첫 번째 릴리즈
- NHN Cloud CloudTrail 로그 조회 명령어, 수집기 제공
첫 번째 릴리즈
- 카카오 비즈니스 알림톡 API를 활용해 메시지를 전송합니다.
- 알림톡 전송 확장명령어 3종 지원
첫번째 릴리스
- MonitorApp AISVA(Application Insight SSL/TLS Visibility Appliance) 로그스키마, 수집모델, 대시보드 지원
- 지원하는 로그유형
- SESSION
- SYSTEM
- TRAFFIC
- NET_TRAFFIC
- AUDIT
액션 센터 보고서 조회 기능 추가
추가된 커맨드
- securitytrails-admin-pages-report: 식별된 관리자 페이지 목록을 조회합니다.
- securitytrails-all-apex-report: 전체 Apex 도메인 목록을 조회합니다.
- securitytrails-all-hostname-report: 전체 호스트명 목록을 조회합니다.
- securitytrails-all-ip-report: 전체 IP 주소 목록을 조회합니다.
- securitytrails-deployment-hardening-report: 배포 설정 취약점 목록을 조회합니다.
- securitytrails-dns-records-report: DNS 레코드 목록을 조회합니다.
- securitytrails-domain-management-report: 도메인 관리 정보를 조회합니다.
- securitytrails-expired-ssl-report: 만료된 SSL 인증서 목록을 조회합니다.
- securitytrails-expiring-ssl-report: 만료 예정인 SSL 인증서 목록을 조회합니다.
- securitytrails-exposures-host-report: 호스트별 취약점 요약을 조회합니다.
- securitytrails-exposures-issue-report: 취약점 이슈 목록을 조회합니다.
- securitytrails-harvested-information-report: 수집된 정보 목록을 조회합니다.
- securitytrails-ports-host-report: 호스트별 열린 포트 목록을 조회합니다.
- securitytrails-ports-ip-report: IP별 열린 포트 목록을 조회합니다.
- securitytrails-product-inventory-report: 제품 인벤토리 목록을 조회합니다.
- securitytrails-remote-access-report: 원격 접속 서비스 목록을 조회합니다.
- securitytrails-vulnerable-products-report: 취약 제품 목록을 조회합니다.
- securitytrails-websec-config-report: 웹 보안 설정 오류 목록을 조회합니다.
변경된 커맨드
- securitytrails-usage: 401 인증 에러 가드 추가
- securitytrails-asi-certificates: N+1 API 호출 문제 개선
- securitytrails-asi-dns-records: N+1 API 호출 문제 개선
- securitytrails-asi-tcp-ports: N+1 API 호출 문제 개선
- securitytrails-asi-whois-records: N+1 API 호출 문제 개선
- securitytrails-asi-exposures: N+1 API 호출 문제 개선
변경 사항
- V3_MALWARE 로그 유형 지원
- 미분류, HIPS_FW 스키마 추가
첫번째 릴리스
변경 내역
- 로그 유형(log_type) 필드 추가
- WEBFRONT 감사 로그 파싱 개선
신규 로그유형 6종 파서 지원 및 로그스키마 추가
- 그룹 VPN 터널 통계
- IPSEC 이벤트
- IPSEC 회선별 통계
- IPSEC 터널 통계
- IPSEC 터널별 상태
- IPSEC 터널별 통계
첫번째 릴리스
첫번째 릴리스
Web Search 기능 추가 및 접속 프로파일 수정
- `chatgpt-ask`, `chatgpt-ask-batch` 확장 명령어에 `web-search` 옵션 추가
- `chatgpt-audit-logs` 확장 명령어 프로파일 지정불가 오류 수정
- 접속프로파일 웹 검색 허용 도메인 추가 (최대 100개)
- 접속프로파일 `GPT-5.4` 모델 선택 추가
기능 개선
- 차단연동 기능 추가
- 안랩 트러스가드 API 접속 프로파일 지원
- `trusguard-blacklist-rules` 블랙리스트 규칙 조회 명령어 추가
- `trusguard-add-blacklist-rule` 블랙리스트 규칙 추가 명령어 추가
- `trusguard-update-blacklist-rule` 블랙리스트 규칙 수정 명령어 추가
- `trusguard-remove-blacklist-rule` 블랙리스트 규칙 삭제 명령어 추가
- `trusguard-blacklist-files` 블랙리스트 파일 목록 조회 명령어 추가
- `trusguard-remove-blacklist-file` 블랙리스트 파일 삭제 명령어 추가
- `trusguard-ipv4-addresses` IPv4 주소 객체 조회 명령어 추가
- `trusguard-add-ipv4-address` IPv4 주소 객체 추가 명령어 추가
- `trusguard-update-ipv4-address` IPv4 주소 객체 수정 명령어 추가
- `trusguard-remove-ipv4-address` IPv4 주소 객체 삭제 명령어 추가
- `trusguard-ipv4-address-groups` IPv4 주소 그룹 조회 명령어 추가
- `trusguard-add-ipv4-address-group` IPv4 주소 그룹 추가 명령어 추가
- `trusguard-update-ipv4-address-group` IPv4 주소 그룹 수정 명령어 추가
- `trusguard-remove-ipv4-address-group` IPv4 주소 그룹 삭제 명령어 추가
- `trusguard-policies` 정책 목록 조회 명령어 추가
- `trusguard-commit` 설정 변경 커밋 명령어 추가
첫 번째 릴리즈
- Akamai Guardicore 수집 모델, 파서, 로그 스키마 5종 지원
개선 사항
- v2.0.11 펌웨어 지원
- 신규 로그 유형 수집 지원
- 3013 인터페이스(이더넷) 로그
- 3014 인터페이스(브리지) 로그
- 3241 Global 프로토콜 이상 규칙 차단 로그
- 3251 국가 기반 차단 필터 차단 로그
- 3300, 3310, 3320, 3330, 3340, 3350, 3360, 3370, 3380, 3390, 3400, 3410, 3420, 3430, 3440, 3450, 3460, 3470 필터 통계 로그
- 3461 Anti-Spoofing(NXDomain) 필터 차단 로그
- 3462 Anti-Spoofing(NXDomain) 필터 허용 로그
- 3471 Anti-Spoofing(UDP) 필터 차단 로그
- 3472 Anti-Spoofing(UDP) 필터 허용 로그
- 3500 NMS 경보 로그
- 3501 NMS 성능 로그
- 신규 로그스키마 추가
- dpx-alert
- dpx-filter-stats
- dpx-iface-bridge
- dpx-iface-ethernet
- dpx-system-perf
- 수집모델에 **미분류** 추가
- 대시보드 **필터 통계** 추가
Attack Surface Intelligence 기능을 SecurityTrails 앱으로 이관
Attack Surface Intelligence 연동 기능 추가
변경사항
- 엑소스피어 웹 접속 관리 수집기 추가
- exosp-webcontrol-logs 명령어 추가
첫번째 릴리스
- Event 수집기 및 대시보드
불필요 탐지룰 객체(tip test) 제거
버그 수정
- SSL 인증서 검증을 비활성화한 경우 호스트명 검증도 함께 생략하도록 수정