Detection Method: Natural Language Understanding

Natural Language Understanding (NLU) uses machine learning algorithms to analyze and interpret message content, helping systems detect subtle signs of malicious intent. Instead of just matching keywords, NLU looks at the context, tone, urgency, and intent behind the message.
NLU can help you detect:
  • Urgent language commonly used in BEC attacks impersonating executives or departments
  • Credential theft attempts disguised as legitimate service notifications
  • Extortion or blackmail tactics used in intimidation campaigns
  • Financial terms typically found in payment fraud or invoice scams
  • Deceptive job offers designed to steal sensitive information
For example, NLU can identify when an email uses urgent language ("immediate attention required") combined with financial requests ("wire transfer") and impersonation, which are common tactics in BEC attacks.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Link: Google Forms link with credential theft language
20h ago
May 11th, 2026
Sublime Security
Spam: Website errors solicitation
5d ago
May 7th, 2026
Sublime Security
Business Email Compromise (BEC) with request for mobile number
5d ago
May 7th, 2026
Sublime Security
Brand impersonation: Booking.com
6d ago
May 6th, 2026
Sublime Security
Suspicious newly registered reply-to domain with engaging financial or urgent language
6d ago
May 6th, 2026
Sublime Security
Link: Cloud service with credential theft language
6d ago
May 6th, 2026
Sublime Security
Callback phishing via calendar invite
6d ago
May 6th, 2026
Sublime Security
Canva infrastructure abuse
8d ago
May 4th, 2026
Sublime Security
Brand impersonation: Trust Wallet
8d ago
May 4th, 2026
Sublime Security
Venmo payment request abuse
8d ago
May 4th, 2026
Sublime Security
Brand impersonation: SharePoint PDF attachment with credential theft language
8d ago
May 4th, 2026
Sublime Security
Extortion / sextortion (untrusted sender)
8d ago
May 4th, 2026
Sublime Security
Brand impersonation: Sharepoint
8d ago
May 4th, 2026
Sublime Security
Impersonation: Suspected supplier impersonation with suspicious content
8d ago
May 4th, 2026
Sublime Security
Callback phishing via Google Group abuse
8d ago
May 4th, 2026
Sublime Security
BEC/Fraud: Student loan callback phishing
8d ago
May 4th, 2026
Sublime Security
BEC/Fraud: Generic scam attempt to undisclosed recipients
12d ago
Apr 30th, 2026
Sublime Security
Link: File sharing impersonation with suspicious language and sending patterns
12d ago
Apr 30th, 2026
Sublime Security
Adobe branded PDF file linking to a password-protected file from untrusted sender
13d ago
Apr 29th, 2026
Sublime Security
Attachment: QR code link with base64-encoded recipient address
13d ago
Apr 29th, 2026
Sublime Security