Detection Method: Natural Language Understanding

Natural Language Understanding (NLU) uses machine learning algorithms to analyze and interpret message content, helping systems detect subtle signs of malicious intent. Instead of just matching keywords, NLU looks at the context, tone, urgency, and intent behind the message.
NLU can help you detect:
  • Urgent language commonly used in BEC attacks impersonating executives or departments
  • Credential theft attempts disguised as legitimate service notifications
  • Extortion or blackmail tactics used in intimidation campaigns
  • Financial terms typically found in payment fraud or invoice scams
  • Deceptive job offers designed to steal sensitive information
For example, NLU can identify when an email uses urgent language ("immediate attention required") combined with financial requests ("wire transfer") and impersonation, which are common tactics in BEC attacks.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Extortion / sextortion (untrusted sender)
14d ago
Dec 19th, 2025
Sublime Security
/feeds/core/detection-rules/extortion-sextortion-untrusted-sender-265913eb
Fake voicemail notification (untrusted sender)
15d ago
Dec 18th, 2025
Sublime Security
/feeds/core/detection-rules/fake-voicemail-notification-untrusted-sender-74ba7787
Xero invoice abuse
16d ago
Dec 17th, 2025
Sublime Security
/feeds/core/detection-rules/xero-invoice-abuse-6538c600
Callback phishing via Microsoft comment
17d ago
Dec 16th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-microsoft-comment-8346c7b9
Salesforce infrastructure abuse
17d ago
Dec 16th, 2025
Sublime Security
/feeds/core/detection-rules/salesforce-infrastructure-abuse-78a77c70
Business Email Compromise: Request for mobile number via reply thread hijacking
18d ago
Dec 15th, 2025
Sublime Security
/feeds/core/detection-rules/business-email-compromise-request-for-mobile-number-via-reply-thread-hijacking-0282f346
Deceptive Dropbox mention
18d ago
Dec 15th, 2025
Sublime Security
/feeds/core/detection-rules/deceptive-dropbox-mention-58a107bc
Credential phishing: Engaging language and other indicators (untrusted sender)
21d ago
Dec 12th, 2025
Sublime Security
/feeds/core/detection-rules/credential-phishing-engaging-language-and-other-indicators-untrusted-sender-c2bc8ca2
Credential phishing: Suspicious subject with urgent financial request and link
21d ago
Dec 12th, 2025
Sublime Security
/feeds/core/detection-rules/credential-phishing-suspicious-subject-with-urgent-financial-request-and-link-056464f4
Brand impersonation: Wise
21d ago
Dec 12th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-wise-01480f95
QR Code with suspicious indicators
21d ago
Dec 12th, 2025
Sublime Security
/feeds/core/detection-rules/qr-code-with-suspicious-indicators-04f5c34f
Link: Self-sender with sender org in subject and credential theft indicator
22d ago
Dec 11th, 2025
Sublime Security
/feeds/core/detection-rules/link-self-sender-with-sender-org-in-subject-and-credential-theft-indicator-bfa9aa08
Scam: Piano giveaway
22d ago
Dec 11th, 2025
Sublime Security
/feeds/core/detection-rules/scam-piano-giveaway-1a91a203
Spam: Website errors solicitation
22d ago
Dec 11th, 2025
Sublime Security
/feeds/core/detection-rules/spam-website-errors-solicitation-122ea794
Attachment: Compensation review lure with QR code
23d ago
Dec 10th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-compensation-review-lure-with-qr-code-9fd8185c
Brand impersonation: Microsoft with low reputation links
23d ago
Dec 10th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-microsoft-with-low-reputation-links-b59201b6
Fake thread with suspicious indicators
24d ago
Dec 9th, 2025
Sublime Security
/feeds/core/detection-rules/fake-thread-with-suspicious-indicators-c2e18a57
Credential phishing: Generic document sharing
25d ago
Dec 8th, 2025
Sublime Security
/feeds/core/detection-rules/credential-phishing-generic-document-sharing-9f0e1d2c
Link: Microsoft Dynamics 365 form phishing
28d ago
Dec 5th, 2025
Sublime Security
/feeds/core/detection-rules/link-microsoft-dynamics-365-form-phishing-f72b9085
Service abuse: Sendgrid credential theft with personalized request targeting single recipient
29d ago
Dec 4th, 2025
Sublime Security
/feeds/core/detection-rules/service-abuse-sendgrid-credential-theft-with-personalized-request-targeting-single-recipient-b9680da1