Detection Method: Content analysis

Content analysis looks at the language and structure of a message to identify signs of phishing, social engineering, and other malicious intent. Instead of scanning for keywords, this method uses natural language understanding (NLU) to detect meaning, intent, and tone across the message.
Content analysis helps detect:
  • BEC attempts with urgent messages from executive impersonators
  • Credential phishing disguised as login or document notifications
  • Callback scams posing as account renewals or fake support
  • Extortion threats or blackmail messages
  • Financial or personal data requests in suspicious contexts
  • Fake job offers targeting employees
  • Invoice fraud, payroll fraud, and more
For example, a phishing email may impersonate a CFO asking for a wire transfer. Content analysis can flag the urgent tone, financial context, and impersonation attempt.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: ICS voicemail lure with suspicious link
1h ago
Sep 16th, 2026
Sublime Security
Attachment: PDF with a suspicious string and single URL
2h ago
Sep 16th, 2026
Sublime Security
Suspicious message with unscannable Cloudflare link
4h ago
Sep 16th, 2026
Sublime Security
Suspicious attachment with unscannable Cloudflare link
4h ago
Sep 16th, 2026
Sublime Security
Brand impersonation: Social Security Administration
6h ago
Sep 16th, 2026
Sublime Security
Attachment: ICS calendar invite with bid/RFP lure and suspicious link
22h ago
Sep 15th, 2026
Sublime Security
Link: Possible Intuit link abuse
22h ago
Sep 15th, 2026
Sublime Security
Brand impersonation: Kroger
1d ago
Sep 15th, 2026
Sublime Security
Attachment: Legal themed message or PDF with suspicious indicators
1d ago
Sep 15th, 2026
Sublime Security
Link: Abused Trac-link URL
2d ago
Sep 14th, 2026
Sublime Security
Link: Google share.google URL shortener in google.<tld>/share.google path form
2d ago
Sep 14th, 2026
Sublime Security
Attachment: ICS calendar invite with Google share.google URL shortener in google.<tld>/share.google path form
2d ago
Sep 14th, 2026
Sublime Security
Attachment: Google share.google URL shortener in google.<tld>/share.google path form
2d ago
Sep 14th, 2026
Sublime Security
Credential phishing: Generic document sharing
2d ago
Sep 14th, 2026
Sublime Security
BEC/Fraud: Fake investment outreach from suspicious TLD
2d ago
Sep 14th, 2026
Sublime Security
Spam: Fake photo share
5d ago
Sep 11th, 2026
Sublime Security
Link: ScreenConnect remote access tool delivery with unattended guest access
5d ago
Sep 11th, 2026
Sublime Security
Brand impersonation: Survey request with credential theft indicators
5d ago
Sep 11th, 2026
Sublime Security
Attachment: Excel file with hyperlinks to suspicious domains
5d ago
Sep 11th, 2026
Sublime Security
Link: Fake Cloudflare verification landing page
5d ago
Sep 11th, 2026
Sublime Security