Detection Method: URL screenshot

URL screenshot captures and analyzes the visual elements of web pages linked in emails to help you spot phishing attempts or suspicious content that might slip past regular URL analysis. By rendering these web pages in a safe, isolated environment, it gives you a sneak peek at the content—without putting you at risk.
URL screenshot can help you detect:
  • Fake login pages pretending to be from trusted services
  • Brand impersonation using logos or design that don’t belong
  • Malicious forms trying to steal your credentials
  • Content that’s designed to trick you but can’t be caught by regular text analysis
  • CAPTCHA forms or other elements trying to bypass automated detection
For example, attackers often create exact replicas of login pages from banks or email providers. URL screenshots make it easier to spot these deceptive pages, whether you're reviewing them manually or relying on automated systems.
This method is crucial for spotting phishing attempts that rely on visual tricks, helping you prevent falling for malicious links that look convincing at first glance.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Service abuse: Formester with suspicious link behavior
14d ago
Dec 19th, 2025
Sublime Security
/feeds/core/detection-rules/service-abuse-formester-with-suspicious-link-behavior-e4b74fd4
Credential phishing content and link (untrusted sender)
16d ago
Dec 17th, 2025
Sublime Security
/feeds/core/detection-rules/credential-phishing-content-and-link-untrusted-sender-f0c95bb7
Link: Microsoft Dynamics 365 form phishing
28d ago
Dec 5th, 2025
Sublime Security
/feeds/core/detection-rules/link-microsoft-dynamics-365-form-phishing-f72b9085
Link: HR impersonation with suspicious domain indicators and credential theft
30d ago
Dec 3rd, 2025
Sublime Security
/feeds/core/detection-rules/link-hr-impersonation-with-suspicious-domain-indicators-and-credential-theft-f31f8831
Link: Cryptocurrency fraud with suspicious links
1mo ago
Dec 1st, 2025
Sublime Security
/feeds/core/detection-rules/link-cryptocurrency-fraud-with-suspicious-links-d0da37ce
Link: Spam website with evasion indicators
1mo ago
Nov 25th, 2025
Sublime Security
/feeds/core/detection-rules/link-spam-website-with-evasion-indicators-08bcd353
Brand impersonation: DocuSign branded attachment lure with no DocuSign links
2mo ago
Oct 22nd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-docusign-branded-attachment-lure-with-no-docusign-links-814a5694
Google Accelerated Mobile Pages (AMP) abuse
3mo ago
Sep 22nd, 2025
Sublime Security
/feeds/core/detection-rules/google-accelerated-mobile-pages-amp-abuse-46907029
Attachment: QR code with credential phishing indicators
3mo ago
Sep 4th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-qr-code-with-credential-phishing-indicators-9f1681e1
Link: Multistage landing - FreshDesk knowledge base abuse
4mo ago
Aug 21st, 2025
Sublime Security
/feeds/core/detection-rules/link-multistage-landing-freshdesk-knowledge-base-abuse-edd6acf7
Link: Multistage landing - Trello board abuse
4mo ago
Aug 20th, 2025
Sublime Security
/feeds/core/detection-rules/link-multistage-landing-trello-board-abuse-14a5b23a
Link: Adobe share with suspicious indicators
5mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/link-adobe-share-with-suspicious-indicators-b33cae80
Suspicious recipients pattern with no Compauth pass and suspicious content
5mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/suspicious-recipients-pattern-with-no-compauth-pass-and-suspicious-content-34fb65f6
Link: Multistage landing - Scribd document
5mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/link-multistage-landing-scribd-document-afa9807d
Link: Multistage landing - Ludus presentation
5mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/link-multistage-landing-ludus-presentation-a8b3c311
Issuu document with suspicious embedded link
5mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/issuu-document-with-suspicious-embedded-link-0d73f43d
Link: Figma design deck with credential theft language
5mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/link-figma-design-deck-with-credential-theft-language-87601924
Link: chatbot.page platform abuse
5mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/link-chatbotpage-platform-abuse-bfd6a076
Link: Credential phishing link with undisclosed recipients
5mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/link-credential-phishing-link-with-undisclosed-recipients-06fc155e
Attachment: EML with link to credential phishing page
5mo ago
Jul 16th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-eml-with-link-to-credential-phishing-page-1df41cca