Skip to main content

January 27, 2025 – Application Update

We are happy to introduce new features and enhancements to improve your experience with our platform. Here’s what’s included in this release:

What’s New


More status options in cases

Users can now manage and monitor cases more effectively with the introduction of In Progress and On Hold status values. These new status values provide greater clarity and control over case workflows. 

  • In Progress: This status indicates that active investigation or resolution is underway, helping teams stay focused on high-priority tasks. It provides visibility into which cases are being addressed and by whom, ensuring accountability and smoother collaboration.
  • On Hold: This status is used for cases that are temporarily paused due to dependencies, lack of information, or other reasons. It ensures that paused cases are not forgotten and can be revisited when conditions are favourable.

Note: By default, the case listing page will now display cases created in the last 24 hours.


Enhanced case list export with filters and metrics



  • Enhanced Traceability: Log events are now enriched with PICO details

    Log events can now be traced back to the specific PICO through which they were ingested, providing enhanced visibility and traceability in your log management process. This enhancement introduces the capture of the following additional fields:
    •   PicoSystemIP
    •   PicoCompID
    •   PicoSystemName

      Note: This feature is available for PICO version 9.4.2 and above. Please ensure that your PICO systems are updated to leverage this enhanced functionality.


  • Support for configurable Protocol and Port in PICO Raw Forwarder

    The PICO Raw Forwarder now supports TCP also for log forwarding. Users can also specify the destination port while configuring the Raw Forwarder.
    Note: This feature is available for PICO version 9.4.1 and above.
Enhancements


  • MITRE page

    The enhanced MITRE page provides users with powerful tools and insights to better understand and manage detection coverage. Key features include
  • Visual and Interactive insights
    • Colourful Heatmap Views: Easily interpret detection coverage with intuitive visual representations and legends.
    • Complete MITRE TTP mapping
  • Coverage details
    • Detection Coverage: Understand coverage based on the workbooks created by users
    • Active Detection Coverage: Gain insights into the active detections linked to your log sources
  • Advanced filtering options: Refine your view of detection coverage using enhanced filters, including:
    • Streams
    • Workbook Scheduling (On-demand, Streamed and Scheduled)
    • Workbook Type (Native and Custom)
    • Workbook Stages
    • Workbook Profile
  • Addition of MITRE sub-techniques
  • View details of individual MITRE techniques
    • Description of the technique
    • List of workbooks
    • Signal activity
  • Additional tab to view Signal activity for each MITRE TTP per day, per week and per month

  • Audit Trail

    • The Audit Trail now tracks and displays the following user activities:
    • Workbook Export
    • Workbook Import
    • Audit Trail Export
    • Multiple Case Closure on Case Listing Page
    • Stream Download
    • Dashboard List Export 
    • Dashboard Import
    • Multiple Case Export from Case Listing page
    • Signal Export
    • Collection Status List Export
    • Enrichment List Export
    • Manage Token List Export