Sublime Security adds integration with CrowdStrike Falcon Next-Gen SIEM
Companies mentioned
Sublime Security said it added an integration with CrowdStrike Falcon Next-Gen SIEM to move email security signals into a SIEM environment. The update focuses on using email data alongside other security telemetry to support investigation and response workflows.
In the release, Sublime Security linked the integration to changes in email threat activity, citing that AI-generated content grew roughly 5x in the last year and that 90% of malicious emails were customized to targeted organizations. It also described a need for connecting email activity with security data across an environment for investigation and response.
Sublime described its platform as agent-based, with ADÉ (Autonomous Detection Engineer) writing, testing, and deploying organization-specific detection coverage and ASA (Autonomous Security Analyst) handling threat triage. It said the integration makes Sublime email security signals available inside Falcon Next-Gen SIEM so analysts can use email context during broader security investigations.
The companies said the integration enables organizations to ingest Sublime email security signals into Falcon Next-Gen SIEM, correlate email activity with endpoint, identity, cloud, threat intelligence, and other telemetry, and incorporate Sublime data and response actions into existing security operations workflows through Falcon Next-Gen SIEM. Josh Kamdjou, CEO and co-founder of Sublime Security, said, “Finding a novel attack is only half the job. Security teams need the ability to act on it immediately,” adding, “By making Sublime's email security signals available within CrowdStrike Falcon Next-Gen SIEM, analysts can connect email activity with broader security telemetry while quickly adapting email detection coverage as new threats emerge.”
Press release, provided by Cision on behalf of Sublime Security. Read the original.