Detection Method: Content analysis

Content analysis looks at the language and structure of a message to identify signs of phishing, social engineering, and other malicious intent. Instead of scanning for keywords, this method uses natural language understanding (NLU) to detect meaning, intent, and tone across the message.
Content analysis helps detect:
  • BEC attempts with urgent messages from executive impersonators
  • Credential phishing disguised as login or document notifications
  • Callback scams posing as account renewals or fake support
  • Extortion threats or blackmail messages
  • Financial or personal data requests in suspicious contexts
  • Fake job offers targeting employees
  • Invoice fraud, payroll fraud, and more
For example, a phishing email may impersonate a CFO asking for a wire transfer. Content analysis can flag the urgent tone, financial context, and impersonation attempt.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: ICS calendar file with suspicious UID domain
4d ago
Sep 4th, 2026
Sublime Security
Attachment: ICS file with excessive custom properties
4d ago
Sep 4th, 2026
Sublime Security
Attachment: ICS calendar file with recipient address in UID field
4d ago
Sep 4th, 2026
Sublime Security
Brand impersonation: MyChart
4d ago
Sep 4th, 2026
Sublime Security
Attachment: Encrypted PDF with credential theft body
4d ago
Sep 4th, 2026
Sublime Security
Attachment: Encrypted PDF with credential theft language in EML
4d ago
Sep 4th, 2026
Sublime Security
Observed IOC: Malicious domains in body links
4d ago
Sep 4th, 2026
Sublime Security
Observed IOC: Malicious root domains in body links
4d ago
Sep 4th, 2026
Sublime Security
Credential phishing: Suspicious e-sign agreement document notification
4d ago
Sep 4th, 2026
Sublime Security
Brand impersonation: AARP
4d ago
Sep 4th, 2026
Sublime Security
Credential phishing: Engaging language and other indicators (untrusted sender)
4d ago
Sep 4th, 2026
Sublime Security
Impersonation: SAM/SBA federal registration
4d ago
Sep 4th, 2026
Sublime Security
Brand impersonation: Cloud services with credential theft intent
5d ago
Sep 3rd, 2026
Sublime Security
Attachment: ICS calendar invite with bid/RFP lure and suspicious link
5d ago
Sep 3rd, 2026
Sublime Security
Body: CSS Hidden text via table-column
5d ago
Sep 3rd, 2026
Sublime Security
Brand impersonation: USPS
6d ago
Sep 2nd, 2026
Sublime Security
Attachment: ICS voicemail lure with suspicious link
6d ago
Sep 2nd, 2026
Sublime Security
Business Email Compromise (BEC) with request for mobile number
6d ago
Sep 2nd, 2026
Sublime Security
Observed IOC: Malicious URLs in body links
6d ago
Sep 2nd, 2026
Sublime Security
Open redirect: Generic link.html redirector abuse
7d ago
Sep 1st, 2026
Sublime Security