Skip to main content

SOC Prime Platform Product Release Notes 6.3.2

N
Written by Nataliia Pukaliak

August 20, 2026

© 2026 SOC Prime Inc.

All rights reserved. This product and documentation related are protected by copyright and distributed under licenses restricting their use, copying, distribution, and decompilation. No part of this product or documentation related may be reproduced in any form or by any means without the prior written authorization of SOC Prime. While every precaution has been taken in the preparation of this book, SOC Prime assumes no responsibility for errors or omissions. This publication and features described herein are subject to change without notice.

CrowdStrike Next-Gen SIEM Integration


With this release, we’ve introduced a new integration with CrowdStrike Next-Gen SIEM, now available in Prime Core and Prime Architect.

  • Added the ability to add a new Data Plane for CrowdStrike Next-Gen SIEM, configurable from the Data Plane page.

  • Added crowdstrike-ng-rule as a new content type, with a corresponding CrowdStrike Next-Gen SIEM Rule content type now available on the Detection Rule page.

  • Detection rules can now be deployed to CrowdStrike Next-Gen SIEM either manually or automatically, including directly from the Detection Rule page.

  • CrowdStrike Next-Gen SIEM Rule can now be selected in the platform filter on the Search page.

  • CrowdStrike Next-Gen SIEM can now be selected as a platform when creating or editing a Job.

  • CrowdStrike Next-Gen SIEM (Rule) is now available in the Platform dropdown in Presets.

  • CrowdStrike Next-Gen SIEM Rule is now available as a target language in Prime Architect, enabling users to translate detection rules from other languages into CrowdStrike Next-Gen SIEM Rule syntax and save the translated content to a custom repository.

Prime Architect


Deep Threat Research Updates

We've enhanced Deep Threat Research by introducing additional threat visualizations. Deep Threat Research now includes the following visualizations of adversary activity derived from analyzed threat reports and based on established threat intelligence frameworks and models.

Cyber Kill Chain

Cyber Kill Chain visualizes the seven stages of the Lockheed Martin Cyber Kill Chain: Reconnaissance, Weaponization, Delivery, Exploitation, Installation, Command & Control, and Actions on Objectives. The visualization shows how the analyzed threat progresses through the attack lifecycle, helping users understand which stages of the Cyber Kill Chain the analyzed threat covers and identify potential detection opportunities. By clicking each stage, users can view its role in the chain and the typical adversary tradecraft involved.

Pyramid of Pain

Pyramid of Pain visualizes six tiers of threat indicators ranked by the level of difficulty they create for adversaries when detected and blocked: Hash Values, IP Addresses, Domain Names, Network/Host Artifacts, Tools, and Tactics, Techniques, and Procedures (TTPs). The visualization helps users explore extracted indicators from the analyzed threat and assess their impact on adversary operations.

By clicking each tier, users can view the corresponding indicators.

Diamond Model

Diamond Model visualization represents the four core elements of threat activity – Adversary, Capability, Victim, and Infrastructure, extracted from the analyzed report and shows relationships between them. It helps users analyze connections between threat entities and explore additional event context through meta-features such as Phase, Result, Direction, Methodology, and Confidence.

By clicking any vertex, users can view the list of entities associated with that vertex.

Web Search

We're continuously adding new capabilities to the Agentic Threat Research in Prime Architect and with this release, we’ve added a Web Search option enabling the AI model to search the internet for relevant information in addition to its internal knowledge base, providing more up-to-date and comprehensive responses. For example, users can use this functionality to retrieve the latest information on recent CVEs, emerging threats, new threat actor campaigns, or current cybersecurity news and research.

To enable this functionality, click the plus (+) icon in the chat input field and turn on the Web Search toggle.

AI Response Actions

Prime Architect now provides additional actions for AI responses. Hover over a response to access the following options:

  • Copy – Copies the response to the clipboard

  • Download – Downloads the response as a .txt file

  • Retry – Opens options to Search the Web, Think longer, or Try again

These options make it easier to reuse, save, or regenerate responses without manually selecting and reformatting the text.

Prime Hunt


LogTotal Sanitizer

LogTotal is now available in Prime Hunt > Event Analysis, allowing users to securely sanitize security logs (hostnames, IPs, credentials, file paths, and more) before further analysis.

With this first iteration, users can upload or paste log data, select which sensitive entities to sanitize, and preview the results before downloading the sanitized file.

In the second iteration, the sanitized logs will be checked against tens of thousands of behavior rules, with matches correlated around Higher Order Sigma rules to surface active threats and correlate detected MITRE ATT&CK techniques.

To use LogTotal:

Go to Prime Hunt > Event Analysis and provide log data using one of the following options:

  • Upload a file: On the File tab, select Choose File, then select a log file from your device.

  • Paste log text: On the Text tab, paste logs data into the text field, and select Configure Sanitization.

After providing logs:

  1. In the modal, choose what gets replaced in logs by selecting the corresponding checkboxes.

  2. Configure a Sanitization key. A key is generated automatically. You can leave the generated key or enter your own.

  3. Select Sanitize & Preview.

  4. Review the sanitized logs. Drag the divider to compare the original and sanitized versions.

  5. Select Details to view and customize the replacements made during sanitization.

    In the modal:

    • Clear the checkboxes for any sanitized entities that you want to exclude from sanitization.

    • Add additional values that you want to sanitize.

    Select Re-run Sanitization to apply the updated replacement settings and generate a new sanitized result, or select Save to save the current sanitized result as a file.

  6. Select View Sanitized File to download the sanitized file.

Supported file types: .log, .json, .jsonl, .evtx, .txt

Maximum size: 3 GB or 3,000,000 events

New API Endpoint: GET /v1/content-coverage/get-coverage


With this release, we’ve introduced a new API endpoint GET /v1/content-coverage/get-coverage that allows users to run content coverage calculations and return the results as a CSV file or as an ATT&CK Navigator JSON layer.

The required parameters:

type – Specifies the type of content coverage to calculate. Available values:

  • mitre – MITRE ATT&CK Coverage

  • ls – Log Source Coverage

answer_format – Specifies the format of the coverage results. Available values:

  • attack_navigator – ATT&CK Navigator JSON

  • csv – CSV

search_profile_name – Specifies the search profile to use for the coverage calculation

Bug Fixes and Improvements


  • Fixed the display of chat titles in the chat list in Prime Architect to use spacing correctly.

  • Added titles to the rule tiles displayed in AI-generated results in Prime Architect.

  • A large block of text pasted into the chat input area in Prime Architect is now automatically converted into an attached file instead of being inserted directly into the chat.

  • Fixed an issue where the Check Connection functionality on the Integrations page sometimes resulted in incorrect error messages.

  • Fixed an issue that sometimes resulted in translation error from Google SecOps Rule (YARA-L) to Microsoft Sentinel Rule (YML).

  • Introduces several enhancements to the website, including:

    • Improved user experience by making SOC Prime Platform category default in the Blog section.

    • Moved the Active Threats section from Resources to the main menu and moved the Ecosystem section from the main menu to the Resources submenu.

    • Fixed the positioning of the image on the homepage.

    • Updated the button hover effects on the homepage to ensure consistency with the rest of the website.

  • Fixed an issue where the chat name in Prime Architect sometimes was displayed incorrectly.

  • Updated the comment in CrowdStrike Next-Gen SIEM Rules to start with #.

  • Fixed an issue where FortiSIEM XML Rule was sometimes displayed in an incorrect format in History.

  • Fixed an issue where, in some cases, the Translate button in the Agentic Threat Research mode was disabled.

  • Fixed an issue where sometimes the Threat of the Month item in the Related Threats section on the Active Threat News Item page could not be opened.

  • Fixed an issue where sometimes Dynamic Content Lists created with Lucene queries remained in a loading state and were not populated with matching rules.

  • Fixed issues that could occasionally occur in Automation, including:

    • Fixed a runtime error ('NoneType' object has no attribute 'decrypt') during job deployment.

    • Fixed runtime errors ('NoneType' object has no attribute 'encode' and IndexError: Replacement index 1 out of range for positional args tuple) during job deployment related to Elastic Stack.

    • Fixed a runtime issue ('NoneType' object is not iterable) during job deployment related to Microsoft Sentinel.

    • Fixed job deployment errors related to Azure DevOps integration: Cannot decode credentials and BaseContentList error: 'fortisiem_platform'", 'execute_content_list'.

Did this answer your question?