25 September 2024 version 2024.9.0
New functionality
MetaStream Module
The MetaStream module is now included with all accounts. Going forward, Admins will only need to create, delete, recreate or retrieve a credential.
User activity timeout
You can now set the amount of inactivity time before a user is automatically logged out of the portal. The new timeout time goes into effect the next time users log into the portal.
Improved functionality
Pivot to events
You can now click the tag icon to pivot directly to the Events table in an investigation. This saves time navigating to the investigation with the GUI. This function is available on all tags in the investigation tooltip, the investigation detail page, and tagged queries in the Private Search page.
The Events table will display the same number of events tagged in the investigation dialog.
Sensor Telemetry
You can now filter the sensor Telemetry data by Day, Hour and last 5 Minutes.
You can also group the page by Sensor.
User Roles
We have added a tooltip with a description of each role when you create a new user. The tooltip describes the privileges and limitations of each role and offers suggestions to make sure you are assigning the appropriate role to the user. For example, the new user may need both Admin and User roles to configure settings and perform queries. To view the description, hover over the name of the role in the dialog.
An auto-check is performed when you select the user role. A warning appears to remind you of the limitations of the role. If you choose to ignore the warning, it will not prevent you from creating the new user.
Detection assignment
You can now assign a detection to any active user with any role in the current account. Previously you could only assign detections to active users created in the current account.
Manage Annotations
You can now open the Entity Panel when you click the Entity Name in the Manage Annotations page when the entity is a valid IP, CIDR, domain, or URL.
You can also right-click the entity with a valid IP to Search Events, View/Create Annotations, perform an Entity Lookup and Global Search, or open a Playbook.