Detection Method: Content analysis

Content analysis looks at the language and structure of a message to identify signs of phishing, social engineering, and other malicious intent. Instead of scanning for keywords, this method uses natural language understanding (NLU) to detect meaning, intent, and tone across the message.
Content analysis helps detect:
  • BEC attempts with urgent messages from executive impersonators
  • Credential phishing disguised as login or document notifications
  • Callback scams posing as account renewals or fake support
  • Extortion threats or blackmail messages
  • Financial or personal data requests in suspicious contexts
  • Fake job offers targeting employees
  • Invoice fraud, payroll fraud, and more
For example, a phishing email may impersonate a CFO asking for a wire transfer. Content analysis can flag the urgent tone, financial context, and impersonation attempt.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Service abuse: Behance document sharing with suspicious language
3d ago
Mar 27th, 2026
Sublime Security
Attachment: PDF bid/proposal lure with credential theft indicators
3d ago
Mar 27th, 2026
Sublime Security
Body: PayApp transaction reference pattern
3d ago
Mar 27th, 2026
Sublime Security
Credential phishing: Financial lure via ActiveCampaign infrastructure
3d ago
Mar 27th, 2026
Sublime Security
Callback phishing in body or attachment (untrusted sender)
3d ago
Mar 27th, 2026
Sublime Security
Business Email Compromise (BEC) with request for mobile number
4d ago
Mar 26th, 2026
Sublime Security
Service abuse: AWS SNS callback scam impersonation
4d ago
Mar 26th, 2026
Sublime Security
Callback phishing via Microsoft comment
4d ago
Mar 26th, 2026
Sublime Security
Brand impersonation: Robinhood
4d ago
Mar 26th, 2026
Sublime Security
VIP impersonation with urgent request (strict match, untrusted sender)
5d ago
Mar 25th, 2026
Sublime Security
VIP impersonation with BEC language (near match, untrusted sender)
5d ago
Mar 25th, 2026
Sublime Security
Brand impersonation: USPS
5d ago
Mar 25th, 2026
Sublime Security
Credential phishing: Fake card notification with tracking lure
6d ago
Mar 24th, 2026
Sublime Security
Link: Financial account issue with suspicious indicators
6d ago
Mar 24th, 2026
Sublime Security
Cloud storage impersonation with credential theft indicators
7d ago
Mar 23rd, 2026
Sublime Security
Credential phishing: Suspicious subject with urgent financial request and link
7d ago
Mar 23rd, 2026
Sublime Security
Spam: Fake dating profile notification
10d ago
Mar 20th, 2026
Sublime Security
Brand Impersonation: Procore
10d ago
Mar 20th, 2026
Sublime Security
Link: PDF display text with fake copyright claim template
12d ago
Mar 18th, 2026
Sublime Security
EML attachment with credential theft language (unknown sender)
13d ago
Mar 17th, 2026
Sublime Security