Detection Method: Content analysis

Content analysis looks at the language and structure of a message to identify signs of phishing, social engineering, and other malicious intent. Instead of scanning for keywords, this method uses natural language understanding (NLU) to detect meaning, intent, and tone across the message.
Content analysis helps detect:
  • BEC attempts with urgent messages from executive impersonators
  • Credential phishing disguised as login or document notifications
  • Callback scams posing as account renewals or fake support
  • Extortion threats or blackmail messages
  • Financial or personal data requests in suspicious contexts
  • Fake job offers targeting employees
  • Invoice fraud, payroll fraud, and more
For example, a phishing email may impersonate a CFO asking for a wire transfer. Content analysis can flag the urgent tone, financial context, and impersonation attempt.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Link: Personal SharePoint with invalid recipients and credential theft language
16m ago
Jan 23rd, 2026
Sublime Security
/feeds/core/detection-rules/link-personal-sharepoint-with-invalid-recipients-and-credential-theft-language-79d5403d
Brand impersonation: File sharing notification with template artifacts
16m ago
Jan 23rd, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-file-sharing-notification-with-template-artifacts-37d89611
Link: Tycoon2FA phishing kit (non-exhaustive)
12h ago
Jan 23rd, 2026
Sublime Security
/feeds/core/detection-rules/link-tycoon2fa-phishing-kit-non-exhaustive-a070d4e2
Service abuse: Adobe legitimate domain with document approval language
15h ago
Jan 23rd, 2026
Sublime Security
/feeds/core/detection-rules/service-abuse-adobe-legitimate-domain-with-document-approval-language-237f4da4
Extortion / sextortion (untrusted sender)
20h ago
Jan 22nd, 2026
Sublime Security
/feeds/core/detection-rules/extortion-sextortion-untrusted-sender-265913eb
Link: Suspicious URL with recipient targeting and special characters
21h ago
Jan 22nd, 2026
Sublime Security
/feeds/core/detection-rules/link-suspicious-url-with-recipient-targeting-and-special-characters-e808be3a
BEC/Fraud: Romance scam
23h ago
Jan 22nd, 2026
Sublime Security
/feeds/core/detection-rules/becfraud-romance-scam-0243cdaa
Fake voicemail notification (untrusted sender)
1d ago
Jan 22nd, 2026
Sublime Security
/feeds/core/detection-rules/fake-voicemail-notification-untrusted-sender-74ba7787
Service abuse: Microsoft Power BI callback scam
1d ago
Jan 22nd, 2026
Sublime Security
/feeds/core/detection-rules/service-abuse-microsoft-power-bi-callback-scam-7a55388e
Brand impersonation: Dropbox
1d ago
Jan 22nd, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-dropbox-61f11d12
Callback phishing in body or attachment (untrusted sender)
1d ago
Jan 22nd, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-in-body-or-attachment-untrusted-sender-b93c6f94
Brand impersonation: AuthentiSign
2d ago
Jan 21st, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-authentisign-445a8c8b
Attachment: Invoice and W-9 PDFs with suspicious creators
2d ago
Jan 21st, 2026
Sublime Security
/feeds/core/detection-rules/attachment-invoice-and-w-9-pdfs-with-suspicious-creators-305d6e32
Link: Display text with excessive right-to-left mark characters
2d ago
Jan 21st, 2026
Sublime Security
/feeds/core/detection-rules/link-display-text-with-excessive-right-to-left-mark-characters-a45cfd4c
Link: Self-sent message with quarterly document review request
2d ago
Jan 21st, 2026
Sublime Security
/feeds/core/detection-rules/link-self-sent-message-with-quarterly-document-review-request-3c42cec6
Job scam with specific salary pattern
2d ago
Jan 21st, 2026
Sublime Security
/feeds/core/detection-rules/job-scam-with-specific-salary-pattern-af7f9e21
Brand impersonation: Fake Fax
2d ago
Jan 21st, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-fake-fax-2a96b90a
Link: Excessive URL rewrite encoders
2d ago
Jan 21st, 2026
Sublime Security
/feeds/core/detection-rules/link-excessive-url-rewrite-encoders-b88e53a7
Brand impersonation: USPS
3d ago
Jan 20th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-usps-28b9130a
Impersonation: Internal corporate services
3d ago
Jan 20th, 2026
Sublime Security
/feeds/core/detection-rules/impersonation-internal-corporate-services-3cd04f33