Skip to main content

SOC Prime Platform Product Release Notes 5.10.4

S
Written by Sergey Bayrachny

April 3, 2024

© 2024 SOC Prime Inc.

All rights reserved. This product and documentation related are protected by copyright and distributed under licenses restricting their use, copying, distribution, and decompilation. No part of this product or documentation related may be reproduced in any form or by any means without the prior written authorization of SOC Prime. While every precaution has been taken in the preparation of this book, SOC Prime assumes no responsibility for errors or omissions. This publication and features described herein are subject to change without notice.

Threat Detection Marketplace


Premium Rules not Granted for Free Anymore

We've terminated the free granting of two Premium Sigma rules per month to organizations under the Community subscription. However, they can still access all the freely available content from SigmaHQ and Microsoft Sentinel repositories.

New Alternative Translation for QRadar

We've added a new alternative translation config for IBM QRadar Queries called Non-UTF8-payload. It uses the default field mapping for QRadar, but if a field is missing from the mapping, the field from Sigma is used.

The new alternative translation has been added to part of the relevant content. The rest of the relevant content will get it soon.

Uncoder AI


Content Deploy

We've added the capability to deploy content in the following formats:

  • Microsoft Sentinel

    • Query

    • Rule

  • Chronicle Security Rule

  • Elastic Stack

    • Detection Rule (Lucene)

    • Detection Rule (EQL)

    • Saved Search

    • Watcher

To deploy a content item, click the Deploy icon. In the modal that appears:

  1. Choose the Data Plane for deployment.

  2. Optionally customize the content name. Use this field for custom content that has not been saved to a repository. Note that when you deploy a content item from a Platform or Custom repository, this value will be overwritten by the title of the saved content item.

  3. Click Deploy.

Open Queries from The Prime Hunt

Now you can open a query parsed in The Prime Hunt directly in Uncoder AI passing the code as part of the URL.

Translation Engine Improvements

  • Microsoft Defender for Endpoint Query. We've added support for verbatim string literals when translating from this format

  • FortiSIEM Rule. We've improved translations into this format:

    • Adopted XML format for GUI

    • Removed quotes around values when the attribute type in FortiSIEM is INT/IP

    • Implemented correct rendering of AND NOT / OR NOT operators

  • LogRhythm Axon Query. We've improved the escaping of special characters

Design Improvements

We've updated the Uncoder AI logo and removed outdated hexagon icons at the bottom of the page.

Key Bug Fixes & Improvements


With this release, we’ve made the following key bug fixes and improvements to enhance the user experience with the SOC Prime Platform:

  • Now the Timeline is preserved when you copy a content item from a Platform repository to a custom repository

  • Added proper handling of invalid JSON errors while deploying an Elastic Detection Rule

  • Resolved an issue that under certain conditions prevented enabling SSO with an Invalid Response error

  • Removed the LR 7 Query (Lucene) option from the LogRhythm group in the target selection dropdown of Uncoder AI since the translation engine for this language requires improvement

  • Fixed issues with adaptive layout on the Presets and Custom Field Mapping pages

  • Fixed a bug where some content items were duplicated in the email about new and updated content

Did this answer your question?