MQL for Email APT Hunting

No ratings

Presented at Wild West Hackin' Fest 2026 by

As a threat detection engineer at Sublime, I use Message Query Language (MQL) daily to detect and investigate advanced email-based threats from groups like APT29 (UNC2452, NOBELIUM, StellarParticle, Dark Halo, SolarStorm) and Famous Chollima (UNC5267, Nickel Tapestry). MQL gives me the flexibility to write targeted queries that surface activity like credential phishing, VIP impersonation, malicious links, and payload-laden attachments. What makes this powerful is the ability to bring in our own behavioral signals and threat intel to tailor detections to our environment. Paired with custom detections in Sublime, this gives us deep visibility into state-sponsored campaigns. We also deploy YARA signatures—both internal and community-created—to proactively block malicious content before it ever hits an inbox. These detections are also provided to the community free in a feed that you can deploy fast and free, too.*Please note, Bryan will be presenting virtually.