Published on September 28, 2026, the article describes an Elastic Security and Sublime Security integration that correlates email and endpoint signals and automates responses with human approval.
On September 28, 2026, Elastic Security Labs published an article about the native integration between Elastic Security and Sublime Security. The described approach sends email threat telemetry to Elastic, where it can be correlated with endpoint, identity, and network signals and used to drive responses in both platforms. The article stresses that quarantining a message does not necessarily end an incident: separate signals may belong to the same campaign.
As an example, it describes a phishing email quarantined at 9 a.m. and a suspicious PowerShell command run on an endpoint at 9:05 a.m. Viewed in isolation, the events may seem resolved or routine; correlated, they may be early signs of a campaign. The article also advocates automated responses with human approval for selected actions. Consult the original Elastic Security Labs material to verify its scope, technical details, and integration limitations.