Detection Method: Content analysis

Content analysis looks at the language and structure of a message to identify signs of phishing, social engineering, and other malicious intent. Instead of scanning for keywords, this method uses natural language understanding (NLU) to detect meaning, intent, and tone across the message.
Content analysis helps detect:
  • BEC attempts with urgent messages from executive impersonators
  • Credential phishing disguised as login or document notifications
  • Callback scams posing as account renewals or fake support
  • Extortion threats or blackmail messages
  • Financial or personal data requests in suspicious contexts
  • Fake job offers targeting employees
  • Invoice fraud, payroll fraud, and more
For example, a phishing email may impersonate a CFO asking for a wire transfer. Content analysis can flag the urgent tone, financial context, and impersonation attempt.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns
3d ago
Apr 17th, 2026
Sublime Security
Link: WordPress admin targeting with recipient identifier in URL fragment
4d ago
Apr 16th, 2026
Sublime Security
Self-sender with copy/paste instructions and suspicious domains (French/Français)
4d ago
Apr 16th, 2026
Sublime Security
Brand impersonation: Wells Fargo
5d ago
Apr 15th, 2026
Sublime Security
Service abuse: Meetup.com redirect with brand impersonation
5d ago
Apr 15th, 2026
Sublime Security
Advance Fee Fraud (AFF) from freemail provider or suspicious TLD
6d ago
Apr 14th, 2026
Sublime Security
Spam: Website errors solicitation
6d ago
Apr 14th, 2026
Sublime Security
Link: Tax document lure Portuguese/Spanish with suspicious domains
6d ago
Apr 14th, 2026
Sublime Security
Attachment: Fake voicemail via PDF
6d ago
Apr 14th, 2026
Sublime Security
Brand impersonation: USPS
7d ago
Apr 13th, 2026
Sublime Security
Callback phishing via Microsoft comment
7d ago
Apr 13th, 2026
Sublime Security
Attachment: PDF with a suspicious string and single URL
10d ago
Apr 10th, 2026
Sublime Security
Attachment: PDF with credential theft language and invalid reply-to domain
10d ago
Apr 10th, 2026
Sublime Security
Link: Shortened URL with fragment matching subject
11d ago
Apr 9th, 2026
Sublime Security
Cloud storage impersonation with credential theft indicators
11d ago
Apr 9th, 2026
Sublime Security
Brand impersonation: McAfee
11d ago
Apr 9th, 2026
Sublime Security
Attachment: Encrypted PDF with credential theft body
11d ago
Apr 9th, 2026
Sublime Security
Credential Phishing: W-2 lure with inline SVG Windows logo
12d ago
Apr 8th, 2026
Sublime Security
Callback phishing via Apple ID display name abuse
12d ago
Apr 8th, 2026
Sublime Security
Body: PayApp transaction reference pattern
13d ago
Apr 7th, 2026
Sublime Security