Detection Method: Natural Language Understanding

Natural Language Understanding (NLU) uses machine learning algorithms to analyze and interpret message content, helping systems detect subtle signs of malicious intent. Instead of just matching keywords, NLU looks at the context, tone, urgency, and intent behind the message.
NLU can help you detect:
  • Urgent language commonly used in BEC attacks impersonating executives or departments
  • Credential theft attempts disguised as legitimate service notifications
  • Extortion or blackmail tactics used in intimidation campaigns
  • Financial terms typically found in payment fraud or invoice scams
  • Deceptive job offers designed to steal sensitive information
For example, NLU can identify when an email uses urgent language ("immediate attention required") combined with financial requests ("wire transfer") and impersonation, which are common tactics in BEC attacks.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Brand impersonation: SoFi
13h ago
Aug 6th, 2026
Sublime Security
Extortion / sextortion in attachment from untrusted sender
22h ago
Aug 6th, 2026
Sublime Security
Brand impersonation: Cloud services with credential theft intent
23h ago
Aug 6th, 2026
Sublime Security
BEC: Tax document request
23h ago
Aug 6th, 2026
Sublime Security
Service abuse: Evernote link
2d ago
Aug 5th, 2026
Sublime Security
Service abuse: Wufoo credential theft
2d ago
Aug 5th, 2026
Sublime Security
Link: Mismatched free file host links with document lure
2d ago
Aug 5th, 2026
Sublime Security
Callback phishing in body or attachment (untrusted sender)
2d ago
Aug 5th, 2026
Sublime Security
VIP Impersonation via Google Group relay with suspicious indicators
2d ago
Aug 5th, 2026
Sublime Security
Brand impersonation: Microsoft with embedded logo and credential theft language
3d ago
Aug 4th, 2026
Sublime Security
Spam: Cold outreach from Cloudflare-hosted newly registered domain
3d ago
Aug 4th, 2026
Sublime Security
Credential phishing: Financial lure via ActiveCampaign infrastructure
3d ago
Aug 4th, 2026
Sublime Security
BEC/Fraud: Fake investment outreach from suspicious TLD
4d ago
Aug 3rd, 2026
Sublime Security
Brand impersonation: Sharepoint
4d ago
Aug 3rd, 2026
Sublime Security
Attachment: Encrypted PDF with credential theft body
9d ago
Jul 29th, 2026
Sublime Security
Attachment: Fictitious invoice using LinkedIn's address
9d ago
Jul 29th, 2026
Sublime Security
Service abuse: Postman reply-to mismatch with credential theft intent
9d ago
Jul 29th, 2026
Sublime Security
Brand impersonation: Microsoft Planner with suspicious link
10d ago
Jul 28th, 2026
Sublime Security
Credential theft: JavaScript date manipulation in HTML body
10d ago
Jul 28th, 2026
Sublime Security
Brand impersonation: USPS
11d ago
Jul 27th, 2026
Sublime Security