May 17, 2023
© 2023 SOC Prime Inc.
All rights reserved. This product and documentation related are protected by copyright and distributed under licenses restricting their use, copying, distribution, and decompilation. No part of this product or documentation related may be reproduced in any form or by any means without the prior written authorization of SOC Prime. While every precaution has been taken in the preparation of this book, SOC Prime assumes no responsibility for errors or omissions. This publication and features described herein are subject to change without notice.
Content
VMware Carbon Black
We've renamed Carbon Black to VMware Carbon Black to be consistent with the current official naming.
Also, we've added support for the EDR version of Carbon Black. Now, there are two formats of translations available for this platform: Cloud and EDR, with response-legacy and wildcard-enabled alternative translation configs for EDR.
Quality Improvement for Elastic
For Elastic translations, we've removed redundant quotes in .text based fields corresponding to Sigma rule fields that include modifiers and have values combined by the OR operator.
Alternative Translations for Splunk Alerts
We've made all alternative translation configs present for Splunk Query also available for Splunk Alert.
Platform Settings
We've moved Presets, Filters, and API from CCM to Platform Settings. Now, all configurations that work across the SOC Prime Platform live in Platform Settings.
Additionally, Presets, Filters, and API pages were restyled to get the look and feel consistent with those of other pages in Platform Settings.
In particular, edit and delete actions are now implemented as separate icons.
Also, on the Search Profiles page, we've updated the switch name from Use in Search to Make Default to better convey the function of the switch.
Attack Detective
Custom Investigation Period
We've added the possibility to set a custom investigation period. To do it, on the Start New Investigation screen:
Select the Custom option in the Select Investigation Period dropdown.
Set the Start Date and End Date.
Note that the investigation period cannot exceed 90 days.
New Views in Blind Spots
We've added two new views on the Blind Spots tab. They present the same information about gaps that has been available in the Data Components view but break it down in a different way:
Optimization
We've optimized the displaying of the investigation result to ensure it shows the accurate data after the start or end date of the investigation was updated.
Available Queries
On the Visibility tab of the Data Audit, we've added visualization of content from TDM available to the user's company according to the identified log sources. Now, you can easily see how much relevant content is offered on the TDM, and what part of it you can use in your investigation.
To improve the UI and keep the presentation of data clear, we've removed the Detections and Techniques columns.
Automatic Sigma Rule Validation in Uncoder AI
We've improved the wording of several errors and warnings displayed after running the automatic Sigma rule validation checks.
Company Website
Partner Program for Universities
We've added a landing page describing our current partner programs for universities and the opportunities SOC Prime offers to higher education institutions.
Pricing Page
We've aligned buttons in the lower three blocks on the Pricing page ensuring they are positioned at the same height.
Cookie Policy
We've updated our main Cookie Policy and the Cookie Policy for Uncoder.IO. Also, we've added several cookies to the Cookie Settings list.
Cyber Library
We've updated the Community button replacing Slack with Discord, and introduced minor color updates to make the general look more consistent with the SOC Prime Platform colors.
Platform Guides
We've updated the Platform Guides according to the new functionality on the SOC Prime Platform.
Key Bug Fixes & Improvements
With this release, we’ve made the following key bug fixes and improvements to enhance the user experience with the SOC Prime Platform:
Fixed a bug where in some cases the user could not switch to the Code tab or the rule's code wasn't displayed
Fixed a bug where an incorrect mapping was applied to the
ImageLoadedfield during translation from Sumo Logic Query to Sumo Logic Query (OCSF)Updated a tooltip on the Upgrade page that showed the same text both for On Demand and Enterprise subscription plans
Fixed bugs with downloading a report from the Dashboard page:
In some cases, a "Not Found" message was displayed after an attempt to download a report from the Dashboard page
In Firefox, corrupted symbols were displayed on the downloading page and the report was not downloaded
Fixed bugs in Attack Detective:
The calculation of the start time of the scan in some cases began before the investigation actually started
In Amazon Athena investigations, an error was sometimes logged while a query was still running
During automatic log source identification if there was no EventID mapping for a table, the None value was added to the query to get the value of this field
In some cases, a Microsoft Defender for Endpoint scan stopped before all queries were executed
