Detection Method: Natural Language Understanding

Natural Language Understanding (NLU) uses machine learning algorithms to analyze and interpret message content, helping systems detect subtle signs of malicious intent. Instead of just matching keywords, NLU looks at the context, tone, urgency, and intent behind the message.
NLU can help you detect:
  • Urgent language commonly used in BEC attacks impersonating executives or departments
  • Credential theft attempts disguised as legitimate service notifications
  • Extortion or blackmail tactics used in intimidation campaigns
  • Financial terms typically found in payment fraud or invoice scams
  • Deceptive job offers designed to steal sensitive information
For example, NLU can identify when an email uses urgent language ("immediate attention required") combined with financial requests ("wire transfer") and impersonation, which are common tactics in BEC attacks.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Link: Figma design deck with credential theft language
13h ago
Mar 4th, 2026
Sublime Security
/feeds/core/detection-rules/link-figma-design-deck-with-credential-theft-language-87601924
Brand Impersonation: Disney
17h ago
Mar 4th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-disney-bf90b8fb
BEC with unusual reply-to or return-path mismatch
2d ago
Mar 3rd, 2026
Sublime Security
/feeds/core/detection-rules/bec-with-unusual-reply-to-or-return-path-mismatch-83e5e2df
Link: Google Forms link with credential theft language
3d ago
Mar 2nd, 2026
Sublime Security
/feeds/core/detection-rules/link-google-forms-link-with-credential-theft-language-0cad40e2
VIP impersonation with w2 request with reply-to mismatch
6d ago
Feb 27th, 2026
Sublime Security
/feeds/core/detection-rules/vip-impersonation-with-w2-request-with-reply-to-mismatch-e7e73fad
Attachment: Encrypted PDF with credential theft body
7d ago
Feb 26th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-encrypted-pdf-with-credential-theft-body-c9596c9a
Credential theft with 'safe content' deception and social engineering topics
8d ago
Feb 25th, 2026
Sublime Security
/feeds/core/detection-rules/credential-theft-with-safe-content-deception-and-social-engineering-topics-22ceee0d
Spam: Sendersrv.com with financial communications and unsubscribe language
9d ago
Feb 24th, 2026
Sublime Security
/feeds/core/detection-rules/spam-sendersrvcom-with-financial-communications-and-unsubscribe-language-69570820
Link: Free file hosting with undisclosed recipients
10d ago
Feb 23rd, 2026
Sublime Security
/feeds/core/detection-rules/link-free-file-hosting-with-undisclosed-recipients-b6281306
Brand impersonation: Survey request with credential theft indicators
13d ago
Feb 20th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-survey-request-with-credential-theft-indicators-ea1c0e09
Cloud storage impersonation with credential theft indicators
13d ago
Feb 20th, 2026
Sublime Security
/feeds/core/detection-rules/cloud-storage-impersonation-with-credential-theft-indicators-4c20f72c
Impersonation: Recipient organization in sender display name with credential theft image
16d ago
Feb 17th, 2026
Sublime Security
/feeds/core/detection-rules/impersonation-recipient-organization-in-sender-display-name-with-credential-theft-image-6abfb20e
Credential phishing: Generic document sharing
19d ago
Feb 14th, 2026
Sublime Security
/feeds/core/detection-rules/credential-phishing-generic-document-sharing-9f0e1d2c
Brand impersonation: USPS
20d ago
Feb 13th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-usps-28b9130a
Link: Credential theft with invisible Unicode character in page title from unsolicited sender
20d ago
Feb 13th, 2026
Sublime Security
/feeds/core/detection-rules/link-credential-theft-with-invisible-unicode-character-in-page-title-from-unsolicited-sender-5fe14d53
Brand impersonation: TikTok
21d ago
Feb 12th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-tiktok-aaacc8b7
Link: PDF filename impersonation with credential theft language
21d ago
Feb 12th, 2026
Sublime Security
/feeds/core/detection-rules/link-pdf-filename-impersonation-with-credential-theft-language-05931513
Brand impersonation: Navan
24d ago
Feb 9th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-navan-3573e9a8
Link: URL shortener with copy-paste instructions and credential theft language
27d ago
Feb 6th, 2026
Sublime Security
/feeds/core/detection-rules/link-url-shortener-with-copy-paste-instructions-and-credential-theft-language-a0a2c573
Service abuse: Apple TestFlight with suspicious developer reference
27d ago
Feb 6th, 2026
Sublime Security
/feeds/core/detection-rules/service-abuse-apple-testflight-with-suspicious-developer-reference-e7ea0ee0