Detection Method: URL screenshot

URL screenshot captures and analyzes the visual elements of web pages linked in emails to help you spot phishing attempts or suspicious content that might slip past regular URL analysis. By rendering these web pages in a safe, isolated environment, it gives you a sneak peek at the content—without putting you at risk.
URL screenshot can help you detect:
  • Fake login pages pretending to be from trusted services
  • Brand impersonation using logos or design that don’t belong
  • Malicious forms trying to steal your credentials
  • Content that’s designed to trick you but can’t be caught by regular text analysis
  • CAPTCHA forms or other elements trying to bypass automated detection
For example, attackers often create exact replicas of login pages from banks or email providers. URL screenshots make it easier to spot these deceptive pages, whether you're reviewing them manually or relying on automated systems.
This method is crucial for spotting phishing attempts that rely on visual tricks, helping you prevent falling for malicious links that look convincing at first glance.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Brand impersonation: DocuSign branded attachment lure with no DocuSign links
21d ago
Oct 22nd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-docusign-branded-attachment-lure-with-no-docusign-links-814a5694
Google Accelerated Mobile Pages (AMP) abuse
1mo ago
Sep 22nd, 2025
Sublime Security
/feeds/core/detection-rules/google-accelerated-mobile-pages-amp-abuse-46907029
Attachment: QR code with credential phishing indicators
2mo ago
Sep 4th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-qr-code-with-credential-phishing-indicators-9f1681e1
Link: Multistage landing - FreshDesk knowledge base abuse
2mo ago
Aug 21st, 2025
Sublime Security
/feeds/core/detection-rules/link-multistage-landing-freshdesk-knowledge-base-abuse-edd6acf7
Link: Multistage landing - Trello board abuse
2mo ago
Aug 20th, 2025
Sublime Security
/feeds/core/detection-rules/link-multistage-landing-trello-board-abuse-14a5b23a
Link: Adobe share with suspicious indicators
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/link-adobe-share-with-suspicious-indicators-b33cae80
Suspicious recipients pattern with no Compauth pass and suspicious content
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/suspicious-recipients-pattern-with-no-compauth-pass-and-suspicious-content-34fb65f6
Link: Multistage landing - Scribd document
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/link-multistage-landing-scribd-document-afa9807d
Link: Multistage landing - Ludus presentation
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/link-multistage-landing-ludus-presentation-a8b3c311
Issuu document with suspicious embedded link
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/issuu-document-with-suspicious-embedded-link-0d73f43d
Link: Figma design deck with credential theft language
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/link-figma-design-deck-with-credential-theft-language-87601924
Link: chatbot.page platform abuse
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/link-chatbotpage-platform-abuse-bfd6a076
Link: Credential phishing link with undisclosed recipients
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/link-credential-phishing-link-with-undisclosed-recipients-06fc155e
Attachment: HTML smuggling - QR Code with suspicious links
3mo ago
Jul 16th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-html-smuggling-qr-code-with-suspicious-links-010e757d
Credential phishing link (unknown sender)
3mo ago
Jul 16th, 2025
Sublime Security
/feeds/core/detection-rules/credential-phishing-link-unknown-sender-a278012b
Free subdomain link with login or captcha (untrusted sender)
3mo ago
Jul 16th, 2025
Sublime Security
/feeds/core/detection-rules/free-subdomain-link-with-login-or-captcha-untrusted-sender-93288f82
Credential phishing content and link (untrusted sender)
3mo ago
Jul 16th, 2025
Sublime Security
/feeds/core/detection-rules/credential-phishing-content-and-link-untrusted-sender-f0c95bb7
Link: Microsoft Dynamics 365 form phishing
3mo ago
Jul 16th, 2025
Sublime Security
/feeds/core/detection-rules/link-microsoft-dynamics-365-form-phishing-f72b9085
Link to auto-downloaded file with Adobe branding
3mo ago
Jul 16th, 2025
Sublime Security
/feeds/core/detection-rules/link-to-auto-downloaded-file-with-adobe-branding-e826c2cf
Link to auto-downloaded file with Google Drive branding
3mo ago
Jul 16th, 2025
Sublime Security
/feeds/core/detection-rules/link-to-auto-downloaded-file-with-google-drive-branding-4b5343be