Detection Method: Content analysis

Content analysis looks at the language and structure of a message to identify signs of phishing, social engineering, and other malicious intent. Instead of scanning for keywords, this method uses natural language understanding (NLU) to detect meaning, intent, and tone across the message.
Content analysis helps detect:
  • BEC attempts with urgent messages from executive impersonators
  • Credential phishing disguised as login or document notifications
  • Callback scams posing as account renewals or fake support
  • Extortion threats or blackmail messages
  • Financial or personal data requests in suspicious contexts
  • Fake job offers targeting employees
  • Invoice fraud, payroll fraud, and more
For example, a phishing email may impersonate a CFO asking for a wire transfer. Content analysis can flag the urgent tone, financial context, and impersonation attempt.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Brand impersonation: Robinhood
19m ago
Aug 27th, 2026
Sublime Security
Impersonation: SAM/SBA federal registration
19m ago
Aug 27th, 2026
Sublime Security
Attachment: ICS invite meeting lure
1h ago
Aug 27th, 2026
Sublime Security
Brand impersonation: McAfee
1h ago
Aug 27th, 2026
Sublime Security
Link: Microsoft protected message with suspicious recipient patterns
2h ago
Aug 27th, 2026
Sublime Security
Body: HTML whitespace stuffing with short initial message
2h ago
Aug 27th, 2026
Sublime Security
Brand impersonation: Microsoft with low reputation links
4h ago
Aug 27th, 2026
Sublime Security
Body: CSS clamp() font obfuscation with suspicious URL
20h ago
Aug 26th, 2026
Sublime Security
Attachment: PDF Grant Payment lure with embedded link
21h ago
Aug 26th, 2026
Sublime Security
ClickFix: Clipboard hijack lure with copy-paste-to-terminal instruction
1d ago
Aug 26th, 2026
Sublime Security
BEC/Fraud: Self-addressed reply with unrelated link in ongoing thread
1d ago
Aug 26th, 2026
Sublime Security
Link: Self-sender with sender org in subject and credential theft indicator
2d ago
Aug 25th, 2026
Sublime Security
Link: Fake RFP/bid reference number lure
2d ago
Aug 25th, 2026
Sublime Security
Business Email Compromise (BEC) with request for mobile number
2d ago
Aug 25th, 2026
Sublime Security
Business Email Compromise: Request for mobile number via reply thread hijacking
2d ago
Aug 25th, 2026
Sublime Security
Brand impersonation: Automobile assistance associations
2d ago
Aug 25th, 2026
Sublime Security
Attachment: Invoice and W-9 PDFs with suspicious creators
2d ago
Aug 25th, 2026
Sublime Security
Attachment: ICS calendar invite with bid/RFP lure and suspicious link
2d ago
Aug 25th, 2026
Sublime Security
Link: Credential harvesting with excess padding evasion
2d ago
Aug 25th, 2026
Sublime Security
Brand impersonation: AARP
2d ago
Aug 25th, 2026
Sublime Security