Detection Method: Natural Language Understanding

Natural Language Understanding (NLU) uses machine learning algorithms to analyze and interpret message content, helping systems detect subtle signs of malicious intent. Instead of just matching keywords, NLU looks at the context, tone, urgency, and intent behind the message.
NLU can help you detect:
  • Urgent language commonly used in BEC attacks impersonating executives or departments
  • Credential theft attempts disguised as legitimate service notifications
  • Extortion or blackmail tactics used in intimidation campaigns
  • Financial terms typically found in payment fraud or invoice scams
  • Deceptive job offers designed to steal sensitive information
For example, NLU can identify when an email uses urgent language ("immediate attention required") combined with financial requests ("wire transfer") and impersonation, which are common tactics in BEC attacks.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Brand impersonation: USPS
14h ago
Jun 1st, 2026
Sublime Security
Brand impersonation: Sharepoint
14h ago
Jun 1st, 2026
Sublime Security
Reconnaissance: Short generic greeting message
4d ago
May 29th, 2026
Sublime Security
Spam: Website errors solicitation
4d ago
May 29th, 2026
Sublime Security
Credential phishing: Engaging language and other indicators (untrusted sender)
4d ago
May 29th, 2026
Sublime Security
Impersonation Link: Cloud branding service with credential theft language
4d ago
May 29th, 2026
Sublime Security
Attachment: Compensation-themed DOCX with QR code credential theft
4d ago
May 29th, 2026
Sublime Security
Business Email Compromise: Request for mobile number via reply thread hijacking
5d ago
May 28th, 2026
Sublime Security
Link: Self-sender credential theft with configuration placeholder
6d ago
May 27th, 2026
Sublime Security
Business Email Compromise (BEC) with request for mobile number
7d ago
May 26th, 2026
Sublime Security
Credential phishing: Onedrive impersonation
7d ago
May 26th, 2026
Sublime Security
Credential phishing: Generic document sharing
11d ago
May 22nd, 2026
Sublime Security
Service abuse: Elastic alerts extortion
12d ago
May 21st, 2026
Sublime Security
Headers: X-Source-Auth mismatch with mismatched reply-to domain
12d ago
May 21st, 2026
Sublime Security
Service abuse: Calendly callback scam detection
12d ago
May 21st, 2026
Sublime Security
Extortion / sextortion (untrusted sender)
13d ago
May 20th, 2026
Sublime Security
Fake thread with suspicious indicators
14d ago
May 19th, 2026
Sublime Security
Advance Fee Fraud (AFF) from freemail provider or suspicious TLD
15d ago
May 18th, 2026
Sublime Security
X (Twitter) impersonation with credential phishing motives
18d ago
May 15th, 2026
Sublime Security
Attachment: Microsoft impersonation via PDF with link and suspicious language
19d ago
May 14th, 2026
Sublime Security