First release
- tenable-sc-cve-findings
- tenable-sc-hosts
- tenable-sc-vulnerabilities
- tenable-sc-vulnerability-details
- tenable-sc-solution-hosts
- tenable-sc-scans
- tenable-sc-scan-results
- tenable-sc-repositories
- tenable-sc-assets
- tenable-sc-filter
- tenable-sc-solutions
- tenable-sc-scanners
- tenable-sc-plugins
- tenable-sc-users
- tenable-sc-license
- tenable-sc-scan-zones
Changelog
- Added AWS VPC Flow log schema and logger model
Bug fix
- Fixed requestBodySize, requestBodySizeInspectedByWAF field casting error that occurs when "Simplify output fields" option is false in AWS WAF logger
- added profile option to aws-cost command
Changelog
- Added 9 new log schemas
- bluemax-ips-system (alert)
- bluemax-ips-audit (config_audit, connection_audit)
- bluemax-ips-iface (system_interface_traffic)
- bluemax-ips-domain-stats (traffic_domain_cnt)
- bluemax-ips-framesize-stats (traffic_framesize_cnt)
- bluemax-ips-inout-stats (traffic_inout_cnt)
- bluemax-ips-interface-stasts (traffic_interface_cnt)
- bluemax-ips-protocol-stats (traffic_protocol_cnt)
- bluemax-ips-service-stats (traffic_service_cnt)
- Fixed BLUEMAX IPS logger model to map "attack" log schema instead of "bluemax-ips-threat" for attack logs
- Also fixed BLUMAX IPS 침입탐지 query to search for "attack" log schema
```note
Before updating the app, delete "침입탐지" stream rule then update
```
Fix for changing the date format in Menlo Security API response values.
First Release
- Supports Fasoo FED-M log schema, logger model, and dashboard
First Release
- Supports Fasoo FXM log schema, logger model, and dashboard
First Release
- Supports Fasoo FDR log schema, logger model, and dashboard
First Release
- Supports Fasoo FSP log schema, logger model, and dashboard
First release
Support Attack Surface Intelligence dashboards and query commands:
- rf-asi-projects
- rf-asi-assets
- rf-asi-exposures
- rf-asi-certificates
- rf-asi-tcp-ports
- rf-asi-dns-records
- rf-asi-whois-records
Improvements to the chatgpt-ask extended command and GPT-5 model support
- Separated connection profiles and added model selection (GPT-5 family supported)
- Added GPT-5–specific options (mode, reasoning, verbosity)
- Support for max-output-tokens configuration
- Improved query cancellation functionality
- For usage instructions, refer to the user guide page
Added Korean translations
- Groups, Campaigns, Softwares, Analytics, Detection Strategies, Data Components, Relations
First release
- MITRE D3FEND version 1.3.0 (2025-12-16 00:12:00+0900)
Improvements
- Added Korean translations for tactics and techniques.
Added app query commands
- Add/list/delete blacklist rules
- Add/list/delete host objects
Added 22 log schemas
- MF2 Audit (audit)
- MF2 Cloud URL Block Status (app_cnt_cloud_url_block)
- MF2 Daemon Status (mng_daemon)
- MF2 FTP Block Status (app_cnt_ftp)
- MF2 HA Status (ha_status)
- MF2 HA Traffic (ha_traffic)
- MF2 Interface Traffic (mng_if_traffic)
- MF2 IPS DDOS Detect (ips_ddos_detect)
- MF2 NAT Rule Traffic (nat_rule_traffic)
- MF2 NAT Traffic (nat_traffic)
- MF2 Performance (mng_resource)
- MF2 QoS Counter (mng_qos)
- MF2 Rule Traffic (fw4_rule_traffic)
- MF2 SSL Traffic (app_cnt_ssl4_traffic, app_cnt_ssl6_traffic)
- MF2 SSLVPN Traffic (sslvpn3_cnt_traffic)
- MF2 SSLVPN Tunnel Status (sslvpn3_cnt_tunnel)
- MF2 Traffic (fw4_traffic, fw6_traffic)
- MF2 Oversubscription (mng_oversubscription)
- MF2 VPN Tunnel Count (vpn_cnt_tunnel_use)
- MF2 Webclient Limit (app_cnt_webclient_limit)
- MF2 Webclient Transaction (app_cnt_webclient_all)
- MF2 Webfilter Status (app_cnt_urlblock)
Others
- Added Unknown log schema
- Added MF2 Perf dashboard
First release
- Support dashboard and 17 query commands.
First release
- MITRE ATT&CK Enterprise 18.1 version (2025-11-13)
- Query commands: mitre-attack-analytics, mitre-attack-data-sources, mitre-attack-campaigns, mitre-attack-detection-strategies, mitre-attack-softwares, mitre-attack-mitigations, mitre-attack-techniques, mitre-attack-groups, mitre-attack-data-components, mitre-attack-relations, mitre-attack-tactics
Changelog
- Added support for WELF log format
- Fixed log schema display names
- Added 7 new log schemas
- Blacklist (fw4_blacklist)
- FQDN management (fqdn_management)
- QoS counter (qos_cnt)
- SSL VPN client profile (sslvpn_client_resource)
- SSL VPN tunnel monitoring (sslvpn_monitoring)
- SSL VPN user auth (sslvpn_user_auth)
- Web filter (urlblock)
Bug fix
- Fixed issue for some query commands not showing proper query plan
- Fixed issue where time filter was not being applied on the dashboard
**Before updating the app, delete the Bluemax NGF app dashboard and update the app for the dashboard to show correct log schema display names**
Bug Fixes
- Fixed an issue where using log command in subqueries caused a NullPointerException.
- Removed explain command that had been moved to the query optimizer app, resolving conflicts with the query optimizer app.
First release
- rules-emerging-threats, rules-threat-hunting resources
- 2026-01-05 6fe7343bf79306884b05837d5e03bcbcb141ce50 commit snapshot