Detection Method: URL screenshot

URL screenshot captures and analyzes the visual elements of web pages linked in emails to help you spot phishing attempts or suspicious content that might slip past regular URL analysis. By rendering these web pages in a safe, isolated environment, it gives you a sneak peek at the content—without putting you at risk.
URL screenshot can help you detect:
  • Fake login pages pretending to be from trusted services
  • Brand impersonation using logos or design that don’t belong
  • Malicious forms trying to steal your credentials
  • Content that’s designed to trick you but can’t be caught by regular text analysis
  • CAPTCHA forms or other elements trying to bypass automated detection
For example, attackers often create exact replicas of login pages from banks or email providers. URL screenshots make it easier to spot these deceptive pages, whether you're reviewing them manually or relying on automated systems.
This method is crucial for spotting phishing attempts that rely on visual tricks, helping you prevent falling for malicious links that look convincing at first glance.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Link: Figma design deck with credential theft language
12h ago
Mar 4th, 2026
Sublime Security
/feeds/core/detection-rules/link-figma-design-deck-with-credential-theft-language-87601924
Attachment: PDF with suspicious link and action-oriented language
6d ago
Feb 27th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-pdf-with-suspicious-link-and-action-oriented-language-816d33a0
Link: Credential theft with invisible Unicode character in page title from unsolicited sender
20d ago
Feb 13th, 2026
Sublime Security
/feeds/core/detection-rules/link-credential-theft-with-invisible-unicode-character-in-page-title-from-unsolicited-sender-5fe14d53
Link: Microsoft Dynamics 365 form phishing
1mo ago
Jan 27th, 2026
Sublime Security
/feeds/core/detection-rules/link-microsoft-dynamics-365-form-phishing-f72b9085
Link: Adobe share with suspicious indicators
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/link-adobe-share-with-suspicious-indicators-b33cae80
Google Accelerated Mobile Pages (AMP) abuse
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/google-accelerated-mobile-pages-amp-abuse-46907029
Link to auto-downloaded file with Google Drive branding
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/link-to-auto-downloaded-file-with-google-drive-branding-4b5343be
Free subdomain link with login or captcha (untrusted sender)
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/free-subdomain-link-with-login-or-captcha-untrusted-sender-93288f82
Link: Multistage landing - Scribd document
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/link-multistage-landing-scribd-document-afa9807d
Suspicious recipients pattern with no Compauth pass and suspicious content
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/suspicious-recipients-pattern-with-no-compauth-pass-and-suspicious-content-34fb65f6
Suspicious recipient pattern and language with low reputation link to login
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/suspicious-recipient-pattern-and-language-with-low-reputation-link-to-login-a8ea0402
Issuu document with suspicious embedded link
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/issuu-document-with-suspicious-embedded-link-0d73f43d
Attachment: QR code with credential phishing indicators
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-qr-code-with-credential-phishing-indicators-9f1681e1
Attachment: HTML smuggling - QR Code with suspicious links
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-html-smuggling-qr-code-with-suspicious-links-010e757d
Service abuse: Formester with suspicious link behavior
2mo ago
Dec 19th, 2025
Sublime Security
/feeds/core/detection-rules/service-abuse-formester-with-suspicious-link-behavior-e4b74fd4
Credential phishing content and link (untrusted sender)
2mo ago
Dec 17th, 2025
Sublime Security
/feeds/core/detection-rules/credential-phishing-content-and-link-untrusted-sender-f0c95bb7
Link: HR impersonation with suspicious domain indicators and credential theft
3mo ago
Dec 3rd, 2025
Sublime Security
/feeds/core/detection-rules/link-hr-impersonation-with-suspicious-domain-indicators-and-credential-theft-f31f8831
Link: Cryptocurrency fraud with suspicious links
3mo ago
Dec 1st, 2025
Sublime Security
/feeds/core/detection-rules/link-cryptocurrency-fraud-with-suspicious-links-d0da37ce
Link: Spam website with evasion indicators
3mo ago
Nov 25th, 2025
Sublime Security
/feeds/core/detection-rules/link-spam-website-with-evasion-indicators-08bcd353
Brand impersonation: DocuSign branded attachment lure with no DocuSign links
4mo ago
Oct 22nd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-docusign-branded-attachment-lure-with-no-docusign-links-814a5694