Detection Method: Content analysis

Content analysis looks at the language and structure of a message to identify signs of phishing, social engineering, and other malicious intent. Instead of scanning for keywords, this method uses natural language understanding (NLU) to detect meaning, intent, and tone across the message.
Content analysis helps detect:
  • BEC attempts with urgent messages from executive impersonators
  • Credential phishing disguised as login or document notifications
  • Callback scams posing as account renewals or fake support
  • Extortion threats or blackmail messages
  • Financial or personal data requests in suspicious contexts
  • Fake job offers targeting employees
  • Invoice fraud, payroll fraud, and more
For example, a phishing email may impersonate a CFO asking for a wire transfer. Content analysis can flag the urgent tone, financial context, and impersonation attempt.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
URL with Unicode U+2044 (⁄) or U+2215 (∕) characters
13h ago
Aug 6th, 2026
@delivr_to
Brand impersonation: SoFi
13h ago
Aug 6th, 2026
Sublime Security
Brand impersonation: Punchbowl
14h ago
Aug 6th, 2026
Sublime Security
Extortion / sextortion in attachment from untrusted sender
22h ago
Aug 6th, 2026
Sublime Security
Spam: Fake photo share
22h ago
Aug 6th, 2026
Sublime Security
BEC: Tax document request
23h ago
Aug 6th, 2026
Sublime Security
Brand impersonation: Cloud services with credential theft intent
23h ago
Aug 6th, 2026
Sublime Security
Callback phishing: Zero-width character obfuscation from freemail sender
2d ago
Aug 5th, 2026
Sublime Security
Body: CSS Hidden text via clip-path
2d ago
Aug 5th, 2026
Sublime Security
Service abuse: Wufoo credential theft
2d ago
Aug 5th, 2026
Sublime Security
Link: Mismatched free file host links with document lure
2d ago
Aug 5th, 2026
Sublime Security
Callback phishing in body or attachment (untrusted sender)
2d ago
Aug 5th, 2026
Sublime Security
Attachment: Callback phishing solicitation via text-based file
2d ago
Aug 5th, 2026
Sublime Security
HTML: Template placeholders or recipient email in element class attributes
2d ago
Aug 5th, 2026
Sublime Security
VIP Impersonation via Google Group relay with suspicious indicators
2d ago
Aug 5th, 2026
Sublime Security
Spam: Cold outreach from Cloudflare-hosted newly registered domain
3d ago
Aug 4th, 2026
Sublime Security
Service abuse: Cognito Forms with short body from unknown sender
3d ago
Aug 4th, 2026
Sublime Security
Brand impersonation: Okta
3d ago
Aug 4th, 2026
Sublime Security
Brand impersonation: SiriusXM
3d ago
Aug 4th, 2026
Sublime Security
Attachment: Targeted DOCX with personalized recipient acknowledgement lure
3d ago
Aug 4th, 2026
Sublime Security