Detection Method: Natural Language Understanding

Natural Language Understanding (NLU) uses machine learning algorithms to analyze and interpret message content, helping systems detect subtle signs of malicious intent. Instead of just matching keywords, NLU looks at the context, tone, urgency, and intent behind the message.
NLU can help you detect:
  • Urgent language commonly used in BEC attacks impersonating executives or departments
  • Credential theft attempts disguised as legitimate service notifications
  • Extortion or blackmail tactics used in intimidation campaigns
  • Financial terms typically found in payment fraud or invoice scams
  • Deceptive job offers designed to steal sensitive information
For example, NLU can identify when an email uses urgent language ("immediate attention required") combined with financial requests ("wire transfer") and impersonation, which are common tactics in BEC attacks.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Credential phishing: 'Secure message' and engaging language
5d ago
Apr 15th, 2026
Sublime Security
Brand impersonation: Amazon with suspicious attachment
6d ago
Apr 14th, 2026
Sublime Security
Advance Fee Fraud (AFF) from freemail provider or suspicious TLD
6d ago
Apr 14th, 2026
Sublime Security
Spam: Website errors solicitation
6d ago
Apr 14th, 2026
Sublime Security
Attachment: Compensation review lure with QR code
6d ago
Apr 14th, 2026
Sublime Security
Brand impersonation: USPS
7d ago
Apr 13th, 2026
Sublime Security
Callback phishing via Microsoft comment
7d ago
Apr 13th, 2026
Sublime Security
Attachment: PDF with credential theft language and invalid reply-to domain
10d ago
Apr 10th, 2026
Sublime Security
Cloud storage impersonation with credential theft indicators
11d ago
Apr 9th, 2026
Sublime Security
Brand impersonation: McAfee
11d ago
Apr 9th, 2026
Sublime Security
Attachment: Encrypted PDF with credential theft body
11d ago
Apr 9th, 2026
Sublime Security
Callback phishing via Apple ID display name abuse
12d ago
Apr 8th, 2026
Sublime Security
Attachment: Calendar invite with Google redirect and invoice request
12d ago
Apr 8th, 2026
Sublime Security
QR Code with suspicious indicators
14d ago
Apr 6th, 2026
Sublime Security
Brand impersonation: Toronto-Dominion Bank
17d ago
Apr 3rd, 2026
Sublime Security
Attachment: Legal themed message or PDF with suspicious indicators
17d ago
Apr 3rd, 2026
Sublime Security
Attachment: Cold outreach with invitation subject and not attachment
17d ago
Apr 3rd, 2026
Sublime Security
Service abuse: Google Firebase sender address with suspicious content
18d ago
Apr 2nd, 2026
Sublime Security
Credential phishing: Generic document share template
20d ago
Mar 31st, 2026
Sublime Security
Business Email Compromise: Request for mobile number via reply thread hijacking
20d ago
Mar 31st, 2026
Sublime Security