Detection Method: Content analysis

Content analysis looks at the language and structure of a message to identify signs of phishing, social engineering, and other malicious intent. Instead of scanning for keywords, this method uses natural language understanding (NLU) to detect meaning, intent, and tone across the message.
Content analysis helps detect:
  • BEC attempts with urgent messages from executive impersonators
  • Credential phishing disguised as login or document notifications
  • Callback scams posing as account renewals or fake support
  • Extortion threats or blackmail messages
  • Financial or personal data requests in suspicious contexts
  • Fake job offers targeting employees
  • Invoice fraud, payroll fraud, and more
For example, a phishing email may impersonate a CFO asking for a wire transfer. Content analysis can flag the urgent tone, financial context, and impersonation attempt.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Service abuse: Demio notifications with suspicious content patterns
22h ago
May 11th, 2026
Sublime Security
Benefits enrollment impersonation
22h ago
May 11th, 2026
Sublime Security
Investor solicitation with organization targeting
4d ago
May 8th, 2026
Sublime Security
Brand impersonation: Quickbooks
4d ago
May 8th, 2026
Sublime Security
Service abuse: Microsoft with suspicious indicators in subject
5d ago
May 7th, 2026
Sublime Security
Attachment: Suspicious PDF created with headless browser
5d ago
May 7th, 2026
Sublime Security
Observed IOC: Malicious domains in body links
5d ago
May 7th, 2026
Sublime Security
Brand Impersonation: PayPal
5d ago
May 7th, 2026
Sublime Security
Spam: Website errors solicitation
5d ago
May 7th, 2026
Sublime Security
Business Email Compromise (BEC) with request for mobile number
5d ago
May 7th, 2026
Sublime Security
Service abuse: Dropbox Paper with copy-paste instructions
5d ago
May 7th, 2026
Sublime Security
Link: Cloud service with credential theft language
6d ago
May 6th, 2026
Sublime Security
Suspicious newly registered reply-to domain with engaging financial or urgent language
6d ago
May 6th, 2026
Sublime Security
Service Abuse: Zoom with freemail reply-to and recipient address in greeting
6d ago
May 6th, 2026
Sublime Security
Link: Romance/Sexual Language With Suspicious Link
7d ago
May 5th, 2026
Sublime Security
Brand impersonation: DocuSign with embedded QR code
8d ago
May 4th, 2026
Sublime Security
BEC/Fraud: Student loan callback phishing
8d ago
May 4th, 2026
Sublime Security
Callback phishing via Zelle Service Abuse
8d ago
May 4th, 2026
Sublime Security
Callback phishing via Intuit service abuse
8d ago
May 4th, 2026
Sublime Security
Impersonation: Suspected supplier impersonation with suspicious content
8d ago
May 4th, 2026
Sublime Security