Quarantined isn't contained: Agentic phishing response with Elastic and Sublime
The native Sublime Security integration sends email detections into Elastic Security, where phishing incident response can tie a quarantined email to what happens next on the endpoint and pull the threat from every mailbox it reached.
Critical signals still land in different security tools, so early signs of a campaign might go unnoticed. That visibility gap is getting more expensive as attackers automate phishing and vulnerability chaining. Although bringing the data together is the foundation, the real shift comes from the agentic layer operating on that data, and that’s what this post explores.
Consider the following:
At 9:00 a.m., Sublime Security quarantines a phishing email before it reaches an inbox.
At 9:05 a.m., an endpoint in the same environment runs a suspicious PowerShell command.
On their own, each event looks handled. The quarantine did its job, and one odd PowerShell process a day is background noise in most environments. But looked at together, they’re the opening moves of a campaign. The problem is that nobody sees them together, because the two signals live in different tools.The email signal sits in your email security product, and the endpoint signal sits in your security information and event management (SIEM) or endpoint detection and response (EDR) tool. Nobody is watching both at 9:05 a.m.
That gap is getting more expensive as attackers use large language models (LLMs) to generate convincing phishing at volume and as autonomous agents start finding and chaining vulnerabilities on their own. Recent incidents, like the OpenAI models reaching Hugging Face's production systems during a cyber evaluation, prove exactly how quickly an automated actor can move once it’s loose.
Defenders need to close that gap and respond at the same speed, while keeping control over what runs automatically and what waits for a human. This post shows how the native Elastic and Sublime Security integration brings email threat telemetry into Elastic Security, where it can be correlated with your endpoint, identity, and network signals and used to drive response across both platforms without switching tools. Removing that friction is an important first step. When signals remain siloed across products, every handoff adds time to the investigation and response.
But bringing the data together is only the foundation. As noted, the real shift toward responding as fast as the attack moves comes from the agentic layer operating on that data. Here, we explore that concept in detail.
Why one quarantined email matters five minutes later
A quarantined email is rarely the end of it. An attacker running a campaign comes back in another form, like a second email from a different sender or a malicious link over another channel. It might even be a call that talks a user into running something they shouldn't. What the first attempt is worth hinges on whether you can connect it to the ones that follow.
That connection depends on where the signal lands. Through the native integration, we pull Sublime's telemetry into Elastic Security, the agentic security operations platform that your analysts already work in and where your agents and orchestration layer run. The email detections and quarantine actions, along with the surrounding context, sit alongside your endpoint, cloud, network, and identity data, so two otherwise dismissible events can become one investigation worth opening, connected by an analyst or by the agent doing the first pass on their behalf.
Native Sublime integration to bring email telemetry to Elastic.
How phishing incident response works across Sublime Security and Elastic
The full flow runs from the first quarantined email to a response back in Sublime Security:
Sublime Security quarantines a phishing email.
The native integration sends the email telemetry to Elastic Security.
Elastic detection rules run against it alongside endpoint, identity, and network data.
Attack Discovery correlates the related alerts into a single attack.
Elastic Workflows creates a case and sends the analyst a Slack notification with the evidence attached.
The analyst approves or rejects the recommended action.
If Elastic Defend has found the malware on a host, Elastic Workflows uses its SHA-256 hash to trigger a blast-radius quarantine in Sublime Security.
Email security SIEM integration: What Sublime Security sends to Elastic
The mailbox is one of those signals. Sublime Security is an email security platform that detects and quarantines attacks aimed at the mailbox, including phishing, business email compromise, malicious attachments, and similar threats. Two things about it matter here. First, its detection logic is open, so you can read and tune the rules that decide what gets quarantined. Elastic's own incident response team runs Sublime day to day, and what stands out to them is that openness.
It's not a black box. We can see exactly why something was detected.
—Jordyn Coyne, Senior Manager of Incident Response, Elastic
Second, it combines those rules with machine learning (ML) to catch variants that a static rule would miss. That produces a stream of high-context email events, each recording:
What was flagged.
Why it was flagged.
Who it targeted.
What Sublime did about it.
On its own, Sublime protects the mailbox. Correlated in Elastic with endpoint, identity, and network signals, it becomes an early warning for the rest of the attack.
How Elastic correlates email and endpoint alerts
Once Sublime Security telemetry is in Elastic, your Elastic detection rules run against it like any other signal. Those rules are open and backed by Elastic Security Labs: Elastic publishes and versions its detection content, so you can read the logic behind an alert or tune it, or you can write your own, the same way that Sublime's rules are open on the email side. In both places, you can see why something fired, not only that it did.
When alerts start stacking up, Attack Discovery is what turns them into a picture. It’s an agentic workflow that pulls the relevant alerts together into unified attack chains, and it does more than line them up. Drawing on its available security skills, it gathers supporting evidence before it produces a prioritized attack. This workflow:
Hunts for related activity.
Reads the individual alerts.
Checks the context around the entities involved.
Queries raw logs across the Elastic platform.
An analyst gets an evidence-grounded account of what happened, mapped to MITRE ATT&CK, with its reasoning visible, rather than a raw queue to sort through.
Evidence-backed correlation generated by the agent.
Attack Discovery correlates the alerts into one single coherent attack.
Human-in-the-loop response in an agentic SOC
Machine-speed correlation is only useful if a human can act on it quickly and with confidence. Elastic Workflows is the platform's automation engine. Workflows connect to Elastic Agent Builder in both directions; that is, an agent can call a workflow as a tool to take a concrete action, and a workflow can hand a step back to an agent when it needs reasoning or language understanding.
The two-way connection between Agent Builder and Elastic Workflows is what lets the response go past advice. Given a discovery, an agent can enrich it and weigh whether it’s a true positive. Plus, it can recommend a next step. Because it reaches actions through Workflows, it can also carry out that step, for example by:
Isolating a host.
Opening a case.
Notifying the on-call analyst.
Triggering a response in a connected tool.
In this flow, Elastic Workflows creates a case for the correlated incident and sends a Slack notification, with the supporting evidence attached, to the analyst. The analyst approves or rejects the recommended action from there, without needing to reconstruct the investigation.
Elastic case created with evidence added by the agent.
Slack notification about the finding, with approval message, sent to the analyst.
The analyst is reviewing an evidence-backed decision, not starting from a raw alert. That’s the difference between reacting at machine speed and only monitoring at machine speed.
Quarantine phishing emails from an endpoint finding
The integration also runs the other direction. We recently added a security orchestration, automation, and response (SOAR) integration with Sublime, which lets you take action on the Sublime side from within Elastic Workflows.
The SOAR integration pays off when an endpoint finding needs an email-side response. If Elastic Defend, our native EDR, identifies a specific piece of malware, you can take the file's SHA-256 hash and use a workflow to trigger a blast-radius quarantine on the Sublime side. An endpoint finding becomes an email-side containment action, so the same indicator that you found on a host is pulled out of every mailbox it reached, and you never leave Elastic to do it.
Elastic Workflows triggers quarantine for the blast-radius message group in Sublime.
Automation you can control
The point of configurable autonomy is that not every action belongs on autopilot. A blast-radius quarantine that pulls a message from every mailbox is high impact, and many teams will want a human to approve it the first several times they run it. A lower-impact enrichment or tagging step is a reasonable candidate to automate outright.
Elastic Workflows lets you set that line per action rather than for the whole system, so you can automate the safe steps and route the consequential ones through the analyst approval flow. Start with more human review than you think you need, and watch how the recommendations hold up against your own judgment. Then move actions to automatic as you build trust in them.
How to roll out the Sublime Security integration in Elastic
The integration is worth rolling out in two stages:
Bring Sublime's telemetry into Elastic, and let your existing detection content pick it up. This gives you the correlation benefit on day one and asks nothing new of your analysts.
Add the two-way SOAR actions once the telemetry is flowing and you’ve decided which responses you want to run automatically and which should wait for an analyst.
The native Sublime integration is available in Elastic now. Set it up to bring the email signal in, and see Workflows for Security for how the response layer fits together.
How helpful was this content?
Related Content

One SOC, 100 projects: running centralized alert triage on Elastic Security Serverless



