August 3, 2026
© 2026 SOC Prime Inc.
All rights reserved. This product and documentation related are protected by copyright and distributed under licenses restricting their use, copying, distribution, and decompilation. No part of this product or documentation related may be reproduced in any form or by any means without the prior written authorization of SOC Prime. While every precaution has been taken in the preparation of this book, SOC Prime assumes no responsibility for errors or omissions. This publication and features described herein are subject to change without notice.
Product Renaming
With this release, we’ve introduced new product names as part of our product redesign.
Threat Detection Marketplace → Prime Core
Uncoder AI → Prime Architect
Attack Detective → Prime Hunt
DetectFlow → Prime Detect
The new product names are now reflected across the platform wherever the products are referenced.
MCP Support
Prime Architect (formerly Uncoder AI) now supports the Model Context Protocol (MCP), enabling users to access Prime Architect capabilities directly from their own AI environment through the MCP Server.
By generating an MCP token in Prime Architect, users can connect their AI agents to the MCP Server and use Prime Architect tools without opening Prime Architect interface.
The MCP Server provides authenticated access to Prime Architect capabilities, allowing AI agents to perform detection engineering and threat research tasks directly from supported AI environments.
To connect to the MCP Server, users should provide the following details in their AI environment (the exact steps vary depending on which agent users use):
Name: name to identify this MCP Server connection
Authentication type – Bearer Token
Token – the MCP token
Note: We currently support only Bearer Token authentication. OAuth, OpenID Connect (OIDC) and other authentication methods are currently not supported.
Once connected, user’s AI agent can use the following Prime Architect tools:
Generate Short Summary – Provides a concise human-readable overview of detection logic from a Sigma rule or threat report.
Generate Full Summary – Creates a detailed explanation of detection logic.
Generate Decision Tree – Explains how detection logic works step by step, with all the embeddings, branches, and other intricate logic.
Generate Attack Flow – Transforms threat reports into structured Attack Flows that visualize adversary activity, including MITRE ATT&CK techniques, attack diagrams, and ATT&CK Matrix mappings.
Generate Behavior Rules – Generates Sigma behavior rules from threat reports.
Deep Threat Research – Performs multi-stage threat analysis, including summaries, Attack Flow generation, behavior rule generation, and malicious activity simulations.
Translate – Converts detection rules between supported formats while preserving detection logic.
Optimize Query – Provides recommendations for improving query efficiency.
For details, follow this guide.
Attack Chains in Prime Hunt (formerly Attack Detective)
With this release, we’ve introduced Attack Chains – possible threats inferred by correlating events identified in Prime Hunt scan results. Using agentic AI, Attack Chains identify potential attack patterns and sequences of adversary activity across user’s Data Planes.
To access the Attack Chains, users should navigate to Prime Hunt and select Attack Chains in the header navigation.
Users can configure the correlation engine via Configure on the Attack Chains page by setting up the following:
Threshold for chain forming – Defines the minimum percentage of Higher Order Sigma rule sequences that must be matched with events for a chain to be formed.
Correlation window – Defines the time interval within which detected events must occur to be correlated into an Attack Chain.
Lookback window – Defines how far back in time the system searches for events when analyzing potential Attack Chains.
Include or exclude Data Planes to control which events to use for monitoring
Auto-add New Data Planes For Monitoring to automatically include newly created Data Planes in the monitoring scope.
Enable Transmitting Hostnames to allow to transfer and store hostname data required for Attack Chain correlation in an encrypted form.
Once chains are formed, the Attack Chains tab lists every detected chain, with severity, hostname, Tenant, Data Plane, match percentage, matched rules, first/last seen timestamps, and investigation status.
Opening an Attack Chain gives users access to:
General – An AI-generated summary of the activity, MITRE ATT&CK techniques and threat actors involved, and a visual timeline of techniques over time, including Detection Bypass found via fuzzy matching.
Active Threat – Threat summary, recommended investigation, mitigation, response actions, and its Attack Flow visualization.
Higher Order Sigma Rules – The correlation rule related to the Active Threats item.
On the Monitored Threats tab, users can view the Active Threats items used as the basis for correlation (by default, all Active Threats from the last 35 days are included). Users can enable or disable individual threats, or apply bulk actions to control what to include in monitoring scope.
For more details about Attack Chains, follow this guide.
New Alternative Translation for Crowdstrike Next-Gen SIEM
Added an alternative translation crowdstrike for CrowdStrike Next-Gen SIEM Query. The crowdstrike alternative translation can now be selected:
Uncoder IO Website
With this release, we’ve updated the Uncoder IO website, since access to Uncoder IO has been closed.
Updated Website Homepage
With this release, we’ve redesigned the website homepage with a refreshed interface and improved visual design.
Integrations and Filters Pages Enhancements
With this release, we’ve introduced the following enhancements to the Integrations and Filters pages on SOC Prime Platform.
To provide a more consistent user experience, we've replaced the action icons with a three-dot menu on the pages in Platform Settings. To edit or delete an item, users should click the three-dot menu next to it and select the desired action.
Updated the messaging on the Restricted Access pages shown to users who don't have access to those Integrations and Filters modules in the SOC Prime Platform. These pages now include descriptive, benefit-oriented headlines that provide a clearer overview of the modules' capabilities. Additionally, we’ve improved visual consistency of the pages by aligning section titles, font sizes, and image sizes.
Improved the pages experience by automatically scrolling to the top of the page when changing pages.
Key Bug Fixes and Improvements
Resolved an issue where rules containing field ImageLoaded were mapped incorrectly when translating to other platforms.
Moved the content that matches the condition tags.author:"Matt Zorich" to the Community repository.
Fixed an issue where tactics sorting in Data Audit Blind Spots did not match the spider chart after updating to MITRE ATT&CK version 19.
Fixed an UI issue where the threat attributes on the Active Threats News Item page were displayed without their corresponding icons.
Fixed an issue in Agentic Threat Research where step execution did not work correctly when using the Attack Flow tool.
Improved scan result performance and product reliability in Prime Hunt.
