Detection Method: URL screenshot

URL screenshot captures and analyzes the visual elements of web pages linked in emails to help you spot phishing attempts or suspicious content that might slip past regular URL analysis. By rendering these web pages in a safe, isolated environment, it gives you a sneak peek at the content—without putting you at risk.
URL screenshot can help you detect:
  • Fake login pages pretending to be from trusted services
  • Brand impersonation using logos or design that don’t belong
  • Malicious forms trying to steal your credentials
  • Content that’s designed to trick you but can’t be caught by regular text analysis
  • CAPTCHA forms or other elements trying to bypass automated detection
For example, attackers often create exact replicas of login pages from banks or email providers. URL screenshots make it easier to spot these deceptive pages, whether you're reviewing them manually or relying on automated systems.
This method is crucial for spotting phishing attempts that rely on visual tricks, helping you prevent falling for malicious links that look convincing at first glance.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Link: Microsoft device code authentication with suspicious indicators
18d ago
Mar 12th, 2026
Sublime Security
Link: Unsolicited email contains link to page containing Tycoon URI structure
20d ago
Mar 10th, 2026
Sublime Security
Attachment: PDF with suspicious link and action-oriented language
24d ago
Mar 6th, 2026
Sublime Security
Link: Figma design deck with credential theft language
26d ago
Mar 4th, 2026
Sublime Security
Link: Credential theft with invisible Unicode character in page title from unsolicited sender
1mo ago
Feb 13th, 2026
Sublime Security
Link: Microsoft Dynamics 365 form phishing
2mo ago
Jan 27th, 2026
Sublime Security
Free subdomain link with login or captcha (untrusted sender)
2mo ago
Jan 12th, 2026
Sublime Security
Link: Multistage landing - Scribd document
2mo ago
Jan 12th, 2026
Sublime Security
Suspicious recipients pattern with no Compauth pass and suspicious content
2mo ago
Jan 12th, 2026
Sublime Security
Suspicious recipient pattern and language with low reputation link to login
2mo ago
Jan 12th, 2026
Sublime Security
Attachment: QR code with credential phishing indicators
2mo ago
Jan 12th, 2026
Sublime Security
Attachment: HTML smuggling - QR Code with suspicious links
2mo ago
Jan 12th, 2026
Sublime Security
Issuu document with suspicious embedded link
2mo ago
Jan 12th, 2026
Sublime Security
Link: Adobe share with suspicious indicators
2mo ago
Jan 12th, 2026
Sublime Security
Google Accelerated Mobile Pages (AMP) abuse
2mo ago
Jan 12th, 2026
Sublime Security
Link to auto-downloaded file with Google Drive branding
2mo ago
Jan 12th, 2026
Sublime Security
Service abuse: Formester with suspicious link behavior
3mo ago
Dec 19th, 2025
Sublime Security
Credential phishing content and link (untrusted sender)
3mo ago
Dec 17th, 2025
Sublime Security
Link: HR impersonation with suspicious domain indicators and credential theft
3mo ago
Dec 3rd, 2025
Sublime Security
Link: Cryptocurrency fraud with suspicious links
3mo ago
Dec 1st, 2025
Sublime Security