Detection Method: Natural Language Understanding

Natural Language Understanding (NLU) uses machine learning algorithms to analyze and interpret message content, helping systems detect subtle signs of malicious intent. Instead of just matching keywords, NLU looks at the context, tone, urgency, and intent behind the message.
NLU can help you detect:
  • Urgent language commonly used in BEC attacks impersonating executives or departments
  • Credential theft attempts disguised as legitimate service notifications
  • Extortion or blackmail tactics used in intimidation campaigns
  • Financial terms typically found in payment fraud or invoice scams
  • Deceptive job offers designed to steal sensitive information
For example, NLU can identify when an email uses urgent language ("immediate attention required") combined with financial requests ("wire transfer") and impersonation, which are common tactics in BEC attacks.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Brand impersonation: McAfee
2h ago
Aug 27th, 2026
Sublime Security
Service abuse: Kagoya.net-hosted domains sending English business lures
2h ago
Aug 27th, 2026
Sublime Security
Brand impersonation: Microsoft with low reputation links
4h ago
Aug 27th, 2026
Sublime Security
ClickFix: Clipboard hijack lure with copy-paste-to-terminal instruction
1d ago
Aug 26th, 2026
Sublime Security
Link: Self-sender with sender org in subject and credential theft indicator
2d ago
Aug 25th, 2026
Sublime Security
Business Email Compromise (BEC) with request for mobile number
2d ago
Aug 25th, 2026
Sublime Security
Business Email Compromise: Request for mobile number via reply thread hijacking
2d ago
Aug 25th, 2026
Sublime Security
Brand impersonation: Automobile assistance associations
2d ago
Aug 25th, 2026
Sublime Security
Brand impersonation: Sedgwick Claims
2d ago
Aug 25th, 2026
Sublime Security
Service abuse: Facebook mail notification callback scam
2d ago
Aug 25th, 2026
Sublime Security
Brand impersonation: United States Patent and Trademark Office
2d ago
Aug 25th, 2026
Sublime Security
Credential Phishing: Bitcoin portfolio confirmation
3d ago
Aug 24th, 2026
Sublime Security
Attachment: PDF proposal with credential theft indicators
3d ago
Aug 24th, 2026
Sublime Security
VIP impersonation: Payment handoff with VIP display name authored fake threads
3d ago
Aug 24th, 2026
Sublime Security
Body: AI-generated invoice template artifacts
5d ago
Aug 22nd, 2026
Sublime Security
Link: Credential phishing with obfuscated JavaScript redirect
6d ago
Aug 21st, 2026
Sublime Security
Job scam with specific salary pattern
7d ago
Aug 20th, 2026
Sublime Security
Service abuse: AWS SNS callback scam impersonation
7d ago
Aug 20th, 2026
Sublime Security
Brand impersonation: Aramco
7d ago
Aug 20th, 2026
Sublime Security
Service abuse: Arketa notification callback scam
8d ago
Aug 19th, 2026
Sublime Security