Sublime Security Announces Integration with CrowdStrike Falcon Next-Gen SIEM
Sublime Security(opens in new tab)(opens in new tab), the agentic email security platform, today at Fal.Con 2026(opens in new tab) announced a new integration that enables Sublime email security signals to flow into CrowdStrike Falcon® Next-Gen SIEM(opens in new tab). The integration enables security teams to correlate Sublime’s email security data with endpoint, identity, cloud, threat intelligence, and other security telemetry during investigations, providing additional context into attacker activity.
Adversarial AI has fundamentally changed the pace and composition of email threats. Attacks with AI-generated content grew roughly 5x in the last year(opens in new tab), and 90% of malicious emails are customized to each targeted organization(opens in new tab). As attackers increasingly adapt their techniques, security teams need to connect email activity with security data from across the environment to investigate and respond to threats quickly.
Sublime utilizes a team of agents to counter the pace of AI threats. Its ADÉ (Autonomous Detection Engineer)(opens in new tab) agent writes, tests, and deploys organization-specific detection coverage tailored to each environment, while ASA (Autonomous Security Analyst)(opens in new tab) handles threat triage. By making Sublime email security signals available within Falcon Next-Gen SIEM, security teams can incorporate email context into broader investigations and security operations workflows.
Falcon Next-Gen SIEM unifies first- and third-party data, native threat intelligence, AI, and workflow automation to transform security operations. Delivering more capabilities with up to 150x faster search performance than legacy SIEMs(opens in new tab) and solutions positioned as SIEM alternatives, at up to 80% lower total cost of ownership(opens in new tab), Falcon Next-Gen SIEM helps organizations detect, investigate, and respond to threats more efficiently.
Also Read: IT Tech Pulse Exclusive Interview with Ken Claffey Chief Executive Officer and President of VDURA
The integration enables organizations to:
- Ingest Sublime email security signals into Falcon Next-Gen SIEM.
- Correlate email activity with endpoint, identity, cloud, threat intelligence, and other security telemetry during investigations.
- Incorporate Sublime data and response actions into existing security operations workflows through Falcon Next-Gen SIEM.
“Finding a novel attack is only half the job. Security teams need the ability to act on it immediately,” said Josh Kamdjou(opens in new tab), CEO and co-founder of Sublime Security. “By making Sublime’s email security signals available within CrowdStrike Falcon Next-Gen SIEM, analysts can connect email activity with broader security telemetry while quickly adapting email detection coverage as new threats emerge.”
“Email has always been a top threat vector and that has never been more true as attackers leverage Al. Email threats move faster than any one model can keep up with,” said Dustin Hillard, Chief Product and Technology Officer at eSentire. “Having Sublime’s detection alongside the rest of our security telemetry where our team already lives means we have a single investigation workflow, and the agility to immediately start blocking and responding to new email attacks when we find them.”
Write to us [wasim.a@demandmediaagency.com] to learn more about our exclusive editorial packages and programmes.