Detection Method: Optical Character Recognition

OCR (Optical Character Recognition) helps systems read and analyze text in images, screenshots, and scanned documents. This method turns visual text into machine-readable content, allowing your security tools to catch things that would normally slip past text-based filters.
OCR can help you detect:
  • Phishing text hidden in images to bypass text-based filters
  • Suspicious language or instructions in scanned documents
  • QR codes with malicious links
  • Brand impersonation attempts using image-based logos or text
  • Requests for sensitive information disguised in images
For example, attackers often embed fake login prompts or instructions to call a "customer support" number in images. These tricks are designed to bypass traditional security filters, but OCR can extract and analyze the text to flag it as malicious before it reaches you.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Brand impersonation: Microsoft with low reputation links
4h ago
Aug 27th, 2026
Sublime Security
Attachment: Invoice and W-9 PDFs with suspicious creators
2d ago
Aug 25th, 2026
Sublime Security
Attachment: PDF proposal with credential theft indicators
3d ago
Aug 24th, 2026
Sublime Security
Brand impersonation: Microsoft logo image linking to free file host
6d ago
Aug 21st, 2026
Sublime Security
Attachment: Image-only docx/pptx callback phishing
6d ago
Aug 21st, 2026
Sublime Security
Brand impersonation: Greetings Island
9d ago
Aug 18th, 2026
Sublime Security
Brand impersonation: SendGrid
20d ago
Aug 7th, 2026
Sublime Security
Extortion / sextortion in attachment from untrusted sender
21d ago
Aug 6th, 2026
Sublime Security
Callback phishing in body or attachment (untrusted sender)
22d ago
Aug 5th, 2026
Sublime Security
Link: QuickBooks image lure with suspicious link
29d ago
Jul 29th, 2026
Sublime Security
Attachment: Fictitious invoice using LinkedIn's address
29d ago
Jul 29th, 2026
Sublime Security
Attachment: EML with link to credential phishing page
1mo ago
Jul 27th, 2026
Sublime Security
Brand impersonation: TikTok
1mo ago
Jul 27th, 2026
Sublime Security
Brand Impersonation: Shein
1mo ago
Jul 27th, 2026
Sublime Security
Brand impersonation: Amazon Web Services (AWS)
1mo ago
Jul 27th, 2026
Sublime Security
Attachment: Microsoft 365 credential phishing
1mo ago
Jul 27th, 2026
Sublime Security
Attachment: Callback phishing solicitation via pdf file
1mo ago
Jul 27th, 2026
Sublime Security
Brand impersonation: Square
1mo ago
Jul 27th, 2026
Sublime Security
Brand impersonation: Internal Revenue Service
1mo ago
Jul 27th, 2026
Sublime Security
Attachment: Microsoft SharePoint Impersonation via images in macro-enabled attachment
1mo ago
Jul 16th, 2026
Sublime Security