Detection Method: URL screenshot

URL screenshot captures and analyzes the visual elements of web pages linked in emails to help you spot phishing attempts or suspicious content that might slip past regular URL analysis. By rendering these web pages in a safe, isolated environment, it gives you a sneak peek at the content—without putting you at risk.
URL screenshot can help you detect:
  • Fake login pages pretending to be from trusted services
  • Brand impersonation using logos or design that don’t belong
  • Malicious forms trying to steal your credentials
  • Content that’s designed to trick you but can’t be caught by regular text analysis
  • CAPTCHA forms or other elements trying to bypass automated detection
For example, attackers often create exact replicas of login pages from banks or email providers. URL screenshots make it easier to spot these deceptive pages, whether you're reviewing them manually or relying on automated systems.
This method is crucial for spotting phishing attempts that rely on visual tricks, helping you prevent falling for malicious links that look convincing at first glance.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Brand impersonation: DocuSign branded attachment lure with no DocuSign links
4d ago
Jun 4th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-docusign-branded-attachment-lure-with-no-docusign-links-814a5694
Link: Multistage Landing - Scribd Document
23d ago
May 16th, 2025
Sublime Security
/feeds/core/detection-rules/link-multistage-landing-scribd-document-afa9807d
Link: Multistage Landing - Ludus Presentation
25d ago
May 14th, 2025
Sublime Security
/feeds/core/detection-rules/link-multistage-landing-ludus-presentation-a8b3c311
Link: Figma Design Deck With Credential Phishing Language
1mo ago
May 7th, 2025
Sublime Security
/feeds/core/detection-rules/link-figma-design-deck-with-credential-phishing-language-87601924
Credential phishing content and link (untrusted sender)
1mo ago
May 7th, 2025
Sublime Security
/feeds/core/detection-rules/credential-phishing-content-and-link-untrusted-sender-f0c95bb7
Issuu Document With Suspicious Embedded Link
1mo ago
May 5th, 2025
Sublime Security
/feeds/core/detection-rules/issuu-document-with-suspicious-embedded-link-0d73f43d
Credential phishing link (unknown sender)
1mo ago
Apr 30th, 2025
Sublime Security
/feeds/core/detection-rules/credential-phishing-link-unknown-sender-a278012b
Attachment: QR code with credential phishing indicators
1mo ago
Apr 14th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-qr-code-with-credential-phishing-indicators-9f1681e1
Free subdomain link with credential theft indicators
5mo ago
Dec 12th, 2024
Sublime Security
/feeds/core/detection-rules/free-subdomain-link-with-credential-theft-indicators-9187479c
Link: Adobe Share with Suspicious Indicators
6mo ago
Dec 3rd, 2024
Sublime Security
/feeds/core/detection-rules/link-adobe-share-with-suspicious-indicators-b33cae80
Link: Microsoft Dynamics 365 form phishing
6mo ago
Nov 14th, 2024
Sublime Security
/feeds/core/detection-rules/link-microsoft-dynamics-365-form-phishing-f72b9085
Attachment: EML with link to credential phishing page
8mo ago
Sep 13th, 2024
Sublime Security
/feeds/core/detection-rules/attachment-eml-with-link-to-credential-phishing-page-1df41cca
Suspicious Recipients pattern with no Compauth pass and suspicious content
9mo ago
Aug 27th, 2024
Sublime Security
/feeds/core/detection-rules/suspicious-recipients-pattern-with-no-compauth-pass-and-suspicious-content-34fb65f6
Google Drive abuse: Credential phishing link
10mo ago
Jul 31st, 2024
Sublime Security
/feeds/core/detection-rules/google-drive-abuse-credential-phishing-link-c74aece0
Suspicious recipient pattern and language with low reputation link to login
1y ago
Apr 30th, 2024
Sublime Security
/feeds/core/detection-rules/suspicious-recipient-pattern-and-language-with-low-reputation-link-to-login-a8ea0402
Google Accelerated Mobile Pages (AMP) abuse
1y ago
Apr 25th, 2024
Sublime Security
/feeds/core/detection-rules/google-accelerated-mobile-pages-amp-abuse-46907029
Link: Credential Phishing link with Undisclosed Recipients
1y ago
Apr 25th, 2024
Sublime Security
/feeds/core/detection-rules/link-credential-phishing-link-with-undisclosed-recipients-06fc155e
Link to auto-downloaded file with Google Drive branding
1y ago
Apr 25th, 2024
Sublime Security
/feeds/core/detection-rules/link-to-auto-downloaded-file-with-google-drive-branding-4b5343be
Free subdomain link with login or captcha (untrusted sender)
1y ago
Apr 25th, 2024
Sublime Security
/feeds/core/detection-rules/free-subdomain-link-with-login-or-captcha-untrusted-sender-93288f82
Attachment: HTML smuggling - QR Code with suspicious links
1y ago
Apr 25th, 2024
Sublime Security
/feeds/core/detection-rules/attachment-html-smuggling-qr-code-with-suspicious-links-010e757d