Skip to main content

SOC Prime Platform Product Release Notes 5.0.6

S
Written by Sergey Bayrachny

December 1, 2021

© 2021 SOC Prime Inc.

All rights reserved. This product and documentation related are protected by copyright and distributed under licenses restricting their use, copying, distribution, and decompilation. No part of this product or documentation related may be reproduced in any form or by any means without the prior written authorization of SOC Prime. While every precaution has been taken in the preparation of this book, SOC Prime assumes no responsibility for errors or omissions. This publication and features described herein are subject to change without notice.

Carbon Black Alternative Translation


With this release, we've made Response Query an alternative translation for Carbon Black and added Carbon Black Enterprise EDR as the original config. This further expands security professionals' capabilities for detection content customization.

Response Query can now be selected from the Config drop-down on the Code tab of a content item page.

Open Distro for Elasticsearch Support


With the latest release, we continue to widen the range of available detection formats, meeting the needs of security experts. This time, we've added support of Open Distro for Elasticsearch security operation platform. Two content types are available: Query and Rule.

For now, security professionals can search for detections tailored to this platform format in the Threat Detection Marketplace and leverage Uncoder.IO for on-the-fly content conversions.

Keeping Selected Sorting in Quick Hunt


With this release, we've enriched the Quick Hunt module with the ability to remember a custom sorting option set by the user. When the security performer selects a certain option in the Sort drop-down, leaves the Quick Hunt page and then returns to it, this sorting option is kept instead of setting it to a default Trending Now value.

Key Bug Fixes & Improvements


With this release, we’ve made the following key bug fixes and improvements to enhance the user experience with the SOC Prime Platform:

  • Fixed the field selection in the search bar. Previously, after selecting an option, it was sometimes impossible to unselect it or select another one.

  • Resolved the issue with applying presets to Splunk detections. Previously, there were cases when incorrect parsing of presets for Splunk could lead to syntax errors after applying those presets to detection content.

  • Fixed the search link validation for Chronicle Security in Uncoder CTI. In earlier versions, drilling down to this platform sometimes resulted in a 404 error because a redundant slash was added to the link provided in the Environment setup.

  • Resolved the issue with query generation for Chronicle Security in Uncoder CTI that occurred in some cases when uploading a file with IOCs.

  • Fixed content deployment to Sumo Logic, which could fail under some configurations.

Did this answer your question?