Initial Release
- Provides logger models for Firewall events, HTTP requests, DNS, Spectrum, Account audit logs
- Ingestion via API polling and Logpush (HTTP, S3)
- Firewall events dashboard
- 7 query commands
- Log query (5): Firewall events · HTTP requests · Audit logs (v1/v2) · IP block rule list
- IP block rule management (2): add · remove
First release
- Syslog parser, log schema, logger model, dashboard, and XDR UI
AI Messenger Interface Support
- Integration with AI assistant and Agentic SOC apps.
AI Messenger Interface Support
- Integration with AI assistant and Agentic SOC apps.
Feature Improvements
- Optimize date comparison logic in S3 daily directory logger
- Fix missing region configuration in AWS Aurora MySQL Audit logger
Command Bug Fixes
* Fixed an issue where the last_scan result of the insightvm-asset command did not show the latest scan value.
Added a timeout setting for connection profiles.
- Usage: Designed to prevent timeouts during long-running tasks, such as commit operations.
Added a timeout setting for connection profiles.
- Usage: Designed to prevent timeouts during long-running tasks, such as commit operations.
Added a timeout setting for connection profiles.
- Usage: Designed to prevent timeouts during long-running tasks, such as commit operations.
API Endpoint Migration
- Removed integration features for portal.quaxar.io
HTTP Proxy Support & Profile Options
- Added support for HTTP Proxy and new profile configuration options
New Commands
TAP Related:
- quaxar-threat-actors
- quaxar-threat-actor-indicators
- quaxar-threat-actor-malwares
- quaxar-threat-actor-tools
- quaxar-threat-actor-ttps
- quaxar-threat-actor-vulnerabilities
- quaxar-threat-actor-reports
- batch command
Report Related:
- quaxar-threat-reports
- quaxar-indicator-reports
- (Current API method) quaxar-talon-reports
- (Current API method) quaxar-vulnerability-reports
SIGV Related:
- quaxar-snort
- quaxar-yara-rules
Removed Incompatible Commands & Dashboards
- quaxar-attack-surface-reports
- quaxar-exposed-services
- quaxar-exposure-service-stats
- quaxar-exposure-trends
- quaxar-open-indicators
- quaxar-security-news
Bug Fixes
Fixed an issue where the days option in the quaxar-recent-indicators command was not functioning
Added response validation for API Key errors, Server errors, and other exceptions
First release
- Provides a logger model, log schema, and query commands for transactions and active services
Improved option validation for query commands
- `notion-pages` / `notion-blocks` / `notion-database-pages`: guidance on missing `page-id` (including empty and blank values)
- `notion-pages`: rejection of negative or non-numeric max-depth
- `notion-blocks-batch`: fix for arbitrary profile selection when the profile option was omitted with multiple Notion profiles (omission still allowed with a single profile)
- `sniper-ngfw-commit-changes`: fixed incorrect `reset-tunnels` option behavior
- Added `unknown` to logger model
New Commands & Updates to Existing Commands
* insightvm-asset: Get details of a specific asset
* insightvm-asset-softwares: Get the software list of a specific asset
* insightvm-vulnerability: Get details of a specific vulnerability
* insightvm-assets: Added 'id' to the output fields. This is a unique value assigned to an asset (device), which can be found in the URL of the asset details page and used as an option field for the insightvm-asset command.
- Replaced hard-coded query with Sonar JDBC logger model
- flexible collection per target DB layout
- Requires uninstalling `previous version (1.0.2401.0)` before install
- Requires `Microsoft SQL Server` app installed first for SQL Server collection
Initial release
- Provides a JDBC logger model, log schemas, and a dashboard for DOCTORSOFT NETCLIENT PC security logs.
Add a Slack online status collector and a dedicated app menu
Remote File Scanning Support
- Requires [Experimental app](/en/apps/experimental) version 2.0.2607.0 or later
- Requires installation of an app that supports remote file streaming (such as the [Microsoft Graph app](/en/apps/ms-graph))
- Please note that, starting with this version, scanning of local files on the server is no longer supported due to security concerns
OneDrive File Streaming
- Requires [Experimental](/en/apps/experimental) app version 2.0.2607.0 or later
- Note: Installation will fail due to dependency errors if the latest version of Experimental app is not installed
Added 6 ticket query commands
- sonar-ticket-repositories
- sonar-create-event-ticket
- sonar-create-markdown-ticket
- sonar-add-ticket-comment
- sonar-update-ticket-comment
- sonar-remove-ticket-comment
Added Interface for Remote File Streaming
- For example, the Microsoft Graph app supports access to OneDrive files, and the Office Scanner app can scan OneDrive files.