Detection Method: Content analysis

Content analysis looks at the language and structure of a message to identify signs of phishing, social engineering, and other malicious intent. Instead of scanning for keywords, this method uses natural language understanding (NLU) to detect meaning, intent, and tone across the message.
Content analysis helps detect:
  • BEC attempts with urgent messages from executive impersonators
  • Credential phishing disguised as login or document notifications
  • Callback scams posing as account renewals or fake support
  • Extortion threats or blackmail messages
  • Financial or personal data requests in suspicious contexts
  • Fake job offers targeting employees
  • Invoice fraud, payroll fraud, and more
For example, a phishing email may impersonate a CFO asking for a wire transfer. Content analysis can flag the urgent tone, financial context, and impersonation attempt.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Brand impersonation: Google Careers
2h ago
Nov 12th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-google-careers-cf2d97ad
VIP Impersonation via Google Group relay with suspicious indicators
3h ago
Nov 12th, 2025
Sublime Security
/feeds/core/detection-rules/vip-impersonation-via-google-group-relay-with-suspicious-indicators-57f9cd3b
Spam: Sexually explicit Google group invitation
3h ago
Nov 12th, 2025
Sublime Security
/feeds/core/detection-rules/spam-sexually-explicit-google-group-invitation-4e0bec29
Fake message thread with a suspicious link and engaging language from an unknown sender
3h ago
Nov 12th, 2025
Sublime Security
/feeds/core/detection-rules/fake-message-thread-with-a-suspicious-link-and-engaging-language-from-an-unknown-sender-8fd0e211
BEC/Fraud: Job scam fake thread or plaintext pivot to freemail
3h ago
Nov 12th, 2025
Sublime Security
/feeds/core/detection-rules/becfraud-job-scam-fake-thread-or-plaintext-pivot-to-freemail-ce21c151
VIP impersonation with charitable donation fraud
3h ago
Nov 12th, 2025
Sublime Security
/feeds/core/detection-rules/vip-impersonation-with-charitable-donation-fraud-35a56b8e
Attachment: PDF with Microsoft Purview message impersonation
2d ago
Nov 10th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-pdf-with-microsoft-purview-message-impersonation-571d4964
Callback phishing in body or attachment (untrusted sender)
4d ago
Nov 8th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-in-body-or-attachment-untrusted-sender-b93c6f94
Attachment: Encrypted PDF with credential theft body
4d ago
Nov 8th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-encrypted-pdf-with-credential-theft-body-c9596c9a
Brand impersonation: Survey request with credential theft indicators
4d ago
Nov 8th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-survey-request-with-credential-theft-indicators-ea1c0e09
Spam: Fake photo share
4d ago
Nov 8th, 2025
Sublime Security
/feeds/core/detection-rules/spam-fake-photo-share-eb086f7d
Brand impersonation: Microsoft with low reputation links
4d ago
Nov 8th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-microsoft-with-low-reputation-links-b59201b6
Credential phishing: Suspicious e-sign agreement document notification
5d ago
Nov 7th, 2025
Sublime Security
/feeds/core/detection-rules/credential-phishing-suspicious-e-sign-agreement-document-notification-9b68c2d8
Brand impersonation: SendGrid
5d ago
Nov 7th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-sendgrid-d800124f
Brand impersonation: Paperless Post
6d ago
Nov 6th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-paperless-post-e9ec5e09
Compensation review with QR code in attached EML
7d ago
Nov 5th, 2025
Sublime Security
/feeds/core/detection-rules/compensation-review-with-qr-code-in-attached-eml-98a2f03c
Brand impersonation: USPS
7d ago
Nov 5th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-usps-28b9130a
Credential theft: Gophish abuse with hidden tracking image
7d ago
Nov 5th, 2025
Sublime Security
/feeds/core/detection-rules/credential-theft-gophish-abuse-with-hidden-tracking-image-59915ceb
Credential phishing: Fake storage alerts (unsolicited)
7d ago
Nov 5th, 2025
Sublime Security
/feeds/core/detection-rules/credential-phishing-fake-storage-alerts-unsolicited-750f04d6
Spam: Mastercard promotional content with image-based body
7d ago
Nov 5th, 2025
Sublime Security
/feeds/core/detection-rules/spam-mastercard-promotional-content-with-image-based-body-5f2cb559