Detection Method: Content analysis

Content analysis looks at the language and structure of a message to identify signs of phishing, social engineering, and other malicious intent. Instead of scanning for keywords, this method uses natural language understanding (NLU) to detect meaning, intent, and tone across the message.
Content analysis helps detect:
  • BEC attempts with urgent messages from executive impersonators
  • Credential phishing disguised as login or document notifications
  • Callback scams posing as account renewals or fake support
  • Extortion threats or blackmail messages
  • Financial or personal data requests in suspicious contexts
  • Fake job offers targeting employees
  • Invoice fraud, payroll fraud, and more
For example, a phishing email may impersonate a CFO asking for a wire transfer. Content analysis can flag the urgent tone, financial context, and impersonation attempt.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: Microsoft OAuth credential harvesting via EML with embedded malicious links
12h ago
Jun 1st, 2026
Sublime Security
Brand impersonation: USPS
14h ago
Jun 1st, 2026
Sublime Security
Brand impersonation: Sharepoint
14h ago
Jun 1st, 2026
Sublime Security
Brand impersonation: Quickbooks
15h ago
Jun 1st, 2026
Sublime Security
Brand Impersonation: PayPal
21h ago
Jun 1st, 2026
Sublime Security
Brand impersonation: Adobe with suspicious language and link
21h ago
Jun 1st, 2026
Sublime Security
Reconnaissance: Short generic greeting message
4d ago
May 29th, 2026
Sublime Security
Spam: Website errors solicitation
4d ago
May 29th, 2026
Sublime Security
Credential phishing: Engaging language and other indicators (untrusted sender)
4d ago
May 29th, 2026
Sublime Security
Body: HTML whitespace stuffing with short initial message
4d ago
May 29th, 2026
Sublime Security
Attachment: ICS calendar file with suspicious product identifier
4d ago
May 29th, 2026
Sublime Security
Impersonation Link: Cloud branding service with credential theft language
4d ago
May 29th, 2026
Sublime Security
Credential phishing: Suspicious e-sign agreement document notification
4d ago
May 29th, 2026
Sublime Security
Attachment: Compensation-themed DOCX with QR code credential theft
4d ago
May 29th, 2026
Sublime Security
Service Abuse: HelloSign share with suspicious sender or document name
5d ago
May 28th, 2026
Sublime Security
Impersonation: Employee using fabricated identity in initial contact
5d ago
May 28th, 2026
Sublime Security
Credential phishing: Fake storage alerts (unsolicited)
5d ago
May 28th, 2026
Sublime Security
Business Email Compromise: Request for mobile number via reply thread hijacking
5d ago
May 28th, 2026
Sublime Security
Credential phishing: AWS Lambda URL with recipient targeting
5d ago
May 28th, 2026
Sublime Security
Link: Self-sender credential theft with configuration placeholder
6d ago
May 27th, 2026
Sublime Security