Jump to Content
Sublime Security
DocumentationAPI Reference
Log InSublime Security
Documentation
Log In
DocumentationAPI Reference

Getting Started

  • Introduction/Overview

Install Sublime

  • Installation Options
  • Sublime Cloud
  • Docker
    • Docker Install
    • Docker Requirements and Limitations
    • Docker Troubleshooting
  • Amazon AWS
    • AWS CloudFormation Install
    • AWS GovCloud Install
    • Custom Domains
  • Microsoft Azure
    • Microsoft Azure ARM Install

Manage Sublime

  • Add Email/Message Sources
    • Microsoft 365
      • Sublime Cloud - Microsoft 365
      • Self Managed - Microsoft 365
    • Google Workspace
      • Sublime Cloud - Google Workspace
      • Self Managed - Google Workspace
    • IMAP
  • Configure "Report Phishing"
    • Add your abuse mailbox
    • Microsoft 365 Configure “Report Phishing”
    • Gmail Configure "Report Phishing"
  • Access & Authentication
    • Administer Users
      • Role-Based Access Control (RBAC)
      • Message Access Controls
    • Single Sign-On (SSO) Configuration
      • Okta SSO Configuration
      • Azure Entra ID SSO Configuration
    • How to manage users with SCIM
  • Integrate Email Threat Intel
  • Export to S3
    • Export Message MDMs
    • Export Audit Logs and Message Events

Use Sublime

  • Message types
  • Message groups
  • MQL Detection Rules
    • Attack Surface Reduction
    • Rule Severity
    • Rule Feeds
      • Rules file format (YAML)
      • Private rule feed authentication
    • YARA
    • Using the MQL Editor
  • Automations
    • Auto-respond to User Reports
  • Actions
    • Quarantine
    • Trash
    • Warning Banners
    • Move to Spam
    • Auto-review
    • Track Link Clicks (beta)
    • Webhook
      • Tines Webhook
    • Email Alert
    • Email Alert with EML Attached
    • Slack Alert
  • Lists
    • Configure the org_vips list
  • Exclusions
  • Attack Score
  • ASA: Autonomous Security Analyst
  • ADÉ: Autonomous Detection Engineer
  • Email bomb protection

Tutorials

  • MQL Guides
    • How to use message header values in a rule
    • How to detect manual outbound forwards
    • How to detect text in attachments
    • How to detect lookalike domains
    • How to detect keywords or phrases in the body content of messages

Reference

  • Message Data Model (MDM)
  • Message Query Language (MQL)
    • Syntax
    • Missing or null values
    • Functions
    • Strings functions
    • RegEx functions
    • Enrichment functions
    • Common snippets
  • Metrics Collection in Self-Hosted Deployments
Powered by 

Administer Users

Suggest Edits

Overview

Sublime has fine grained options for controlling what users can access, as well as what they can see within the platform.

Role Based Access Controls

Email Message Access Controls

Updated about 1 month ago


  • Table of Contents
    • Overview