Skip to main content

SOC Prime Platform Product Release Notes 5.8.0

S
Written by Sergey Bayrachny

June 27, 2023

© 2023 SOC Prime Inc.

All rights reserved. This product and documentation related are protected by copyright and distributed under licenses restricting their use, copying, distribution, and decompilation. No part of this product or documentation related may be reproduced in any form or by any means without the prior written authorization of SOC Prime. While every precaution has been taken in the preparation of this book, SOC Prime assumes no responsibility for errors or omissions. This publication and features described herein are subject to change without notice.

New Subscription Plans


We've updated some of our subscription plans and added new offerings. You can find more details on each current plan on the redesigned Pricing page.

Each product now has its own Community, OnDemand, and Enterprise plans presented on a separate tab on the Pricing page.

In particular, we've updated the terms of the Threat Detection Marketplace (TDM) OnDemand plan. Now, it gives access to detection content in just 24 hours after its release, includes 200 Sigma rules of your choice, and offers unlimited TDM functionality.

Also, we are glad to announce a special version of TDM Enterprise named Threat Informed Defense. In addition to 100 rules of your choice, it includes 1,000 pre-selected rules to detect Bear, Panda, and Kitten families of threat actors.

As for Attack Detective, we've added an OnDemand plan that provides your organization with 12 investigations per month and much more content to use for scanning.

Note that old subscription plans that are not offered anymore remain valid until they expire.

Threat Detection Marketplace


Alternative Translations for QRadar

As part of continually expanding the range of supported detection content formats, we've added a new config for alternative translations into QRadar with data schema alias v7.4.3.

Connection Check

We've added a connection check feature to the Microsoft Defender for Endpoint Data Planes. Click the Check Connection action button next to a Data Plane of this type to ensure the configured integration works fine.

If your Data Plane is disconnected, you'll see an error message specifying whether the issue is with the used credentials or the lack of required permissions.

History Export

In the History section of Automation, you can now export your history records. Click the export button, and a CSV with your history records will be saved.

Note that the scope of data for export corresponds to the scope of data currently visible on the selected page in the History section. This is intended to prevent the creation of extra-large export files.

Icons for Automation Sections

We've added icons next to the section names in Automation to improve the design and make section selection more intuitive.

Uncoder AI


Support for Splunk Alert Reverse Translations

We've added support for reverse translations from Splunk Alert into multiple platform-specific formats.

To see all available output formats, select Splunk Alert with default data schema as your input format and open the output format dropdown.

Sigma as a Reverse Translation Output

We've added Sigma as an output format option for all input formats with reverse translation supported.

Community Plan Capabilities

We've updated the number of parsed IOCs for queries available under a Community plan to 20.

Additionally, the limitations of some features in Uncoder.IO also changed and now are as follows:

  • 5 automatic Sigma rule checks with Green Warden

  • 2 IOC-based query generations

  • 10 parsed IOCs can be used for queries

Autocomplete

We've made the autocomplete window larger to ensure this feature is convenient for every security practitioner.

Company Website


Capitalization in Menu Items

We've made the subtitle capitalization approach consistent across all menu items.

Link for Feedback

On the Cyber Threat Search Engine page, we've added a link to our Discord channel where users can provide feedback on the detection content.

Leadership Page

We've updated the Investors/Advisors section on the Leadership page by adding a new advisor.

Uncoder.IO


We've made limitation messages in popups more informative and added a button to sign up on the SOC Prime Platform and use the free plan of Uncoder AI with more capabilities offered right away.

Key Bug Fixes & Improvements


With this release, we’ve made the following key bug fixes and improvements to enhance the user experience with the SOC Prime Platform:

  • Fixed bugs in Uncoder AI:

    • Fixed a bug where the Uncoder AI title in some cases disappeared from the product selection menu in the header after it was clicked

    • Removed IOCs as an output option for Sigma input since this combination is impossible

    • Fixed a bug where after unlocking a premium Sigma rule via Uncoder AI, the button that displays the rule's intelligence was inactive until the rule was reloaded

  • Removed the possibility to have Workbooks in the Inventory section of Automation since this content type is not supported anymore.

  • Updated the text on tooltips for dots that indicate whether techniques/sub-techniques in MITRE ATT&CK® Coverage or services in Log Source Coverage are addressed/not addressed. Previously, the tooltip repeated the corresponding technique/sub-technique or service name, and now it states whether they are addressed or not addressed

  • Resolved an issue with saving certain values in the Platform field of Search Profiles that resulted in no content matching an affected Profile applied in MITRE ATT&CK Coverage or Log Source Coverage

  • Fixed a bug on Leaderboards where a wrong amount of content released in March 2022 was displayed

  • Resolved an issue where the Search Result statistics in some cases did not update after applying a Search Profile

  • Resolved an issue where after opening the Contacts modal from the footer on the Search page and then closing it, the Filters block disappeared and the user was logged out if they refreshed the page

  • Fixed a bug where the top navigation menu item that corresponded to the current page was not highlighted on some pages

  • Fixed account menu overlapping on the Your Account page

  • Fixed an issue where the title of the Center of Excellence for Amazon Web Services page was not displayed in full in a preview on LinkedIn

  • Resolved an issue in the TDM search bar where after removing the applied search term and clicking on the search icon the search results were not updated to all TDM content

Did this answer your question?