Add the `ahnlab-tip-related-actors-batch` command
- Use IoC information to look up related threat actor information.
Changelog
- Supports Syslog BSD date format (MMM d HH:mm:ss, MMM dd HH:mm:ss)
- 2 log schemas added
- nexg-fw-ssh-auth
- nexg-fw-audit
Bugfix
- Fixed typo in stream rule queries
Changelog
- SNIPER TMS-Plus IP block integration support using address groups
- 18 new Commands added
- sniper-tms-ipv4-blocklist
- sniper-tms-ipv6-blocklist
- sniper-tms-block-ip
- sniper-tms-block-ip-batch
- sniper-tms-unblock-ip
- sniper-tms-unblock-ip-batch
- sniper-tms-ipv4-allowlist
- sniper-tms-ipv6-allowlist
- sniper-tms-allow-ip
- sniper-tms-allow-ip-batch
- sniper-tms-remove-allow-ip
- sniper-tms-remove-allow-ip-batch
- sniper-tms-devices
- sniper-tms-sensor-block-ips
- sniper-tms-snort-rules
- sniper-tms-pattern-blocks
- sniper-tms-users
- sniper-tms-deploy
- 2 new Log-Schemas added
- sniper-tms-plus-resource (Resource Log)
- sniper-tms-plus-firewall-session (Firewall Session Log)
First release
- tenable-sc-cve-findings
- tenable-sc-hosts
- tenable-sc-vulnerabilities
- tenable-sc-vulnerability-details
- tenable-sc-solution-hosts
- tenable-sc-scans
- tenable-sc-scan-results
- tenable-sc-repositories
- tenable-sc-assets
- tenable-sc-filter
- tenable-sc-solutions
- tenable-sc-scanners
- tenable-sc-plugins
- tenable-sc-users
- tenable-sc-license
- tenable-sc-scan-zones
Changelog
- Added AWS VPC Flow log schema and logger model
Bug fix
- Fixed requestBodySize, requestBodySizeInspectedByWAF field casting error that occurs when "Simplify output fields" option is false in AWS WAF logger
- added profile option to aws-cost command
Changelog
- Added 9 new log schemas
- bluemax-ips-system (alert)
- bluemax-ips-audit (config_audit, connection_audit)
- bluemax-ips-iface (system_interface_traffic)
- bluemax-ips-domain-stats (traffic_domain_cnt)
- bluemax-ips-framesize-stats (traffic_framesize_cnt)
- bluemax-ips-inout-stats (traffic_inout_cnt)
- bluemax-ips-interface-stasts (traffic_interface_cnt)
- bluemax-ips-protocol-stats (traffic_protocol_cnt)
- bluemax-ips-service-stats (traffic_service_cnt)
- Fixed BLUEMAX IPS logger model to map "attack" log schema instead of "bluemax-ips-threat" for attack logs
- Also fixed BLUMAX IPS 침입탐지 query to search for "attack" log schema
```note
Before updating the app, delete "침입탐지" stream rule then update
```
Fix for changing the date format in Menlo Security API response values.
First Release
- Supports Fasoo FED-M log schema, logger model, and dashboard
First Release
- Supports Fasoo FXM log schema, logger model, and dashboard
First Release
- Supports Fasoo FDR log schema, logger model, and dashboard
First Release
- Supports Fasoo FSP log schema, logger model, and dashboard
First release
Support Attack Surface Intelligence dashboards and query commands:
- rf-asi-projects
- rf-asi-assets
- rf-asi-exposures
- rf-asi-certificates
- rf-asi-tcp-ports
- rf-asi-dns-records
- rf-asi-whois-records
Improvements to the chatgpt-ask extended command and GPT-5 model support
- Separated connection profiles and added model selection (GPT-5 family supported)
- Added GPT-5–specific options (mode, reasoning, verbosity)
- Support for max-output-tokens configuration
- Improved query cancellation functionality
- For usage instructions, refer to the user guide page
Added Korean translations
- Groups, Campaigns, Softwares, Analytics, Detection Strategies, Data Components, Relations
First release
- MITRE D3FEND version 1.3.0 (2025-12-16 00:12:00+0900)
Improvements
- Added Korean translations for tactics and techniques.
Added app query commands
- Add/list/delete blacklist rules
- Add/list/delete host objects
Added 22 log schemas
- MF2 Audit (audit)
- MF2 Cloud URL Block Status (app_cnt_cloud_url_block)
- MF2 Daemon Status (mng_daemon)
- MF2 FTP Block Status (app_cnt_ftp)
- MF2 HA Status (ha_status)
- MF2 HA Traffic (ha_traffic)
- MF2 Interface Traffic (mng_if_traffic)
- MF2 IPS DDOS Detect (ips_ddos_detect)
- MF2 NAT Rule Traffic (nat_rule_traffic)
- MF2 NAT Traffic (nat_traffic)
- MF2 Performance (mng_resource)
- MF2 QoS Counter (mng_qos)
- MF2 Rule Traffic (fw4_rule_traffic)
- MF2 SSL Traffic (app_cnt_ssl4_traffic, app_cnt_ssl6_traffic)
- MF2 SSLVPN Traffic (sslvpn3_cnt_traffic)
- MF2 SSLVPN Tunnel Status (sslvpn3_cnt_tunnel)
- MF2 Traffic (fw4_traffic, fw6_traffic)
- MF2 Oversubscription (mng_oversubscription)
- MF2 VPN Tunnel Count (vpn_cnt_tunnel_use)
- MF2 Webclient Limit (app_cnt_webclient_limit)
- MF2 Webclient Transaction (app_cnt_webclient_all)
- MF2 Webfilter Status (app_cnt_urlblock)
Others
- Added Unknown log schema
- Added MF2 Perf dashboard
First release
- Support dashboard and 17 query commands.