-
Cumulative Byte counts are now displayed on the Foreign IP Reports card.
-
Download Manager: Long running tasks (such as downloads of large files) no longer require sitting on the same page while they process. These now run in the background on the server and can be picked up on the Long Tasks page when completed.
-
Event Card Configurator: When creating a new Event Reports card on the dashboard, the user will now be walked through a setup process for any filters or configurations they want to apply to that card.
-
Domain Generation Algorithm (DGA) Detection Model: This model identifies suspicious domains based on their name. Any connections with domains deemed suspicious are created as Evidence, so a suspicious domain alone will not generate an Event. We will monitor this Evidence and see if it makes sense to promote it to a full Event based on model performance.
-
Added Nomic Networks threat data as an enrichment on Events. Nomic identifies IPs conducting scanning or reconnaissance activity across the internet.
-
Brute Force (T1110) Events will now be tagged as Anomalous instead of Threat if they are Internal to Internal.
-
Suricata Event Representative Connections now display fields from relevant child objects (i.e. HTTP, DNS, DHCP, etc.) based on the rule that triggered.
-
Added child object fields to all other Events that didn’t previously get them.
-
Rules can now be created using hostname as a field.
-
Added support for MITRE ATT&CK version 18.