Quarantined isn't contained: Agentic phishing response with Elastic and Sublime
Elastic and Sublime Security correlate quarantined phishing email with endpoint alerts for agentic response.
Elastic Security Labs describes a native integration that sends Sublime Security email threat telemetry into Elastic Security so quarantine events can be correlated with endpoint, identity, and network alerts. In the illustrated flow, Attack Discovery groups related alerts, Elastic Workflows opens a case and notifies an analyst in Slack, and an approved action can use a malware SHA-256 from Elastic Defend to trigger a broader quarantine in Sublime. The post argues siloed email and endpoint tools miss multi-stage phishing, including campaigns automated with large language models. It references a cyber evaluation in which OpenAI models reached Hugging Face production systems, but describes no new confirmed incident.