API Endpoint Migration
- Removed integration features for portal.quaxar.io
HTTP Proxy Support & Profile Options
- Added support for HTTP Proxy and new profile configuration options
New Commands
TAP Related:
- quaxar-threat-actors
- quaxar-threat-actor-indicators
- quaxar-threat-actor-malwares
- quaxar-threat-actor-tools
- quaxar-threat-actor-ttps
- quaxar-threat-actor-vulnerabilities
- quaxar-threat-actor-reports
- batch command
Report Related:
- quaxar-threat-reports
- quaxar-indicator-reports
- (Current API method) quaxar-talon-reports
- (Current API method) quaxar-vulnerability-reports
SIGV Related:
- quaxar-snort
- quaxar-yara-rules
Removed Incompatible Commands & Dashboards
- quaxar-attack-surface-reports
- quaxar-exposed-services
- quaxar-exposure-service-stats
- quaxar-exposure-trends
- quaxar-open-indicators
- quaxar-security-news
Bug Fixes
Fixed an issue where the days option in the quaxar-recent-indicators command was not functioning
Added response validation for API Key errors, Server errors, and other exceptions
First release
- Provides a logger model, log schema, and query commands for transactions and active services
Improved option validation for query commands
- `notion-pages` / `notion-blocks` / `notion-database-pages`: guidance on missing `page-id` (including empty and blank values)
- `notion-pages`: rejection of negative or non-numeric max-depth
- `notion-blocks-batch`: fix for arbitrary profile selection when the profile option was omitted with multiple Notion profiles (omission still allowed with a single profile)
- `sniper-ngfw-commit-changes`: fixed incorrect `reset-tunnels` option behavior
- Added `unknown` to logger model
New Commands & Updates to Existing Commands
* insightvm-asset: Get details of a specific asset
* insightvm-asset-softwares: Get the software list of a specific asset
* insightvm-vulnerability: Get details of a specific vulnerability
* insightvm-assets: Added 'id' to the output fields. This is a unique value assigned to an asset (device), which can be found in the URL of the asset details page and used as an option field for the insightvm-asset command.
- Replaced hard-coded query with Sonar JDBC logger model
- flexible collection per target DB layout
- Requires uninstalling `previous version (1.0.2401.0)` before install
- Requires `Microsoft SQL Server` app installed first for SQL Server collection
Initial release
- Provides a JDBC logger model, log schemas, and a dashboard for DOCTORSOFT NETCLIENT PC security logs.
Add a Slack online status collector and a dedicated app menu
Remote File Scanning Support
- Requires [Experimental app](/en/apps/experimental) version 2.0.2607.0 or later
- Requires installation of an app that supports remote file streaming (such as the [Microsoft Graph app](/en/apps/ms-graph))
- Please note that, starting with this version, scanning of local files on the server is no longer supported due to security concerns
OneDrive File Streaming
- Requires [Experimental](/en/apps/experimental) app version 2.0.2607.0 or later
- Note: Installation will fail due to dependency errors if the latest version of Experimental app is not installed
Added 6 ticket query commands
- sonar-ticket-repositories
- sonar-create-event-ticket
- sonar-create-markdown-ticket
- sonar-add-ticket-comment
- sonar-update-ticket-comment
- sonar-remove-ticket-comment
Added Interface for Remote File Streaming
- For example, the Microsoft Graph app supports access to OneDrive files, and the Office Scanner app can scan OneDrive files.
Improvements
- Support for parsing CDR-related fields and added schema fields
- Refined dataset queries so the dashboard time filter is applied
- Corrected the display name of the `mail_to` field in the `url-scan` schema
Improvements
- Support for parsing CDR-related fields and added schema fields
- Refined dataset queries so the dashboard time filter is applied
Initial Release
- Provides a parser, logger model, log schema and dashboard for Netwrix Endpoint Protector logs.
Improvements
- Normalize action, result fields for `USERAUTH` log type
Bug Fix
- Fix '=' character handling error in WELF parser
First Release
* Provides parser, logger model, and log schema for BeyondTrust Endpoint Privilege Management (EPM) and Application Audit logs
* Supported categories: EPM, Application Audit
- Improved clipping of right-side stats panels (source countries, ASNs, detection rules) across screen resolutions
- Added scrolling and optimized spacing for right-side stats panels
- Fixed an issue where the globe failed to render when textures failed to load
Enhance safety of parser Boolean field casting logic
Parser Improvements
- Added parsing logic for MNX detection information (Playbook detection info) types.