Detection Method: Natural Language Understanding

Natural Language Understanding (NLU) uses machine learning algorithms to analyze and interpret message content, helping systems detect subtle signs of malicious intent. Instead of just matching keywords, NLU looks at the context, tone, urgency, and intent behind the message.
NLU can help you detect:
  • Urgent language commonly used in BEC attacks impersonating executives or departments
  • Credential theft attempts disguised as legitimate service notifications
  • Extortion or blackmail tactics used in intimidation campaigns
  • Financial terms typically found in payment fraud or invoice scams
  • Deceptive job offers designed to steal sensitive information
For example, NLU can identify when an email uses urgent language ("immediate attention required") combined with financial requests ("wire transfer") and impersonation, which are common tactics in BEC attacks.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Headers: Self-sender using Microsoft CompAuth bypass with credential theft content
12h ago
Apr 21st, 2026
Sublime Security
Credential phishing: 'Secure message' and engaging language
2d ago
Apr 20th, 2026
Sublime Security
Credential phishing: Suspicious subject with urgent financial request and link
2d ago
Apr 20th, 2026
Sublime Security
Brand impersonation: Amazon with suspicious attachment
8d ago
Apr 14th, 2026
Sublime Security
Advance Fee Fraud (AFF) from freemail provider or suspicious TLD
8d ago
Apr 14th, 2026
Sublime Security
Spam: Website errors solicitation
8d ago
Apr 14th, 2026
Sublime Security
Attachment: Compensation review lure with QR code
8d ago
Apr 14th, 2026
Sublime Security
Brand impersonation: USPS
9d ago
Apr 13th, 2026
Sublime Security
Callback phishing via Microsoft comment
9d ago
Apr 13th, 2026
Sublime Security
Attachment: PDF with credential theft language and invalid reply-to domain
12d ago
Apr 10th, 2026
Sublime Security
Brand impersonation: McAfee
13d ago
Apr 9th, 2026
Sublime Security
Cloud storage impersonation with credential theft indicators
13d ago
Apr 9th, 2026
Sublime Security
Attachment: Encrypted PDF with credential theft body
13d ago
Apr 9th, 2026
Sublime Security
Callback phishing via Apple ID display name abuse
14d ago
Apr 8th, 2026
Sublime Security
Attachment: Calendar invite with Google redirect and invoice request
14d ago
Apr 8th, 2026
Sublime Security
QR Code with suspicious indicators
16d ago
Apr 6th, 2026
Sublime Security
Brand impersonation: Toronto-Dominion Bank
19d ago
Apr 3rd, 2026
Sublime Security
Attachment: Legal themed message or PDF with suspicious indicators
19d ago
Apr 3rd, 2026
Sublime Security
Attachment: Cold outreach with invitation subject and not attachment
19d ago
Apr 3rd, 2026
Sublime Security
Service abuse: Google Firebase sender address with suspicious content
20d ago
Apr 2nd, 2026
Sublime Security