April 3, 2024
© 2024 SOC Prime Inc.
All rights reserved. This product and documentation related are protected by copyright and distributed under licenses restricting their use, copying, distribution, and decompilation. No part of this product or documentation related may be reproduced in any form or by any means without the prior written authorization of SOC Prime. While every precaution has been taken in the preparation of this book, SOC Prime assumes no responsibility for errors or omissions. This publication and features described herein are subject to change without notice.
Threat Detection Marketplace
Premium Rules not Granted for Free Anymore
We've terminated the free granting of two Premium Sigma rules per month to organizations under the Community subscription. However, they can still access all the freely available content from SigmaHQ and Microsoft Sentinel repositories.
New Alternative Translation for QRadar
We've added a new alternative translation config for IBM QRadar Queries called Non-UTF8-payload. It uses the default field mapping for QRadar, but if a field is missing from the mapping, the field from Sigma is used.
The new alternative translation has been added to part of the relevant content. The rest of the relevant content will get it soon.
Uncoder AI
Content Deploy
We've added the capability to deploy content in the following formats:
Microsoft Sentinel
Query
Rule
Chronicle Security Rule
Elastic Stack
Detection Rule (Lucene)
Detection Rule (EQL)
Saved Search
Watcher
To deploy a content item, click the Deploy icon. In the modal that appears:
Choose the Data Plane for deployment.
Optionally customize the content name. Use this field for custom content that has not been saved to a repository. Note that when you deploy a content item from a Platform or Custom repository, this value will be overwritten by the title of the saved content item.
Click Deploy.
Open Queries from The Prime Hunt
Now you can open a query parsed in The Prime Hunt directly in Uncoder AI passing the code as part of the URL.
Translation Engine Improvements
Microsoft Defender for Endpoint Query. We've added support for verbatim string literals when translating from this format
FortiSIEM Rule. We've improved translations into this format:
Adopted XML format for GUI
Removed quotes around values when the attribute type in FortiSIEM is INT/IP
Implemented correct rendering of AND NOT / OR NOT operators
LogRhythm Axon Query. We've improved the escaping of special characters
Design Improvements
We've updated the Uncoder AI logo and removed outdated hexagon icons at the bottom of the page.
Key Bug Fixes & Improvements
With this release, we’ve made the following key bug fixes and improvements to enhance the user experience with the SOC Prime Platform:
Now the Timeline is preserved when you copy a content item from a Platform repository to a custom repository
Added proper handling of invalid JSON errors while deploying an Elastic Detection Rule
Resolved an issue that under certain conditions prevented enabling SSO with an Invalid Response error
Removed the LR 7 Query (Lucene) option from the LogRhythm group in the target selection dropdown of Uncoder AI since the translation engine for this language requires improvement
Fixed issues with adaptive layout on the Presets and Custom Field Mapping pages
Fixed a bug where some content items were duplicated in the email about new and updated content
