Correlate Sublime Logs in Panther for Centralized Threat Detection · Blog · Sublime Security
ID: 396135d6-7592-59cc-9cc7-576d8339a5e1
STIX ID: report--396135d6-7592-59cc-9cc7-576d8339a5e1
Feed Name: Sublime Security Blog
This document outlines the Sublime + Panther integration that exports Sublime email and audit logs (including Message Data Model-formatted messages) to Panther via S3, enabling centralized, high-fidelity email telemetry ingestion. It highlights use cases such as creating bundled alerts for emails matching multiple rules, extending detection-as-code within Panther, and monitoring Sublime audit events to detect misconfigurations or visibility reductions, and points readers to documentation to get started.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
