Skip to main content

SOC Prime Platform Product Release Notes 5.7.5

S
Written by Sergey Bayrachny

May 17, 2023

© 2023 SOC Prime Inc.

All rights reserved. This product and documentation related are protected by copyright and distributed under licenses restricting their use, copying, distribution, and decompilation. No part of this product or documentation related may be reproduced in any form or by any means without the prior written authorization of SOC Prime. While every precaution has been taken in the preparation of this book, SOC Prime assumes no responsibility for errors or omissions. This publication and features described herein are subject to change without notice.

Content


VMware Carbon Black

We've renamed Carbon Black to VMware Carbon Black to be consistent with the current official naming.

Also, we've added support for the EDR version of Carbon Black. Now, there are two formats of translations available for this platform: Cloud and EDR, with response-legacy and wildcard-enabled alternative translation configs for EDR.

Quality Improvement for Elastic

For Elastic translations, we've removed redundant quotes in .text based fields corresponding to Sigma rule fields that include modifiers and have values combined by the OR operator.

Alternative Translations for Splunk Alerts

We've made all alternative translation configs present for Splunk Query also available for Splunk Alert.

Platform Settings


We've moved Presets, Filters, and API from CCM to Platform Settings. Now, all configurations that work across the SOC Prime Platform live in Platform Settings.

Additionally, Presets, Filters, and API pages were restyled to get the look and feel consistent with those of other pages in Platform Settings.

In particular, edit and delete actions are now implemented as separate icons.

Also, on the Search Profiles page, we've updated the switch name from Use in Search to Make Default to better convey the function of the switch.

Attack Detective


Custom Investigation Period

We've added the possibility to set a custom investigation period. To do it, on the Start New Investigation screen:

  1. Select the Custom option in the Select Investigation Period dropdown.

  2. Set the Start Date and End Date.

Note that the investigation period cannot exceed 90 days.

New Views in Blind Spots

We've added two new views on the Blind Spots tab. They present the same information about gaps that has been available in the Data Components view but break it down in a different way:

  • By log sources

  • By tools

Optimization

We've optimized the displaying of the investigation result to ensure it shows the accurate data after the start or end date of the investigation was updated.

Available Queries

On the Visibility tab of the Data Audit, we've added visualization of content from TDM available to the user's company according to the identified log sources. Now, you can easily see how much relevant content is offered on the TDM, and what part of it you can use in your investigation.

To improve the UI and keep the presentation of data clear, we've removed the Detections and Techniques columns.

Automatic Sigma Rule Validation in Uncoder AI


We've improved the wording of several errors and warnings displayed after running the automatic Sigma rule validation checks.

Company Website


Partner Program for Universities

We've added a landing page describing our current partner programs for universities and the opportunities SOC Prime offers to higher education institutions.

Pricing Page

We've aligned buttons in the lower three blocks on the Pricing page ensuring they are positioned at the same height.

Cookie Policy

We've updated our main Cookie Policy and the Cookie Policy for Uncoder.IO. Also, we've added several cookies to the Cookie Settings list.

Cyber Library


We've updated the Community button replacing Slack with Discord, and introduced minor color updates to make the general look more consistent with the SOC Prime Platform colors.

Platform Guides


We've updated the Platform Guides according to the new functionality on the SOC Prime Platform.

Key Bug Fixes & Improvements


With this release, we’ve made the following key bug fixes and improvements to enhance the user experience with the SOC Prime Platform:

  • Fixed a bug where in some cases the user could not switch to the Code tab or the rule's code wasn't displayed

  • Fixed a bug where an incorrect mapping was applied to the ImageLoaded field during translation from Sumo Logic Query to Sumo Logic Query (OCSF)

  • Updated a tooltip on the Upgrade page that showed the same text both for On Demand and Enterprise subscription plans

  • Fixed bugs with downloading a report from the Dashboard page:

    • In some cases, a "Not Found" message was displayed after an attempt to download a report from the Dashboard page

    • In Firefox, corrupted symbols were displayed on the downloading page and the report was not downloaded

  • Fixed bugs in Attack Detective:

    • The calculation of the start time of the scan in some cases began before the investigation actually started

    • In Amazon Athena investigations, an error was sometimes logged while a query was still running

    • During automatic log source identification if there was no EventID mapping for a table, the None value was added to the query to get the value of this field

    • In some cases, a Microsoft Defender for Endpoint scan stopped before all queries were executed

Did this answer your question?