Skip to main content

SOC Prime Platform Product Release Notes 5.16.0

Written by Eugene

April 16, 2025

© 2025 SOC Prime Inc.

All rights reserved. This product and documentation related are protected by copyright and distributed under licenses restricting their use, copying, distribution, and decompilation. No part of this product or documentation related may be reproduced in any form or by any means without the prior written authorization of SOC Prime. While every precaution has been taken in the preparation of this book, SOC Prime assumes no responsibility for errors or omissions. This publication and features described herein are subject to change without notice.

Elastic ES/QL Query Support


With this SOC Prime Platform release 5.16.0, we’ve added Elastic ES|QL Query and Elastic ES|QL Rule support to the following Threat Detection Marketplace (TDM) functionality:

  • Lists when selecting the Content Platform

  • Presets

  • Filters

  • Jobs

  • Custom Field Mapping (with the ability to display Elastic ES|QL Query/Rule mapping configuration on the content item page and Data Planes)

  • Inventory page (by adding the ability to deploy detection content in the Elastic ES|QL format)

  • The Elastic Data Plane, where the corresponding format will be deployed, is now available for selection

  • Content actions, like editing and deployment, are now accessible in the corresponding language format

  • On the content item page: with the ability to click the Deploy button and go through the full content deployment flow

As part of UX improvements to the Elastic ES|QL Query and Rule support, we’ve added the “Remove trailing spaces after the rule name prefix and leading spaces before suffix” checkbox to the Presets functionality.

New Elastic Parameter


With the support of Elastic ES|QL Query and Elastic ES|QL Rule language formats, we’ve added a new Elastic parameter to Presets for the following content types to enable both manual and automated content deployments:

  • Elastic Detection Rule (EQL)

  • Elastic Detection Rule (Lucene)

  • Elastic Detection Rule (ES|QL)

The Create New Preset Profile settings now include the additional Timestamp override field and the corresponding “Do not use @timestamp as a fallback timestamp field“ checkbox.

Also, as part of this Platform release, we’ve added a new Elastic Parameter to Jobs and the Rule Template service.

AWS OpenSearch Detection Rule Support


With the latest Platform release, we’ve also added support for AWS OpenSearch Detection Rule (opensearch-json-rule), which is now available in Uncoder AI and the Threat Detection Marketplace for the following functionality:

  • On the Search page within the Platform filters

  • On the content item page

Detection content in the corresponding language format can now be saved in custom repositories in the Threat Detection Marketplace.

The OpenSearch Detection Rule format can be selected as the target language during automated content translation via Uncoder AI.

Mandatory Two-Factor Authentication (2FA) Enforcement


As part of our commitment to enhancing platform security, we’ve introduced a new feature that allows Managers to enforce Two-Factor Authentication (2FA) for all team members using the SOC Prime Platform.

Specifically, a new Enforce Two-Factor Authentication binary toggle has been added to the Team Management page. Managers now can choose between two options:

  • Enabled: The toggle is green, and all company users must set up 2FA before accessing the platform.

  • Disabled: Users can access the platform without enforced 2FA.

Once 2FA enforcement is enabled, all users within the team will see a screen with the 2FA setup prompt and a message: “Your manager has enabled mandatory two-factor authentication for the entire team, please set it up.”

After this step is completed, the users will then proceed to the Recovery Codes step to finish the setup.

Once all the routines are completed, users will be able to access the Platform normally.

Note: With Enforce Two-Factor Authentication enabled by the Manager, the Platform will block users from accessing their accounts until they have completed the 2FA setup.

Referral Program


We have recently released our Referral Program. When referring a peer or a friend to subscribe to TDM or Uncoder AI, they will receive 20% off their first Solo subscription, whether monthly or annual. Upon their successful subscription, the referrer will also receive 20% off their next Solo payment.

Just log in to the SOC Prime Platform, press the Refer a Friend button in the header menu, and share the referral link to your friend, or simply type their email for an invite.

Note: There are no limits on invitations—SOC Prime users can refer as many contacts as they want to get more rewards.

TOS Updates


With this latest release 5.16.0, we’ve made changes to the following TOS documents on SOC Prime Platform to reflect the latest product updates, including:

  • Uncoder AI major upgrade

  • Threat Detection Marketplace

  • The Enterprise pop-up related to the Referral Program (to specify that the Referred Customer must belong to a different company than the user who referred them)

Company Website Updates


AI SOC Ecosystem

We have released the AI SOC Ecosystem landing page, which is now available within a separate Ecosystem tab on the main navigation. Adding this new tab also affected a set of website navigation changes, including the removal of the Community tab from the main menu.

The Become a Partner button leads to the form that enables connecting with SOC Prime experts to explore partnership opportunities and drive the future of cybersecurity together.

Homepage Updates

With this latest release, we’ve updated the UI of the main company website page at https://socprime.com/ by adding the AI-Powered Cyber Defense block with three videos and summaries on the following AI/ML models we support:

  • SOC Prime RAG LLM model

  • SOC Prime MITRE ATT&CK tagging model

  • SOC Prime Language Detection ML model

By clicking the Explore More button on the first screen, SOC Prime users instantly drill down to the AI-Powered Cyber Defense for more details.

Events Page Updates

In view of two upcoming events, we have added the following information to the Events page, which leads to the corresponding registration pages/Pipedrive form:

  • SOC Prime’s webinar “SOC Prime Ecosystem: Drive Maximum Value From Your Security Stack With Automation & AI

  • Bi-lingual webinar “Next-Gen SOC: Innovations & Best Practices for Enterprise Security”, which is designed for both English- and German-speaking audiences

Other UX Improvements

With this Platform release, we've included the Bluesky icon across our social media sections—now visible on the SOC Prime blog, News section, and in the footer of the company website.

Threat Detection Marketplace


Light Search

With the latest release, we have introduced a set of improvements to the Light Search page. Specifically, we have expanded the sorting options by adding the Severity parameter. Users can now filter detections based on threat severity directly from the Light Search Sorting Menu, enabling quicker access to the most relevant and critical results.

Note: Severity can not be chosen as a default parameter for sorting.

Additionally, the SOC Prime Platform now remembers the selected sorting option across user sessions to ensure a more consistent and personalized experience.

With the latest release, we have also enhanced the Light Search interface by adding new elements to the content table for better clarity:

  • Category

  • Product

  • Severity

The severity status for each rule is now visually represented using a colored arrow icon, enabling quicker threat prioritization at a glance.

Standard Search

With the latest release, we have improved the rules sorting by adding the Severity parameter to the Standard Search Sorting Menu.

Also, Standard Search is now automatically selected by default for all users with access to this feature under the TDM subscription plan.

Inventory Page

In the latest release, we have improved Inventory page filtering and sorting options when working with detection content updates. This enhancement applies to both the Platform and custom detection content.

When the selected Data Plane contains updated rules, a notification banner now appears indicating the number of rules containing updates.

The Show button in the notification is clickable and triggers the Inventory view filtering by the Update Exists parameter to display only the detection content items with updates available.

If no updates are available, this notification is not shown.

Notably, a new column labeled Update has been added to the Inventory table. It displays:

  • A green circle icon for content with available updates (clicking the icon initiates the update flow).

  • A dash symbol for content with no updates.

The drop-down filter has been added to the Update column header, including the following options:

  • All

  • No Update

  • Update Exists

Selecting any of these filters dynamically updates the table content accordingly.

Rule Intelligence

We’ve enhanced the Rule Intelligence section of each content item by introducing a new Relation Graph feature, designed to help users visually explore related detection content:

  • Visual Browsing: Easily navigate relationships between rules based on shared metadata tags (e.g., MITRE ATT&CK).

  • Interactive Tags: Each tag in the rule’s metadata now acts as a link, connecting you to other rules with the same tag.

  • Top Matches Displayed: The graph is limited to the 10 most relevant related rules, selected by the number of shared tags for clarity and performance.

Note: Currently, Relation Graphs are available only for Platform-managed rules. Tag-based relations for custom content are not yet supported.

Splunk GitHub Repository Synchronization

We’ve implemented synchronization of detection content from the official Splunk Security Content GitHub repository. All rules from the detections/ directory are now synced into TDM library under splunk/security_content repo, excluding deprecated content.

Deprecated rules are monitored continuously. If a rule is moved to the deprecated folder, it will be automatically marked as deprecated and hidden in TDM. This integration helps keep your threat detection library aligned with the latest Splunk security content updates.

Elastic GitHub Repository Synchronization

We’ve implemented synchronization detection content from the official Elastic Detection Rules GitHub repository. All .toml rules from the rules/ directory are now synced into the TDM library under the elastic/detection-rules repo, excluding content from _deprecated, apm, and ml folders.

Rules located in the _deprecated folder are continuously monitored and automatically marked as deprecated and hidden in TDM. This integration helps keep your detection library aligned with the latest updates from Elastic’s open-source content.

HijackLibs Detection Content Synchronization

We’ve integrated a new public detection feed from HijackLibs into the SOC Prime Platform. Now, users can access the corresponding Sigma rules by choosing the HijackLibs repo in the Platform Repos drop-down list. This integration helps keep your detection library aligned with the latest updates from HijackLibs.

Uncoder AI


Free Access to AI-Powered Features

We’ve unlocked all AI-powered features in Uncoder AI for every user across all subscription tiers. These capabilities are now available without token limits, ensuring everyone—Free, Solo, or Enterprise—can fully benefit from AI-assisted detection engineering.

The list of AI-powered features now available for free includes the following:

  • Rule/query generation from Threat Report

  • Rule/query generation via Custom Prompt

  • Decision tree summarization

  • Short and full rule/query summarization

  • Query optimization

  • Rule syntax & structural validation

  • MITRE ATT&CK tag prediction

  • Attack Flow generation (Beta)

  • Cross-platform rule translation

  • Supercharging into Roota

Boost Your Translation With External AI Agreement Pop-Up

As part of this major Uncoder AI release, we have enabled SOC Prime users to accept their agreement before using external AI. This pop-up appears only once. We’ve changed the pop-up text as follows: “Only correlation functions, such as aggregation functions, are sent to OpenAI API. The core detection logic and translations are done locally at SOC Prime SOC 2 Type II private AWS cloud segment, so no sensitive data ever leaves our cloud.” By clicking Allow, Uncoder AI users proceed with enabling external AI translation enhancement.

Once allowed, the Translate functions {model name} in the top right-hand corner toggle switch is automatically enabled.

AI Task in Progress

For a better user experience using Uncoder AI, we’ve added a pop-up warning users of an AI task in progress that will not be able to complete and display the results if the user closes the page: “You have an AI-powered content generation task in progress. If you close this page, you won’t be able to view the generation results. If you still want to leave, just click the x icon on the tab again.”

When a user initiates one of the AI Tools options, the close ("X") button on the results panel will be disabled while waiting for the service response.

AI-Assisted Translation of Detection Content Available in TDM and Uncoder AI

With this release, we have generated the translation of all non-Sigma detection rules (e.g., Microsoft Sentinel, Elastic, Splunk native rules & queries) from GitHub repositories into all language formats currently supported by SOC Prime Platform.

Note: AI-powered content translations were generated only for non-Sigma rules present in the SOC Prime Platform repositories. Custom repositories remain unchanged.

Every AI-generated translation now includes a field indicating that it was produced by AI, ensuring transparency about AI-powered content generation. To enhance visibility, an AI-generated icon has been added to indicate AI-assisted translations. This icon will be displayed next to the platform name and all language format names within the chosen platform.

Note: AI-assisted translations are NOT included in Dynamic Content Lists and are NOT used for Attack Detective scans.

Status Icons in Cross-Platform Translation

For a better UX experience using Uncoder AI, the right tab for the selected target language now applies an icon (if applicable) to indicate a specific translation status:

  • A checkmark icon is displayed when the translation is successfully generated and complete

  • An exclamation mark icon if there are translation issues

  • Crossed-out circle icon if the translation fails at all

AI Descriptions for Supported Functions

With this latest release, we’ve enriched Uncoder functionality with descriptions of supported functions that can now be received from AI. This is an additional Uncoder AI-powered enhancement since descriptions were available only for unsupported functions before this release.

AI Tools

As part of the latest Platform release, we’ve added the AI Tools functionality to the interface, which is designed to generate an AI summary of detection code for a better understanding of its logic. Available options are as follows (with the corresponding tooltips):

  • Short Summary: Understand the intent and detection method at a glance.

  • Full Summary: Deep dive into the detection logic and understand all fine points of the query or rule.

  • Decision Tree: Follow the detection logic step by step to understand what exactly the query or rule does.

  • Query Optimization: Get detailed instructions on how to improve your query’s performance.

  • Predict ATT&CK Tags: Enrich the Sigma rule with ML-predicted MITRE ATT&CK tags.

Note: This option is available only when Sigma is selected as the language format.

  • Attack Flow: Visualize the flow of an attack described in a threat report as a flowchart. This functionality is now in BETA, which is indicated with a corresponding label in the interface, and is available for Threat Report or a Custom Prompt.

By clicking the Gear icon, Uncoder AI users can now see a list of models to choose from. To confirm the selection, click Apply.

Note: Currently, a private LLM (llama3.3:70b) is used. In future updates, users will be able to select a private or public model from the options below:

  • deepseek-r1:70b: DeepSeek’s first-generation reasoning model, achieving performance comparable to OpenAI’s o1, with a context window of 128K tokens. Privately hosted by SOC Prime.

  • gpt-4o-mini: A compact version of OpenAI’s GPT-4o, designed for enhanced reasoning capabilities with reduced computational requirements and faster response times. Publicly hosted OpenAI’s model accessed by API.

  • llama3.1:latest: The latest iteration in the Llama series, offering improved scalability and adaptability in AI model parameters. Privately hosted by SOC Prime.

  • llama3.3:70b: A 70-billion parameter model in the Llama series, known for its scalability and adaptability, making it a strong contender in AI model parameter comparisons. Privately hosted by SOC Prime.

  • mistral-large:123b: A 123-billion parameter model by Mistral AI, focusing on high performance and efficiency in natural language processing tasks. Privately hosted by SOC Prime.

  • o3-mini: OpenAI’s compact AI model, emphasizing improved reasoning capabilities at a lower cost, offering faster response times and reduced computational requirements. Publicly hosted OpenAI’s model accessed by API.

New Intelligence Sections

Added the following sections to the rule intelligence from the Platform Repo displayed in Uncoder AI:

  • Short Summary

  • Extended Summary

  • Decision Tree

They are now displayed at the top above the other sections with intelligence.

AI-Assisted Rule Syntax Validation

As part of the SOC Prime Platform 5.16.0 release, we’ve introduced new AI-assisted syntax validation for native detection rules and queries, extending beyond traditional Sigma and Roota support.

The Validate button is now available for all supported source types in the source language drop-down, excluding Threat Report and Custom Prompt. To validate, simply paste your rule into the left-side Uncoder AI panel and click Validate. The AI-generated results will appear on the right panel.

Note: AI-assisted syntax validation is not available for Sigma and Roota. For these formats, the validation that was available before this release is applied.

For full transparency and privacy at every step, when AI is involved in the validation, the result panel includes the following tooltip: “This text has been generated in our secure, privately hosted LLM based on the input detection. Your data did not leave SOC Prime’s infrastructure.”

AI-Assisted Rule Generation

In the SOC Prime Platform 5.16.0 release, we've introduced major enhancements to the Uncoder AI layout and functionality to support AI-powered rule generation from threat reports and custom prompts.

Correspondingly, new source options have been added to Uncoder AI:

  • Threat Report (formerly “IOCs”): Enables IOC extraction and behavior-based rule generation.

  • Custom Prompt: Free-form text used to generate detection rules using natural language input.

Depending on the detected or selected source input, Uncoder AI now displays dynamic options:

  • Translate (shown when source is a known detection language):

    • Translate – Converts a detection rule to a different platform/language.

    • Supercharge – Converts rule to platform-agnostic Roota format with enriched metadata.

  • Generate (shown when source is Threat Report or Custom Prompt):

    • Behavior Rule – Generates a behavioral detection rule from the custom user prompt.

    • IOC Query – Parses indicators of compromise and builds detection queries. (IOC Query option is disabled when the source is Custom Prompt)

Also, Uncoder AI now intelligently detects if the input is a detection rule code, IOC set, or free-form prompt to dynamically present the right generation options.

To improve the user experience in view of the new Uncoder AI functionality, a set of UI improvements has been made:

  • The source and target language drop-downs have been resized and repositioned for better usability.

  • Supercharge mode is now available as a sub-option under the new Translate button.

  • Target language drop-downs are now two-level (Language → Content Type).

  • The third level (Data Schemas) has been moved to the new dedicated drop-down.

  • A new Data Schema drop-down appears only when a target language is selected. This drop-down allows choosing from schema options specific to the selected language.

Note: When choosing the Data Schema, please consider the gap between the data schema applied for translation/generation and the one you are using. To remap, select an alternative schema in the Data Schema drop-down menu or configure and apply a Custom Field Mapping profile under the Gear icon to the right.

Debug Console

With this latest release, we’ve added a Debug Console that displays the following:

  • All system errors

  • All backend messages, including unsupported functions and fields

  • Results of Warden checks

  • Results of the validation in ML

  • All translation issues

By default, the Debug Console panel opens in a semi-collapsed state only when it contains content and clears when the Translate button is clicked or the page is reloaded.

The panel header contains:

  • A red dot if there is content

  • A counter showing the number of items that need debugging (lines)

Improved Detection Content Filtering

After establishing synchronization with new detection content sources, including the official Splunk Security Content GitHub repository, the official Elastic Detection Rules GitHub repository, and public detection feed from HijackLibs, Uncoder AI users can filter out detection rules for listed sources by choosing a corresponding Platform Repo in the drop-down list.

Intra-Vendor Translations with Alternative Mappings

With the latest release, Uncoder AI has been enhanced with the functionality designed to unlock rule translation within the same vendor using different field mappings. This update removes previous limits and lets users switch between mapping profiles without issues.

UI/UX Improvements

With the latest Uncoder AI updates, the target language editor panel now has two tabs:

  • The first one shows Sigma, which is generated automatically

  • Another displays the translation to the selected language format

Other UI/UX enhancements as part of the major Uncoder AI update include the following:

  • The improved source language ML-based autodetection

  • After performing the translation, moving to the target language tab, and then clicking the Translate button again, the Uncoder AI user will remain at the target language tab without being redirected to the Sigma tab.

  • For a better user experience, when clicking a certain word, it will be selected across the entire code.

  • New loading animation for any AI-powered feature within Uncoder AI & Light Search. We’ve also added a status bar with four bars indicating the progress status to improve the user experience.

  • The improved syntax and function highlighting for better readability. Functions in both the source and target languages are now highlighted on hover, with a tooltip displaying the details.

Pricing Updates

With the latest release, we have introduced the following changes to the Threat Detection Marketplace Solo and Uncoder AI Solo subscriptions that involve:

  • Discount for annual subscription changes

  • Price for Uncoder AI Solo subscription

  • Price for Threat Detection Marketplace Solo annual subscription

Key Bug Fixes & Improvements


  • Fixed an issue with translating detections from Sigma to Google SecOps via Uncoder.IO when references were missing in the target language format.

  • Fixed an issue where Uncoder AI displayed a generic error message with wrong platform names instead of a clear explanation when translation failed in some cases..

  • Resolved an issue where a warning about reaching the 500-item limit was in some cases incorrectly displayed when adding a Dynamic Content List from a repository containing fewer than 500 items.

  • Fixed an issue where social media icons on some website pages were broken and hidden in the website sidebar, restoring proper visibility and functionality.

  • Fixed an issue where, in some cases, the Content Author field remained empty in Inventory after manual deployment.

  • Resolved an issue on the Inventory page where, in some cases, tooltips were cropped and formatting was broken in the Edit window when the Content Name contained a single quote symbol.

  • Restored nocase modifier for Chronicle translations using the new mapping.

  • Fixed an issue where, in some cases, during manual query deployment from the Rule page, the query has a NULL body.

  • Fixed an issue where YAML content was truncated after a newline character during content update via Inventory to Azure DevOps.

  • Data type for field extensions.auth.auth_details has been changed to string for Chronicle translations.

  • Resolved issues with rule metadata enrichment, resulting in improper Roota generation when applying Supercharge for Sigma rules.

  • ​​Resolved a translation issue in Threat Detection Marketplace where Microsoft Sentinel alerts and queries used =~ instead of == for fields with 'true' or 'false' values.

  • Fixed the issue where forking content from one custom repo to another resulted in a decrease in available Sigma rules balance. If no Sigma rules balance is available, the fork operation previously failed with an error message. Now, the operation is properly handled.

  • Resolved the issue where users faced a 504 error when attempting to download the SOC 2 Type Report from a corresponding page on the SOC Prime website.

  • Resolved an issue where Elastic detection content was, in some cases, downloaded with incorrect NDJSON formatting (multiline). Now, the content is correctly downloaded in a single-line NDJSON format.

  • Addressed Chronicle duplicates:

    • Added a name check during the validation of previous document existence for Jobs deployment process to prevent discrepancies during deployment. Ensured the system correctly handles deployment of different content with the same name.

    • Implemented detailed logging to inform users of the specific reasons why content did not reach the deployment stage, improving transparency and troubleshooting.

  • Resolved an issue where, in some cases, the Contact Us modal opened without proper layout on some of the Threat Detection Marketplace pages. Now the modal displays correctly across all pages.

  • Fixed the issue with the View Content button on the Inventory page, which is now always available if “SOC Prime Platform is selected as the Source.

  • Improved Uncoder AI messaging, where the description field of Sigma rules containing special characters resulted in the error message "Cannot be automatically converted." Now, users will receive a more informative message: "It seems that the description field of the Sigma rule contains special characters. Please, remove them and try again."

  • When translation cannot be generated at all, the error message is now recorded in the Debug Console to prevent such issues from being treated as translations and saved to the Repo.

  • Fixed the SentinelOne translation issue with two operators (in and Contains).

Did this answer your question?