Support for commands to search for employees and departments
First Release
- Provides parser, logger model, log schema, and dashboard for AXGATE SSLVPN logs
- Supports parsing of USERAUTH, AUDIT, and SESSION logs
Add S3 DNS, audit log collector, and dashboards
Bugfix
- Implement multi-profile guard for batch commands
Feature Enhancements
- Expanded Command Support: Added 13 new extended commands and integrated blocking synchronization.
- CEF Log Support: Now supports a CEF (Common Event Format) log parser.
- Needs Logpresso Sonar version 4.0.2502.0 or above.
Feature Improvements
- Block Integration & 13 New Extended Commands: Added integration for blocking features and introduced 13 additional extended commands.
- Needs Logpresso Sonar version 4.0.2502.0 or above.
New Log Field Parsing Support
- INTEL Log Type: Added support for parsing risk(level) and threat category(assessment) fields.
- ALERT Log Type: Added support for parsing risk(level) and nested event data by log type.
Feature Enhancement (Requires **Logpresso Sonar version 5.0.2603.0 or later**)
- Added support for Okta SAML 2.0 Single Sign-On (SSO)
Feature Improvements
- Improved logic for handling whitespace in dates.
- Added parsing failure handling for unsupported log types.
Fixed parsing failure caused by mismatched log type names.
Support 21 query commands
- umbrella-activity-logs
- umbrella-domain-whois
- umbrella-domain-risk-score
- umbrella-domain-security
- umbrella-domain-category
- umbrella-domain-whois-batch
- umbrella-domain-risk-score-batch
- umbrella-domain-security-batch
- umbrella-domain-category-batch
- umbrella-top-destinations
- umbrella-top-identities
- umbrella-top-threats
- umbrella-apps
- umbrella-summary
- umbrella-networks
- umbrella-categories
- umbrella-destination-lists
- umbrella-destinations
- umbrella-category-stats
- umbrella-destination-stats
- umbrella-api-usage-summary
First release
- Attack Graph, Knowledge Graph, Network Topology
Add logger model
- Provide **Chakra Max DAC (SFTP)** logger model.
Bug Fix: Extended Command Visibility
- Fixed an issue where certain extended commands were not being displayed.
- The azure-activity-logs command is now visible.
- Note: Azure Monitoring Reader permissions must be granted to use this feature.
Bug Fix: Connection Profile Timeout Unit
- Fixed the timeout unit to be applied in seconds (previously applied in milliseconds).
- For sites using version 1.4.2512.0, please re-enter the timeout options.
First Release
- Support for NHN Cloud Security Monitoring event retrieval command and logger.
- Support for NHN Cloud Security Monitoring ticket retrieval command.
First Release
- Provides command and logger to retrieve NHN Cloud CloudTrail logs.
First Release
- Sends messages using Kakao Business AlimTalk API.
- Supports three extended commands for AlimTalk message delivery.
First Release
- Supports MonitorApp AISVA(Application Insight SSL/TLS Visibility Appliance) log schemas, logger model, and dashboard
- Suppported log types
- SESSION
- SYSTEM
- TRAFFIC
- NET_TRAFFIC
- AUDIT
Implemented report commands using Action Center API.
New Commands
- securitytrails-admin-pages-report: Fetch identified admin pages from SecurityTrails service.
- securitytrails-all-apex-report: Fetch all apex domain list from SecurityTrails service.
- securitytrails-all-hostname-report: Fetch all hostname list from SecurityTrails service.
- securitytrails-all-ip-report: Fetch all IP address list from SecurityTrails service.
- securitytrails-deployment-hardening-report: Fetch deployment hardening report from SecurityTrails service.
- securitytrails-dns-records-report: Fetch DNS records report from SecurityTrails service.
- securitytrails-domain-management-report: Fetch domain management report from SecurityTrails service.
- securitytrails-expired-ssl-report: Fetch expired SSL report from SecurityTrails service.
- securitytrails-expiring-ssl-report: Fetch expiring SSL report from SecurityTrails service.
- securitytrails-exposures-host-report: Fetch exposures host report from SecurityTrails service.
- securitytrails-exposures-issue-report: Fetch exposures issue report from SecurityTrails service.
- securitytrails-harvested-information-report: Fetch harvested information report from SecurityTrails service.
- securitytrails-ports-host-report: Fetch open ports per host from SecurityTrails service.
- securitytrails-ports-ip-report: Fetch open ports per IP from SecurityTrails service.
- securitytrails-product-inventory-report: Fetch product inventory report from SecurityTrails service.
- securitytrails-remote-access-report: Fetch remote access service list from SecurityTrails service.
- securitytrails-vulnerable-products-report: Fetch vulnerable products report from SecurityTrails service.
- securitytrails-websec-config-report: Fetch web security configuration report from SecurityTrails service.
Changed Commands
- securitytrails-usage: Added 401 authentication error guard.
- securitytrails-asi-certificates: Eliminated N+1 API calls
- securitytrails-asi-dns-records: Eliminated N+1 API calls
- securitytrails-asi-tcp-ports: Eliminated N+1 API calls
- securitytrails-asi-whois-records: Eliminated N+1 API calls
- securitytrails-asi-exposures: Eliminated N+1 API calls