Detection Method: Content analysis

Content analysis looks at the language and structure of a message to identify signs of phishing, social engineering, and other malicious intent. Instead of scanning for keywords, this method uses natural language understanding (NLU) to detect meaning, intent, and tone across the message.
Content analysis helps detect:
  • BEC attempts with urgent messages from executive impersonators
  • Credential phishing disguised as login or document notifications
  • Callback scams posing as account renewals or fake support
  • Extortion threats or blackmail messages
  • Financial or personal data requests in suspicious contexts
  • Fake job offers targeting employees
  • Invoice fraud, payroll fraud, and more
For example, a phishing email may impersonate a CFO asking for a wire transfer. Content analysis can flag the urgent tone, financial context, and impersonation attempt.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Service abuse: DocSend share from an unsolicited reply-to address
5d ago
Jun 18th, 2026
Sublime Security
Body: Fake secure email portal with HTML obfuscation
5d ago
Jun 18th, 2026
Sublime Security
Employee impersonation: Payroll fraud
5d ago
Jun 18th, 2026
Sublime Security
BEC/Fraud: Unsolicited business acquisition offer
5d ago
Jun 18th, 2026
Sublime Security
Brand impersonation: Cloud services with credential theft intent
5d ago
Jun 18th, 2026
Sublime Security
Service abuse: Google Firebase sender address with suspicious content
5d ago
Jun 18th, 2026
Sublime Security
Credential phishing: Fake storage alerts (unsolicited)
5d ago
Jun 18th, 2026
Sublime Security
Brand impersonation: Bids & Tenders
6d ago
Jun 17th, 2026
Sublime Security
Service abuse: Outlook Groups with Google Sites link and evasion tag
6d ago
Jun 17th, 2026
Sublime Security
Brand impersonation: Microsoft
6d ago
Jun 17th, 2026
@amitchell516
Attachment: PDF with a suspicious string and single URL
6d ago
Jun 17th, 2026
Sublime Security
Evasion: Hidden content divs from freemail sender
6d ago
Jun 17th, 2026
Sublime Security
Brand impersonation: Quickbooks
6d ago
Jun 17th, 2026
Sublime Security
Link: Romance/Sexual Language With Suspicious Link
6d ago
Jun 17th, 2026
Sublime Security
Attachment: Encrypted PDF with credential theft body
6d ago
Jun 17th, 2026
Sublime Security
Reconnaissance: Short generic greeting message
6d ago
Jun 17th, 2026
Sublime Security
Brand impersonation: Fake Fax
6d ago
Jun 17th, 2026
Sublime Security
Fake thread with suspicious indicators
6d ago
Jun 17th, 2026
Sublime Security
Brand impersonation: Survey request with credential theft indicators
6d ago
Jun 17th, 2026
Sublime Security
Attachment: PDF file with recipient domain and ATT eCheckRun pattern
7d ago
Jun 16th, 2026
Sublime Security