Detection Method: Natural Language Understanding

Natural Language Understanding (NLU) uses machine learning algorithms to analyze and interpret message content, helping systems detect subtle signs of malicious intent. Instead of just matching keywords, NLU looks at the context, tone, urgency, and intent behind the message.
NLU can help you detect:
  • Urgent language commonly used in BEC attacks impersonating executives or departments
  • Credential theft attempts disguised as legitimate service notifications
  • Extortion or blackmail tactics used in intimidation campaigns
  • Financial terms typically found in payment fraud or invoice scams
  • Deceptive job offers designed to steal sensitive information
For example, NLU can identify when an email uses urgent language ("immediate attention required") combined with financial requests ("wire transfer") and impersonation, which are common tactics in BEC attacks.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
BEC/Fraud: Fake investment outreach from suspicious TLD
39m ago
Oct 6th, 2026
Sublime Security
Fake voicemail notification (untrusted sender)
1h ago
Oct 6th, 2026
Sublime Security
Spoofing: Hidden Outlook headers in self-addressed forwards
4h ago
Oct 6th, 2026
Sublime Security
Service abuse: Google callback scam
4h ago
Oct 6th, 2026
Sublime Security
Service Abuse: American Express callback scam
5h ago
Oct 6th, 2026
Sublime Security
Attachment: Excel file with hyperlinks to suspicious domains
6h ago
Oct 6th, 2026
Sublime Security
Link: Possible Intuit link abuse
1d ago
Oct 5th, 2026
Sublime Security
Attachment: Fake email body embedded in inline image
1d ago
Oct 5th, 2026
Sublime Security
Credential phishing: Generic document sharing
2d ago
Oct 4th, 2026
Sublime Security
Service abuse: Microsoft Power Apps callback scam
4d ago
Oct 2nd, 2026
Sublime Security
Brand impersonation: Google Authenticator
4d ago
Oct 2nd, 2026
Sublime Security
Business Email Compromise: Request for mobile number via reply thread hijacking
4d ago
Oct 2nd, 2026
Sublime Security
Attachment: Fictitious invoice using LinkedIn's address
5d ago
Oct 1st, 2026
Sublime Security
Evasion: Credential phishing with newly registered domain redirecting to Wikipedia
5d ago
Oct 1st, 2026
Sublime Security
Attachment: PDF credential phishing via wkhtmltopdf/Qt with suspicious link
5d ago
Oct 1st, 2026
Sublime Security
Credential phishing: Email delivery failure impersonation
5d ago
Oct 1st, 2026
Sublime Security
Credential phishing: Engaging language and other indicators (untrusted sender)
5d ago
Oct 1st, 2026
Sublime Security
Service abuse: Apple callback scam
7d ago
Sep 29th, 2026
Sublime Security
Credential phishing language and suspicious indicators (unknown sender)
7d ago
Sep 29th, 2026
Sublime Security
Attachment: RFC822 containing suspicious file sharing language with links from untrusted sender
7d ago
Sep 29th, 2026
Sublime Security