Authors
Jack Hirsch
Product Management
Sam Martin
Engineering

Email is a primary vector for initial access, which makes email data a critical source of attack context for the SOC. That is why we are excited to announce our new integration with CrowdStrike. Sublime email detections now flow directly into the CrowdStrike Falcon platform, so email sits next to endpoint, identity, and cloud security data in the platform your team already lives in.

Three integrations are live today in the CrowdStrike Marketplace:

  • CrowdStrike Falcon Next-Gen SIEM. Analysts can correlate attacks with Sublime email detection events to build cases from the whole picture.
  • CrowdStrike Falcon Fusion SOAR. Sublime investigation, detection management, and response actions show up as native playbook steps, so email response runs inside the automation you have already built.
  • CrowdStrike Falcon Sandbox. Analysts can detonate a suspicious email and get the verdict back in Sublime, with no malicious file to download and no secondary tool to pivot to.

In this post, we look at what each of these means for a Falcon analyst.

Email detection in CrowdStrike Falcon Next-Gen SIEM

Connecting the data behind phishing emails and the endpoint timeline are best viewed in a single console. When they aren’t connected in a timeline, the underlying threat is likely to be missed. The CrowdStrike Falcon Next-Gen SIEM integration with Sublime closes that gap.

Sublime email detections arrive in the Next-Gen SIEM as alert events. From there, analysts can search email and endpoint records together in one query language as a single incident, making attack correlation and triage fast and easy.

The Sublime integration in Falcon Nex-Gen SIEM includes a dashboard template, so teams get a readable view of their top email security events on day one, before writing a single query of their own.

In the event that a Falcon case reveals a novel attack originating in email, analysts can automatically generate new, backtested coverage using Sublime’s Autonomous Detection Engineer (ADÉ) AI agent. This allows analysts to go from attack discovery to coverage in under an hour.

Rich automated triage from CrowdStrike Falcon Fusion SOAR

Orchestration and automation through Fusion SOAR is a critical piece of a Falcon analyst’s response playbook. The Sublime integration runs in both directions to improve these playbooks.

From the email side, events and indicators are sent from Sublime to Falcon, so analysts can retrieve hunt results and remediate messages without ever leaving their investigation. On the SOAR side, endpoint, cloud, and identity events are sent from Falcon to Sublime, so a malicious domain, sender, or hash uncovered in an investigation can be used in a detection rule or list to stop the same attack from landing again.

Additionally, remediation automations allow analysts to quarantine, trash, restore, or dismiss emails directly from Falcon. Bringing the threat response to where the investigation occurs saves Falcon analysts both time and effort.

Sublime email detonation in the CrowdStrike Falcon Sandbox

Detonating a potentially malicious message can be a time consuming, risky, and a cross-application effort. By connecting the Falcon sandbox to the Sublime email platform, the sandbox verdict is seen in the same view as the email incident. Now analysts can begin a deep dive investigation in a single click – no downloading dangerous files, no switching between different screens.

What this means for Falcon analysts

Together, these integrations give a Falcon analyst email detection in the SIEM they already use, email response in the playbooks they’ve already built, and email detonation without leaving the tool they’re working in. Less pivoting between consoles, faster time to a decision, and a case that reflects the full attack instead of just the part that landed on the endpoint.

This is the beginning of the Sublime and CrowdStrike partnership, and we are excited about what comes next. If you use CrowdStrike, book a live demo to see the integration in action.

Share this post

Get the latest

Sublime releases, detections, blogs, events, and more directly to your inbox.

check
Thank you!

Thank you for reaching out.  A team member will get back to you shortly.

Oops! Something went wrong while submitting the form.