September 11, 2026
© 2026 SOC Prime Inc.
All rights reserved. This product and documentation related are protected by copyright and distributed under licenses restricting their use, copying, distribution, and decompilation. No part of this product or documentation related may be reproduced in any form or by any means without the prior written authorization of SOC Prime. While every precaution has been taken in the preparation of this book, SOC Prime assumes no responsibility for errors or omissions. This publication and features described herein are subject to change without notice.
Multiple Destination Topics per Pipeline
Users now have the ability to route a pipeline's events to multiple destination topics. Each destination topic can be individually configured on the Create/Edit Pipeline page.
Multiple Correlation Pipelines
Introduced the capability to create more than one Correlation Pipeline, allowing users to separately correlate events coming from different environments and form Attack Chains individually for each of those environments. For more information, please follow the User Guide.
New Role: Viewer
Added a new Viewer role that provides view-only access and prevents users from making changes.
Added new functions to schema parser
parse_leef – Parse events in Log Event Extended Format when configuring a log source
parse_xml – Parse an XML string into a nested dictionary
list_to_dict – Turn a list of objects into a dictionary using two fields as key and value
See the User Guide for detailed descriptions of each function.
Attack Chains: MITRE ATT&CK Search
Attack Chains and Active Threats on the Attack Chains page are now searchable by MITRE ATT&CK technique ID.
Key Bug Fixes and Improvements
Fixed notifications closing automatically and added a close button, allowing users to dismiss notifications manually.
Fixed text overlap issue on the User Management page.
Resolved an issue that caused an Internal Server Error when a Repository was added to a Detection Pipeline.
Fixed an issue where searching for Attack Chains on the Attack Chains page did not display results correctly in Firefox.
Fixed the search functionality in the Mapping (YAML) editor on the Create/Edit Log Source page.
Added the ability to edit a rule opened from the Monitored Threat details page.
Added the ability to view and edit a rule from the Attack Chain details page.
Updated dashboard colors: repository data flows are now yellow, and destination topic data flows are green.
