Detection Method: Natural Language Understanding

Natural Language Understanding (NLU) uses machine learning algorithms to analyze and interpret message content, helping systems detect subtle signs of malicious intent. Instead of just matching keywords, NLU looks at the context, tone, urgency, and intent behind the message.
NLU can help you detect:
  • Urgent language commonly used in BEC attacks impersonating executives or departments
  • Credential theft attempts disguised as legitimate service notifications
  • Extortion or blackmail tactics used in intimidation campaigns
  • Financial terms typically found in payment fraud or invoice scams
  • Deceptive job offers designed to steal sensitive information
For example, NLU can identify when an email uses urgent language ("immediate attention required") combined with financial requests ("wire transfer") and impersonation, which are common tactics in BEC attacks.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Suspicious attachment with unscannable Cloudflare link
4h ago
Sep 16th, 2026
Sublime Security
Link: Possible Intuit link abuse
22h ago
Sep 15th, 2026
Sublime Security
Brand impersonation: Kroger
1d ago
Sep 15th, 2026
Sublime Security
Attachment: Legal themed message or PDF with suspicious indicators
1d ago
Sep 15th, 2026
Sublime Security
BEC/Fraud: Fake investment outreach from suspicious TLD
2d ago
Sep 14th, 2026
Sublime Security
Credential phishing: Generic document sharing
2d ago
Sep 14th, 2026
Sublime Security
Brand impersonation: Survey request with credential theft indicators
5d ago
Sep 11th, 2026
Sublime Security
Attachment: Excel file with hyperlinks to suspicious domains
5d ago
Sep 11th, 2026
Sublime Security
Brand impersonation: USPS
6d ago
Sep 10th, 2026
Sublime Security
Business Email Compromise: Request for mobile number via reply thread hijacking
6d ago
Sep 10th, 2026
Sublime Security
Attachment: ICS calendar invite with photo/file share lure
7d ago
Sep 9th, 2026
Sublime Security
Brand impersonation: Morgan Stanley
8d ago
Sep 8th, 2026
Sublime Security
BEC: Wealth management lure from newly registered domain
8d ago
Sep 8th, 2026
Sublime Security
Attachment: Word document with hyperlink and fraud language
12d ago
Sep 4th, 2026
Sublime Security
Brand impersonation: MyChart
12d ago
Sep 4th, 2026
Sublime Security
Attachment: Encrypted PDF with credential theft language in EML
12d ago
Sep 4th, 2026
Sublime Security
Attachment: Encrypted PDF with credential theft body
12d ago
Sep 4th, 2026
Sublime Security
Callback Scam: Outlook groups
12d ago
Sep 4th, 2026
Sublime Security
Attachment: ICS file with credential theft indicators
12d ago
Sep 4th, 2026
Sublime Security
Credential phishing: Engaging language and other indicators (untrusted sender)
12d ago
Sep 4th, 2026
Sublime Security