July 21, 2026
© 2026 SOC Prime Inc.
All rights reserved. This product and documentation related are protected by copyright and distributed under licenses restricting their use, copying, distribution, and decompilation. No part of this product or documentation related may be reproduced in any form or by any means without the prior written authorization of SOC Prime. While every precaution has been taken in the preparation of this book, SOC Prime assumes no responsibility for errors or omissions. This publication and features described herein are subject to change without notice.
GitLab Integration
DetectFlow now supports integration with GitLab, allowing users to synchronize Sigma rules from GitLab projects. Follow the DetectFlow user guide for more details.
Push Control for Threat Detection Marketplace Integration
Added the ability to control whether changes made in DetectFlow are pushed to the SOC Prime Platform. Introduced the Push toggle, allowing users to disable pushing local changes from DetectFlow to the custom repository in Threat Detection Marketplace.
Windows Event Log Parsing for QRadar
Added the parse_wincollect_win_event_log parsing function to support parsing Windows event logs forwarded from QRadar.
Bug Fixes and Improvements
Fixed an issue where synchronization with Threat Detection Marketplace custom repositories could fail in some cases.
Removed the use of port 22 for GitHub SigmaHQ connection health checks, now using only port 443.
