Detection Method: Content analysis

Content analysis looks at the language and structure of a message to identify signs of phishing, social engineering, and other malicious intent. Instead of scanning for keywords, this method uses natural language understanding (NLU) to detect meaning, intent, and tone across the message.
Content analysis helps detect:
  • BEC attempts with urgent messages from executive impersonators
  • Credential phishing disguised as login or document notifications
  • Callback scams posing as account renewals or fake support
  • Extortion threats or blackmail messages
  • Financial or personal data requests in suspicious contexts
  • Fake job offers targeting employees
  • Invoice fraud, payroll fraud, and more
For example, a phishing email may impersonate a CFO asking for a wire transfer. Content analysis can flag the urgent tone, financial context, and impersonation attempt.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
BEC/Fraud: Fake investment outreach from suspicious TLD
38m ago
Oct 6th, 2026
Sublime Security
Fake voicemail notification (untrusted sender)
1h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage /index and /unsub link pair
4h ago
Oct 6th, 2026
Sublime Security
Link: Malformed subdomain ending in hyphen
5h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage with short-path link delivery
5h ago
Oct 6th, 2026
Sublime Security
Service Abuse: American Express callback scam
5h ago
Oct 6th, 2026
Sublime Security
Link: Observed URL path (lht) with recipient email address
5h ago
Oct 6th, 2026
Sublime Security
Service abuse: Lovable-hosted redirect to external phishing page
6h ago
Oct 6th, 2026
Sublime Security
Attachment: Excel file with hyperlinks to suspicious domains
6h ago
Oct 6th, 2026
Sublime Security
Observed IOC: Malicious domains in body links
6h ago
Oct 6th, 2026
Sublime Security
Link: Possible Intuit link abuse
1d ago
Oct 5th, 2026
Sublime Security
Observed IOC: Malicious root domains in body links
1d ago
Oct 5th, 2026
Sublime Security
Attachment: Microsoft OAuth credential harvesting via EML with embedded malicious links
2d ago
Oct 4th, 2026
Sublime Security
Credential phishing: Generic document sharing
2d ago
Oct 4th, 2026
Sublime Security
Attachment: ICS with Suspicious Office 365 app authorization (OAuth) link
2d ago
Oct 4th, 2026
Sublime Security
Attachment: Suspicious use of Unicode tag characters in ICS File
2d ago
Oct 4th, 2026
Sublime Security
Evasion: Suspicious use of Unicode tag characters
2d ago
Oct 4th, 2026
Sublime Security
Service abuse: Microsoft Power Apps callback scam
4d ago
Oct 2nd, 2026
Sublime Security
Spam: Fake photo share
4d ago
Oct 2nd, 2026
Sublime Security
Body: Bid solicitation PDF lure
4d ago
Oct 2nd, 2026
Sublime Security