Detection Method: Natural Language Understanding

Natural Language Understanding (NLU) uses machine learning algorithms to analyze and interpret message content, helping systems detect subtle signs of malicious intent. Instead of just matching keywords, NLU looks at the context, tone, urgency, and intent behind the message.
NLU can help you detect:
  • Urgent language commonly used in BEC attacks impersonating executives or departments
  • Credential theft attempts disguised as legitimate service notifications
  • Extortion or blackmail tactics used in intimidation campaigns
  • Financial terms typically found in payment fraud or invoice scams
  • Deceptive job offers designed to steal sensitive information
For example, NLU can identify when an email uses urgent language ("immediate attention required") combined with financial requests ("wire transfer") and impersonation, which are common tactics in BEC attacks.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Credential phishing: 'Secure message' and engaging language
3d ago
Mar 27th, 2026
Sublime Security
Attachment: PDF bid/proposal lure with credential theft indicators
3d ago
Mar 27th, 2026
Sublime Security
Credential phishing: Financial lure via ActiveCampaign infrastructure
3d ago
Mar 27th, 2026
Sublime Security
Callback phishing in body or attachment (untrusted sender)
3d ago
Mar 27th, 2026
Sublime Security
Business Email Compromise (BEC) with request for mobile number
4d ago
Mar 26th, 2026
Sublime Security
Service abuse: AWS SNS callback scam impersonation
4d ago
Mar 26th, 2026
Sublime Security
Callback phishing via Microsoft comment
4d ago
Mar 26th, 2026
Sublime Security
VIP impersonation with urgent request (strict match, untrusted sender)
5d ago
Mar 25th, 2026
Sublime Security
VIP impersonation with BEC language (near match, untrusted sender)
5d ago
Mar 25th, 2026
Sublime Security
Brand impersonation: USPS
5d ago
Mar 25th, 2026
Sublime Security
Credential phishing: Fake card notification with tracking lure
6d ago
Mar 24th, 2026
Sublime Security
Link: Financial account issue with suspicious indicators
6d ago
Mar 24th, 2026
Sublime Security
Cloud storage impersonation with credential theft indicators
7d ago
Mar 23rd, 2026
Sublime Security
Credential phishing: Suspicious subject with urgent financial request and link
7d ago
Mar 23rd, 2026
Sublime Security
Spam: Fake dating profile notification
10d ago
Mar 20th, 2026
Sublime Security
Link: Free file hosting with undisclosed recipients
11d ago
Mar 19th, 2026
Sublime Security
Service abuse: Substack credential theft with confusable characters and branded button redirects
11d ago
Mar 19th, 2026
Sublime Security
EML attachment with credential theft language (unknown sender)
13d ago
Mar 17th, 2026
Sublime Security
Attachment: PDF proposal with credential theft indicators
13d ago
Mar 17th, 2026
Sublime Security
Service abuse: Google Calendar notification with callback scam language
14d ago
Mar 16th, 2026
Sublime Security