June 14, 2023
© 2023 SOC Prime Inc.
All rights reserved. This product and documentation related are protected by copyright and distributed under licenses restricting their use, copying, distribution, and decompilation. No part of this product or documentation related may be reproduced in any form or by any means without the prior written authorization of SOC Prime. While every precaution has been taken in the preparation of this book, SOC Prime assumes no responsibility for errors or omissions. This publication and features described herein are subject to change without notice.
Threat Detection Marketplace
Premium Sigma Rule Balance
We've improved premium Sigma rule balance synchronization in the UI to ensure that when a Sigma rule is unlocked, the balance in the Account menu is decreased at once.
CCM API Integration Tool
We've updated the CCM API Integration Tool to v3.1.2. The update includes a fix for the use of the unlock_rules parameter in the search input.
If you use the Tool, please download and install the latest version to ensure it works correctly.
Attack Detective
Demo Investigation
We've added a Demo Investigation so that any user can explore Attack Detective capabilities right after registration, without having to set up an integration with their Data Plane.
The Demo Investigation includes Data Audit and Scan results for a demo environment.
In the Demo Investigation, you can explore most capabilities of Attack Detective:
Check out the finished Investigation overview
See the visibility and blind spots
Drill down to scan details, view queries with hits, and filter them
Demo Investigation does not include access to the scanned Data Plane itself, so hunting with a query to validate a hit and providing feedback through Action Loop are not available.
Once you are ready to add an integration with your Data Plane and run an investigation in your own infrastructure, click Start Investigation.
After your first Investigation is finished, the Demo Investigation will disappear from the list of your investigations.
Tactic View of Blind Spots
On the Blind Spots tab of the Data Audit, we've added another view to present potential gaps in security data.
The Tactic view shows potential issues with log sources broken down by MITRE ATT&CK® tactics and techniques.
Data Audit List
We've added a new page called Data Audit. It lists all Data Audits conducted by your team and is available via the top navigation menu.
For each Data Audit, you can see its basic details and action buttons:
Start Investigation
Logs (written if a Scan has been executed)
Scan details (shown if a Scan has been executed)
Delete
Investigation List Updated
We've updated the details of the Investigations shown on the Investigations page.
Now, for each of your organization's Investigations you can see:
The status, name, and duration of the Investigation
Scan period
Number of launched queries and queries with hits
Data Plane name
Created time and the user who created the Investigation
Content Preparation
We've improved content preparation for scanning the Microsoft Sentinel Data Planes to ensure that relevant table names determined during Data Audit are used in the scan queries.
MITRE ATT&CK® Version
We've updated MITRE ATT&CK used in Attack Detective to v13.1.
Uncoder AI
Navigation from Cyber Threat Search Engine
Now, when a user who has signed up with a personal email opens a Sigma rule in the Cyber Threat Search Engine and clicks Explore More, they are redirected to Uncoder AI with this rule opened in search.
Translate Button
We've simplified and improved the looks of the Translate button.
Home Page
We've expanded the clickable area on the product blocks so that clicking anywhere on the block opens the corresponding product.
Company Website
Page Updates
On the Center of Excellence for Microsoft Sentinel SIEM & SOAR page, we've updated the amount of content for Microsoft Sentinel
On the Leadership page, we've introduced changes according to the current titles and composition of the leadership team
On several outdated pages, redirects have been added
Contact Sales Modal
To ensure a consistent style throughout the pages, we've updated the design of the Contact Sales modal shown in the Add-on section of the Pricing page.
Threat Bounty Program
We've updated the SOC Prime Threat Bounty Program Guide according to the latest Program terms and content development best practices.
Platform Guides
We've redesigned and improved our API Guide to make it more convenient to use.
Cyber Library
We've removed guides in Cyber Library related to deprecated content types.
Key Bug Fixes & Improvements
With this release, we’ve made the following key bug fixes and improvements to enhance the user experience with the SOC Prime Platform:
Fixed bugs in Uncoder AI:
Improved IOC parsing for query generation to ensure that any valid IP addresses are parsed
Fixed a bug where in some cases generating queries based on parsed IOCs resulted in clearing the input
Resolved issues that resulted in showing wrong limitation messages and preventing users with a Community plan from translating between different formats of the same platform
Fixed the Author filter in search. Now you can filter the search results by the following author groups:
Threat Bounty
SigmaHQ
SOC Prime
Note that selecting only the SigmaHQ option lets you see only open-source content with each rule's code accessible for free.
Corrected a spelling mistake in one of the filters
Improved Warden validation checks so that regexes in the detection component of a Sigma rule are not recognized as an error.
Solved an issue where rules sometimes became unavailable in search after changing the number of rules per page in pagination
Fixed bugs in Attack Detective:
Resolved an issue that in some cases could result in the hit number in a heatmap cell not matching the sum of all hits of all related queries
Fixed a bug where Data Audit spider charts were not rendered correctly in new Athena and Elastic Investigations
Fixed a bug where Blind Spots for the Microsoft Windows log source in some cases contained event IDs relevant to Sysmon
Fixed a bug where after navigating to a different page of queries with hits, the list of queries on the page did not change
Fixed a bug with using the unlock_rules parameter in API requests where despite setting the value to true, premium Sigma rule translations were still unavailable for some time
Fixed a bug with GitHub synchronization where in some cases quotation marks could disappear from the Sigma code
