May 29, 2024
© 2024 SOC Prime Inc.
All rights reserved. This product and documentation related are protected by copyright and distributed under licenses restricting their use, copying, distribution, and decompilation. No part of this product or documentation related may be reproduced in any form or by any means without the prior written authorization of SOC Prime. While every precaution has been taken in the preparation of this book, SOC Prime assumes no responsibility for errors or omissions. This publication and features described herein are subject to change without notice.
ToS Updated
We've updated the SOC Prime Platform Terms of Service to include clauses that relate to new functionality.
Threat Detection Marketplace
Import from File
We've added a possibility to import content from a file into a custom repository. Currently, this functionality is supported only for QRadar Rules (as XML files).
To use the new feature:
Go to Threat Detection Marketplace > Search.
Click Import Content.
The Import Content modal appears. In the Import To dropdown select the repository you've created for importing your content.
Click Browse File to select the file with content you've exported from your SIEM.
Wait until the file is ready and click Import.
The file is parsed. Once the parsing is done, click Finish.
The content is imported. Your repository with imported content is displayed.
Support for Hunters
We've added support for the Hunters platform. Now, you can:
Find Hunters translations in Threat Detection Marketplace
Translate from Sigma, Roota, and supported platform-specific formats into Hunters and save the translation in a custom repository in Uncoder AI
Share Repository with SOC Prime
Now, clients can share the content of their custom repositories with SOC Prime for professional services. This option is available only to users with a Manager role.
To enable sharing:
Open the settings of your custom repository.
In the Additional Access Settings, enable the Share to SOC Prime switch to grant SOC Prime access to your repository, and set the sharing period.
Save changes.
You can enable or disable this setting at any time by editing the repository settings.
Uncoder AI
New Data Schema for Sentinel Translations
We've added Microsoft Defender for Endpoint as an alternative data schema for translations from Sigma into Microsoft Sentinel Query and Rule.
Cyber Threat Search Engine
MITRE ATT&CK View Updated
We've updated the technique and sub-technique filters. The second column now includes both techniques and sub-techniques related to the tactic selected in the first column.
So, if a rule is mapped only to a sub-technique, it is displayed only inside that sub-technique rather than also being present inside the parent technique.
Key Bug Fixes & Improvements
Fixed translation issues:
An issue where filtering condition from the Sigma rule in some cases was not applied in translation into Chronicle Security Query
Issues with CarbonBlack translations:
Strict mapping in some cases was not applied to translations from Sigma
Certain Sigma rules with unsupported fields were translated
Missing escaping of some special characters in translations into CarbonBlack
An issue where in some cases not all tactics and techniques were parsed when translating Sigma rules to Microsoft Sentinel rules
Updated the wording on cards on the home page of the SOC Prime Platform
Fixed a bug where a Dynamic Content List in some cases did not return all content that met the set criteria
