Agentic email security provider Sublime Security announced a platform integration with CrowdStrike Falcon® Next-Gen SIEM at Fal.Con 2026. The technical capability routes Sublime’s email threat telemetry directly into CrowdStrike Falcon Next-Gen SIEM, enabling enterprise security operations center (SOC) teams to correlate email security signals alongside endpoint, identity, cloud, and threat intelligence data during incident investigations.
The evolution of adversarial artificial intelligence has altered the speed and complexity of email-borne cyber threats. Over the last year, attacks exploiting AI-generated content increased about five times, with 90% of malicious emails being tailored specifically for their target enterprises. In order to fight off such adaptive threats, security experts need unified visibility that links email activity with corporate IT infrastructure logs.
Agentic Defense Framework Meets Enterprise SIEM Analytics
Sublime Security addresses rapid threat creation through a multi-agent digital architecture. The platform features an Autonomous Detection Engineer (ADÉ) agent that writes, tests, and deploys environment-specific detection rules, alongside an Autonomous Security Analyst (ASA) agent that automates initial threat triage.
Also Read: Sayari and DataExpert Form Strategic Partnership to Deliver Sovereign AI for European Economic Security
By ingesting Sublime’s email security data into CrowdStrike Falcon Next-Gen SIEM, security operations teams gain several operational advantages:
Unified Telemetry Ingestion: Streams Sublime email threat signals directly into Falcon Next-Gen SIEM for centralized data analysis.
Cross-Domain Threat Correlation: Links email activity with endpoint behaviors, identity metrics, cloud workloads, and threat intelligence streams.
Streamlined SOC Workflows: Incorporates Sublime threat data and automated response actions into established security operations procedures.
Accelerated Search and Investigation: Leverages Falcon Next-Gen SIEM’s query performance—delivering search speeds up to 150 times faster than traditional SIEM architectures to analyze email threats in real time.
“Finding a novel attack is only half the job. Security teams need the ability to act on it immediately,” said Josh Kamdjou, CEO and co-founder of Sublime Security. “By making Sublime’s email security signals available within CrowdStrike Falcon Next-Gen SIEM, analysts can connect email activity with broader security telemetry while quickly adapting email detection coverage as new threats emerge.”
“Email has always been a top threat vector and that has never been more true as attackers leverage Al. Email threats move faster than any one model can keep up with,” said Dustin Hillard, Chief Product and Technology Officer at eSentire. “Having Sublime’s detection alongside the rest of our security telemetry where our team already lives means we have a single investigation workflow, and the agility to immediately start blocking and responding to new email attacks when we find them.”
Enhancing Security Operations Efficiency
Technical integration empowers enterprise security teams, MD&R providers and SOC analysts with the ability to tear down isolation areas between email security and core infrastructure monitoring. By combining the tasks of threat identification and incident resolution, companies can cut their average detection delay (MDTD) and speed up average response time (MTTR) against complex email phishing campaigns, BEC and social engineering schemes.





























