Jump to Content
Sublime Security
DocumentationAPI Reference
Log InSublime Security
Documentation
Log In
DocumentationAPI Reference

Getting Started

  • Introduction/Overview

Install Sublime

  • Installation Options
  • Sublime Cloud
  • Docker
    • Docker Install
    • Docker Requirements and Limitations
    • Docker Troubleshooting
  • Amazon AWS
    • AWS CloudFormation Install
    • AWS GovCloud Install
    • Custom Domains
  • Microsoft Azure
    • Microsoft Azure ARM Install

Manage Sublime

  • Add Email/Message Sources
    • Microsoft 365
      • Sublime Cloud - Microsoft 365
      • Self Managed - Microsoft 365
    • Google Workspace
      • Sublime Cloud - Google Workspace
      • Self Managed - Google Workspace
    • IMAP
  • Configure "Report Phishing"
    • Add your abuse mailbox
    • Microsoft 365 Configure “Report Phishing”
    • Gmail Configure "Report Phishing"
  • Access & Authentication
    • Administer Users
      • Role-Based Access Control (RBAC)
      • Message Access Controls
    • Single Sign-On (SSO) Configuration
      • Okta SSO Configuration
      • Azure Entra ID SSO Configuration
    • How to manage users with SCIM
  • Integrate Email Threat Intel
  • Export to S3
    • Export Message MDMs
    • Export Audit Logs and Message Events

Use Sublime

  • Message types
  • Message groups
  • MQL Detection Rules
    • Attack Surface Reduction
    • Rule Severity
    • Rule Feeds
      • Rules file format (YAML)
      • Private rule feed authentication
    • YARA
    • Using the MQL Editor
  • Automations
    • Auto-respond to User Reports
  • Actions
    • Quarantine
    • Trash
    • Warning Banners
    • Move to Spam
    • Auto-review
    • Track Link Clicks (beta)
    • Webhook
      • Tines Webhook
    • Email Alert
    • Email Alert with EML Attached
    • Slack Alert
  • Lists
    • Configure the org_vips list
  • Exclusions
  • Attack Score
  • ASA: Autonomous Security Analyst
  • ADÉ: Autonomous Detection Engineer
  • Email bomb protection

Tutorials

  • MQL Guides
    • How to use message header values in a rule
    • How to detect manual outbound forwards
    • How to detect text in attachments
    • How to detect lookalike domains
    • How to detect keywords or phrases in the body content of messages

Reference

  • Message Data Model (MDM)
  • Message Query Language (MQL)
    • Syntax
    • Missing or null values
    • Functions
    • Strings functions
    • RegEx functions
    • Enrichment functions
    • Common snippets
  • Metrics Collection in Self-Hosted Deployments
Powered by 

Installation Options

Suggest Edits

Managed Deployment

  • Sublime Cloud: Let us handle it! A Sublime Managed Deployment. For organizations of any size. First 100 mailboxes free.

Docker

  • Docker: Up to 600 active mailboxes.

Amazon AWS

  • AWS CloudFormation : Scales to any number of mailboxes.
  • AWS GovCloud: For AWS GovCloud

Microsoft Azure

  • Azure ARM: Scales to any number of mailboxes.

Updated about 1 month ago


  • Table of Contents
    • Managed Deployment
    • Docker
    • Amazon AWS
    • Microsoft Azure