June 27, 2023
© 2023 SOC Prime Inc.
All rights reserved. This product and documentation related are protected by copyright and distributed under licenses restricting their use, copying, distribution, and decompilation. No part of this product or documentation related may be reproduced in any form or by any means without the prior written authorization of SOC Prime. While every precaution has been taken in the preparation of this book, SOC Prime assumes no responsibility for errors or omissions. This publication and features described herein are subject to change without notice.
New Subscription Plans
We've updated some of our subscription plans and added new offerings. You can find more details on each current plan on the redesigned Pricing page.
Each product now has its own Community, OnDemand, and Enterprise plans presented on a separate tab on the Pricing page.
In particular, we've updated the terms of the Threat Detection Marketplace (TDM) OnDemand plan. Now, it gives access to detection content in just 24 hours after its release, includes 200 Sigma rules of your choice, and offers unlimited TDM functionality.
Also, we are glad to announce a special version of TDM Enterprise named Threat Informed Defense. In addition to 100 rules of your choice, it includes 1,000 pre-selected rules to detect Bear, Panda, and Kitten families of threat actors.
As for Attack Detective, we've added an OnDemand plan that provides your organization with 12 investigations per month and much more content to use for scanning.
Note that old subscription plans that are not offered anymore remain valid until they expire.
Threat Detection Marketplace
Alternative Translations for QRadar
As part of continually expanding the range of supported detection content formats, we've added a new config for alternative translations into QRadar with data schema alias v7.4.3.
Connection Check
We've added a connection check feature to the Microsoft Defender for Endpoint Data Planes. Click the Check Connection action button next to a Data Plane of this type to ensure the configured integration works fine.
If your Data Plane is disconnected, you'll see an error message specifying whether the issue is with the used credentials or the lack of required permissions.
History Export
In the History section of Automation, you can now export your history records. Click the export button, and a CSV with your history records will be saved.
Note that the scope of data for export corresponds to the scope of data currently visible on the selected page in the History section. This is intended to prevent the creation of extra-large export files.
Icons for Automation Sections
We've added icons next to the section names in Automation to improve the design and make section selection more intuitive.
Uncoder AI
Support for Splunk Alert Reverse Translations
We've added support for reverse translations from Splunk Alert into multiple platform-specific formats.
To see all available output formats, select Splunk Alert with default data schema as your input format and open the output format dropdown.
Sigma as a Reverse Translation Output
We've added Sigma as an output format option for all input formats with reverse translation supported.
Community Plan Capabilities
We've updated the number of parsed IOCs for queries available under a Community plan to 20.
Additionally, the limitations of some features in Uncoder.IO also changed and now are as follows:
5 automatic Sigma rule checks with Green Warden
2 IOC-based query generations
10 parsed IOCs can be used for queries
Autocomplete
We've made the autocomplete window larger to ensure this feature is convenient for every security practitioner.
Company Website
Capitalization in Menu Items
We've made the subtitle capitalization approach consistent across all menu items.
Link for Feedback
On the Cyber Threat Search Engine page, we've added a link to our Discord channel where users can provide feedback on the detection content.
Leadership Page
We've updated the Investors/Advisors section on the Leadership page by adding a new advisor.
Uncoder.IO
We've made limitation messages in popups more informative and added a button to sign up on the SOC Prime Platform and use the free plan of Uncoder AI with more capabilities offered right away.
Key Bug Fixes & Improvements
With this release, we’ve made the following key bug fixes and improvements to enhance the user experience with the SOC Prime Platform:
Fixed bugs in Uncoder AI:
Fixed a bug where the Uncoder AI title in some cases disappeared from the product selection menu in the header after it was clicked
Removed IOCs as an output option for Sigma input since this combination is impossible
Fixed a bug where after unlocking a premium Sigma rule via Uncoder AI, the button that displays the rule's intelligence was inactive until the rule was reloaded
Removed the possibility to have Workbooks in the Inventory section of Automation since this content type is not supported anymore.
Updated the text on tooltips for dots that indicate whether techniques/sub-techniques in MITRE ATT&CK® Coverage or services in Log Source Coverage are addressed/not addressed. Previously, the tooltip repeated the corresponding technique/sub-technique or service name, and now it states whether they are addressed or not addressed
Resolved an issue with saving certain values in the Platform field of Search Profiles that resulted in no content matching an affected Profile applied in MITRE ATT&CK Coverage or Log Source Coverage
Fixed a bug on Leaderboards where a wrong amount of content released in March 2022 was displayed
Resolved an issue where the Search Result statistics in some cases did not update after applying a Search Profile
Resolved an issue where after opening the Contacts modal from the footer on the Search page and then closing it, the Filters block disappeared and the user was logged out if they refreshed the page
Fixed a bug where the top navigation menu item that corresponded to the current page was not highlighted on some pages
Fixed account menu overlapping on the Your Account page
Fixed an issue where the title of the Center of Excellence for Amazon Web Services page was not displayed in full in a preview on LinkedIn
Resolved an issue in the TDM search bar where after removing the applied search term and clicking on the search icon the search results were not updated to all TDM content
