Detection Method: Natural Language Understanding

Natural Language Understanding (NLU) uses machine learning algorithms to analyze and interpret message content, helping systems detect subtle signs of malicious intent. Instead of just matching keywords, NLU looks at the context, tone, urgency, and intent behind the message.
NLU can help you detect:
  • Urgent language commonly used in BEC attacks impersonating executives or departments
  • Credential theft attempts disguised as legitimate service notifications
  • Extortion or blackmail tactics used in intimidation campaigns
  • Financial terms typically found in payment fraud or invoice scams
  • Deceptive job offers designed to steal sensitive information
For example, NLU can identify when an email uses urgent language ("immediate attention required") combined with financial requests ("wire transfer") and impersonation, which are common tactics in BEC attacks.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Brand impersonation: Cloud services with credential theft intent
5d ago
Jun 18th, 2026
Sublime Security
Service abuse: Google Firebase sender address with suspicious content
5d ago
Jun 18th, 2026
Sublime Security
Attachment: Encrypted PDF with credential theft body
6d ago
Jun 17th, 2026
Sublime Security
Reconnaissance: Short generic greeting message
6d ago
Jun 17th, 2026
Sublime Security
Fake thread with suspicious indicators
6d ago
Jun 17th, 2026
Sublime Security
Brand impersonation: Survey request with credential theft indicators
6d ago
Jun 17th, 2026
Sublime Security
Fake Zoom meeting invite with suspicious link
7d ago
Jun 16th, 2026
Sublime Security
HTML content with print styling and credential theft language
7d ago
Jun 16th, 2026
Sublime Security
Service abuse: IBM IAM account notification with callback scam indicators
7d ago
Jun 16th, 2026
Sublime Security
Advance Fee Fraud (AFF) from freemail provider or suspicious TLD
8d ago
Jun 15th, 2026
Sublime Security
Credential phishing: Generic document sharing
8d ago
Jun 15th, 2026
Sublime Security
Scam soliciting employer review/rating
11d ago
Jun 12th, 2026
Sublime Security
Callback phishing via Apple ID display name abuse
12d ago
Jun 11th, 2026
Sublime Security
Link: Credential theft with Cloudflare tunnel and recipient targeting
13d ago
Jun 10th, 2026
Sublime Security
Attachment: PDF with QR code containing recipient-specific credential theft content
13d ago
Jun 10th, 2026
Sublime Security
Brand impersonation: Zoom
18d ago
Jun 5th, 2026
Sublime Security
Credential phishing: Engaging language and other indicators (untrusted sender)
18d ago
Jun 5th, 2026
Sublime Security
HR impersonation via e-sign agreement comment
18d ago
Jun 5th, 2026
Sublime Security
Credential phishing: Suspicious subject with urgent financial request and link
18d ago
Jun 5th, 2026
Sublime Security
Brand impersonation: Microsoft Planner with suspicious link
18d ago
Jun 5th, 2026
Sublime Security