Detection Method: Content analysis

Content analysis looks at the language and structure of a message to identify signs of phishing, social engineering, and other malicious intent. Instead of scanning for keywords, this method uses natural language understanding (NLU) to detect meaning, intent, and tone across the message.
Content analysis helps detect:
  • BEC attempts with urgent messages from executive impersonators
  • Credential phishing disguised as login or document notifications
  • Callback scams posing as account renewals or fake support
  • Extortion threats or blackmail messages
  • Financial or personal data requests in suspicious contexts
  • Fake job offers targeting employees
  • Invoice fraud, payroll fraud, and more
For example, a phishing email may impersonate a CFO asking for a wire transfer. Content analysis can flag the urgent tone, financial context, and impersonation attempt.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Cloud storage impersonation with credential theft indicators
21h ago
Mar 13th, 2026
Sublime Security
Link: Obfuscation via userinfo with suspicious indicators
21h ago
Mar 13th, 2026
Sublime Security
VIP impersonation with w2 request with reply-to mismatch
2d ago
Mar 12th, 2026
Sublime Security
Link: Microsoft device code authentication with suspicious indicators
2d ago
Mar 12th, 2026
Sublime Security
Service abuse: Google Firebase sender address with suspicious content
2d ago
Mar 12th, 2026
Sublime Security
Brand impersonation: SendGrid
2d ago
Mar 12th, 2026
Sublime Security
BEC/Fraud: Reply-chain manipulation with urgent keywords and self-reply
3d ago
Mar 11th, 2026
Sublime Security
Brand impersonation: McAfee
3d ago
Mar 11th, 2026
Sublime Security
Brand impersonation: GitHub with callback scam indicators
3d ago
Mar 11th, 2026
Sublime Security
Impersonation: Legal firm with copyright infringement notice
4d ago
Mar 10th, 2026
Sublime Security
Spam: Sexually explicit content with emoji in subject from freemail provider
4d ago
Mar 10th, 2026
Sublime Security
BEC/Fraud: Romance scam
5d ago
Mar 9th, 2026
Sublime Security
Service abuse: File sharing impersonation with external SharePoint links
5d ago
Mar 9th, 2026
Sublime Security
Link: Mixed case HTTPS protocol
5d ago
Mar 9th, 2026
Sublime Security
Service abuse: Monday.com infrastructure with phishing intent
5d ago
Mar 9th, 2026
Sublime Security
Credential phishing: Blue button styled link with file-sharing template artifacts
5d ago
Mar 9th, 2026
Sublime Security
Request for Quote or Purchase (RFQ|RFP) with suspicious sender or recipient pattern
5d ago
Mar 9th, 2026
Sublime Security
Service abuse: Vimeo with external plain-text links in message
8d ago
Mar 6th, 2026
Sublime Security
Attachment: PDF with suspicious link and action-oriented language
8d ago
Mar 6th, 2026
Sublime Security
Service abuse: Nylas tracking subdomain with suspicious content
8d ago
Mar 6th, 2026
Sublime Security