security tools to catch things that would normally slip past text-based filters.
OCR can help you detect:
  • Phishing text hidden in images to bypass text-based filters
  • Suspicious language or instructions in scanned documents
  • QR codes with malicious links
  • Brand impersonation attempts using image-based logos or text
  • Requests for sensitive information disguised in images
For example, attackers often embed fake login prompts or instructions to call a "customer support" number in images. These tricks are designed to bypass traditional security filters, but OCR can extract and analyze the text to flag it as malicious before it reaches you.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Extortion / sextortion in attachment from untrusted sender
22h ago
Aug 6th, 2026
Sublime Security
Callback phishing in body or attachment (untrusted sender)
2d ago
Aug 5th, 2026
Sublime Security
Link: QuickBooks image lure with suspicious link
9d ago
Jul 29th, 2026
Sublime Security
Attachment: Fictitious invoice using LinkedIn's address
9d ago
Jul 29th, 2026
Sublime Security
Attachment: EML with link to credential phishing page
11d ago
Jul 27th, 2026
Sublime Security
Brand Impersonation: Shein
11d ago
Jul 27th, 2026
Sublime Security
Brand impersonation: TikTok
11d ago
Jul 27th, 2026
Sublime Security
Brand impersonation: Internal Revenue Service
11d ago
Jul 27th, 2026
Sublime Security
Attachment: Callback phishing solicitation via pdf file
11d ago
Jul 27th, 2026
Sublime Security
Brand impersonation: Square
11d ago
Jul 27th, 2026
Sublime Security
Brand impersonation: Amazon Web Services (AWS)
11d ago
Jul 27th, 2026
Sublime Security
Attachment: Microsoft 365 credential phishing
11d ago
Jul 27th, 2026
Sublime Security
Attachment: Microsoft SharePoint Impersonation via images in macro-enabled attachment
22d ago
Jul 16th, 2026
Sublime Security
Link: Multistage landing - Abused Adobe Acrobat hosted PDF
24d ago
Jul 14th, 2026
Sublime Security
Attachment: Suspicious PDF created with headless browser
1mo ago
Jul 1st, 2026
Sublime Security
Cloud storage impersonation with credential theft indicators
1mo ago
Jun 30th, 2026
Sublime Security
Attachment: Invoice and W-9 PDFs with suspicious creators
1mo ago
Jun 26th, 2026
Sublime Security
Attachment: Duplicated header pages in fraudulent multi-page PDF Request for Quotation
1mo ago
Jun 25th, 2026
Sublime Security
Brand impersonation: Fake procurement/RFQ PDF from energy and industrial companies
1mo ago
Jun 25th, 2026
Sublime Security
Brand impersonation: Fake Fax
1mo ago
Jun 17th, 2026
Sublime Security