Popular Updates

Devo Platform release 8.2.26

 Devo is happy to make available the latest release of the Devo Platform.  This update brings a selection of improvements and bug fixes sourced by our customers!Release InformationTime Window: Thursday August 31, 9:00 AM UTCDuration: 2 HoursImpact: NONE Geo Availability <Region Status CA Released US Released EU Released APACReleased  Table of ContentsNew Features New Data Search Events marked on arrival  Alert Subscription Enhancement Improvements Aggregation Task calendar migrated to Data Search time picker Improved Data Search Copy command Increased Home Widget Accuracy Enhanced LookUp Errors Better handling of large synthesis operations Bug Fixes New FeaturesNew Data Search Events marked on arrivalNew highlights added to new events on both Table View and List view in Data Search. Alert Subscription EnhancementThe user’s email is now displayed on the Alert Subscription page instead of the Username.  This conforms with the consistent behavior through other pages in Devo ensuring an expected experience.  ImprovementsAggregation Task calendar migrated to Data Search time pickerImproved Data Search Copy commandImproved UX with the contextual menu “Copy” reducing the number of mouse clicks required to reach the command. Increased Home Widget AccuracyUnits are now accurately displayed between the volume widget and the shown metric. Both now display the superior binary ingestion size (TiB, GiB, MiB, KiB) over the previously used decimal (TB, GB, MB, KB) representation.  This change ensures clear and correct data visualization for ingestion within your domain. The Event Volume chart on the Home Page is now more accurate due to this change.  The data continues to be accurate, and now the average and limit lines will match the data exactly. Enhanced LookUp ErrorsThe team has made huge efforts to create more detailed error outputs to better diagnose and troubleshoot Lookup issues.   In addition to this, errors are now available in multiple languages, including Catalan!Our goal here is to continuously improve the LookUp experience! Better handling of large synthesis operationsWe’ve increased the size of POST and DELETE requests to accommodate larger synthesis operations.  We also added new error messages with details to help diagnose problems with large synthesis operations.  Bug FixesImprove Autoparser handling of INTEGER types. Improve Aggregation task calendar Fixed an issue with relative dates when using search history Improved ip4 operation handling 

Related products:Devo Platform

Devo Platform release 8.2.21

Devo is happy to deliver this new version of the Platform.  Containing new features and improvements to Activeboards. Geo AvailabilityRegion Status CA Released US Released EU Released APAC Released  Table of ContentsNew Features New Activeboard Widget - Calendar Heatmap Improvements Improved Widget - MakersMap New look and usability improvements for Charts Improvements to Export to PDF  New FeaturesNew Activeboard Widget - Calendar HeatmapThe new Calendar Heatmaps represent time-series numerical data through a conventional calendar where each day is shaded on a light to dark gradient based on the sum of the values of the said numerical variable along the day. ImprovementsImproved Widget - MakersMapMakerMap is now using the new Google maps library “@googlemaps/marketclusterer”.  This new library  brings the following improvements:More accurate location icons:  Correct icon placement at all zoom levels. New grouping location functionality: New Design Proportional icon size to the number of locations it represents More than 5 colors possible! A themed color palette is implemented. When several icons overlap, the biggest one is displayed at the foreground. New look and usability improvements for ChartsCharts receive new colors, and legends are now delimited with a background light gray area. Improvements to Export to PDFCleaned up header duplication Improvements to layout

Related products:Devo Platform

Devo SOAR Release m113.8

New SOAR release includes new functionality, vulnerability and bug fixes! Geo AvailabilityRegion Status CA Released US Released EU Released APAC Released  Table of ContentsNew features New Actions for Sailpoint New to Zendesk Integration Improvements Bug Fixes New featuresNew Actions for SailpointSailpoint Integration has added 6 new actions:Search List Accounts Delete Account Get Account Activity List Account Activities Get AccountNew to Zendesk IntegrationAdded token-based authentication at the connection level. ImprovementsDestination: Added retries and visibility of the result of forwarding.Improved performance of loading detection under My UseCases section.Disabled Query section when we run/update SQL node.Changed from Python2 to Python3 for vulnerability fix in the following integrations:GRR Nmap UtilitiesCode vulnerability fix by removing the usage of the static jar from:JDBC Microsft SQL ServerBug FixesIf a user’s password expires (per system security settings), or if an admin resets a user’s password and gives them a temporary password, that password can still be used for whatever the user wants in scripting without authorization being denied. We have fixed this now. Update Case/ Create Case action failing for field( type single select) update with an invalid value of integration Case Management. We have fixed this now. Showing proper error message when some error occurs in connecting the server or retrieving the message of integration Exchange (Quarantine Messages).

Related products:Devo SOAR

Collector Catalog Update: July

The Integrations team has released in this update, a selection of new collectors and updates to existing ones documented below! Geo availabilityRegion Status CA Released US Released EU Released APAC Released  Table of ContentsNew Collectors Spycloud Collector 1.0.0 Proofpoint CASB Collector 1.0.1 CyberArk EPM Collector 1.0.0 Taxii Collector 1.0.0 Collectors Updated Azure Collector 1.6.0 MS Graph 1.6.2 Google Workplace Alerts (aka Gsuite Alerts) 1.6.0 CrowdStrike API Resource Collector 1.4.2 Spycloud 1.0.1 Okta Collector 1.7.0 Cisco eStreamer collector 1.3.0 Rapid7 Insights 2.0.0 Office 365 Exchange Message Tracing 2.1.0  New CollectorsSpycloud Collector 1.0.0The SpyCloud collector can help fraud prevention teams stay ahead of customer ATO fraud by detecting and resetting exposed consumer passwords early in the breach lifecycle, heading off account takeover attempts. Full details here.Proofpoint CASB Collector 1.0.1Proofpoint Cloud App Security Broker (Proofpoint CASB) helps you secure applications such as Microsoft Office 365, Google Workspace, Box, and more. It gives you people-centric visibility and control over your cloud apps, so you can deploy cloud services with confidence. Full details here.CyberArk EPM Collector 1.0.0CyberArk is an Identity Security Platform that enables secure access for any identity — human or machine — to any resource or environment from anywhere, using any device. Full details here.Taxii Collector 1.0.0Trusted Automated Exchange of Intelligence Information (TAXII™) is an application protocol for exchanging CTI over HTTPS. ​TAXII defines a RESTful API (a set of services and message exchanges) and a set of requirements for TAXII Clients and Servers. Full details here. Collectors UpdatedAzure Collector 1.6.0» DetailsMS Graph 1.6.2» DetailsGoogle Workplace Alerts (aka Gsuite Alerts) 1.6.0» DetailsCrowdStrike API Resource Collector 1.4.2» DetailsSpycloud 1.0.1» DetailsOkta Collector 1.7.0» DetailsCisco eStreamer collector 1.3.0» DetailsRapid7 Insights 2.0.0» DetailsOffice 365 Exchange Message Tracing 2.1.0» Details

Related products:Devo Integrations

Devo Exchange Catalog Update: July

Devo Exchange and SciSec Teams hare happy to announce the Content update for July for Devo Exchange! Geo AvailabilityRegion Status CA Released US Released EU Released APAC Released  Table of ContentLookups MitreAlertsExtendedDefinition Activeboards Cloud Azure Summary Office365 Active Directory Proxy Zxcaler Activity Office365 Overview Use Cases Office365 Overview Use Case Content Packs 14 MITRE Tactics Content Packs 97 MITRE Technique Alert Packs  LookupsMitreAlertsExtendedDefinitionThis lookup will allow you to add Alerts to your MITRE ATT&CK Adviser mapped to multiple tactics and techniques.  You can still use SecOpsAlertDescription to and alerts with a single mapping. ActiveboardsCloud Azure SummaryGive a summary to clients about their Azure events like geolocalization, severities, average duration, critical events...Office365 Active DirectoryOverview of Office 365 Active Directory user and login eventsProxy Zxcaler ActivityGeneral overview of Zscaler Proxy solution and activity.Office365 OverviewShows a summary of all Microsoft Office 365 activity: Active Directory, SharePoint, OneDrive, Teams and Exchange. Use CasesOffice365 Overview Use CaseWorks with the Office365 Management Injection synthetic data and the Office365 Overview activeboard Content Packs14 MITRE Tactics Content PacksFull List available here.97 MITRE Technique Alert PacksFull list available here 

Related products:Devo Exchange

Devo Platform release 8.2.15

The next release of the Devo Product is almost here.   You might have noticed more update announcements more often,  the team is working hard to make sure you have the right information at the right time!   Here are the coming changes to the product! Geo AvailabilityRegion Status CA Released US Released EU Released APAC Released  Table of ContentsNew Features Built-in application preferences at the domain level New Sensitive data handling Deprecated Action Improvements X.509 New status Bug Fixes New FeaturesBuilt-in application preferences at the domain levelAllows the user to manage “application preferences” at the domain level for applications that have built-in preferences. New Sensitive data handlingTo address the problem of sensitive data being exposed to any user role and provide flexibility in audit actions the team has created the following rule:Only hide those parameters coming from requests with URL-encoded content and using HTTP verbs other than “GET”. Deprecated ActionRemoved add data from Dropbox action due to lack of user adoptions. ImprovementsX.509 New statusX.509 Certificates gain new status “Expired” in UI. In addition to this new status expired certificates:Cannot be downloaded. Will display a “---” in all columns except name and dates.Bug FixesFixed User Session invalidates prematurely Fixed Support form Send Fixed incorrect translation into Spanish in Autoparser.  

Related products:Devo Platform

Devo Platform 8.2.8 Release

This release of the Devo Platform brings you new features to Activeboards, Scheduled reports and User interaction improvements.Geo AvailabilityRegion Status CA Released US Released EU Released APAC Released  Table of contentsNew Features Activeboards Unified Y axis Two new methods added to Activeboads language Improvements Scheduled Reports - Hidden Recipients Scheduled reports - New Information fields Additional Improvements Bug Fixes New FeaturesActiveboards Unified Y axisThis new feature added in the Line/Column/Area widgets, will allow the user to have all the metrics in the same Y axis and with the same scale. The current behavior (a different Y axis/scale for each metric) will be also available.Two new methods added to Activeboads languageMethod Syntax Description Take take (query, N) Takes the first N elements from a data set Sort sort(query, columnName, ‘ASC’ | ‘DESC’) Sorts a dataset by column with ASC/DESC order  ImprovementsScheduled Reports - Hidden RecipientsThe To: field will now display as empty when sending Scheduled reports, maintaining privacy for all users.Scheduled reports - New Information fieldsNew information fields added:Field Name Available in Environment Subject and Content Domain Subject and Content Activeboard Name Content Creation Date Timezone Content (specified in Scheduling) Activeboard ID Content exclusive to error emails  Additional ImprovementsSpeed up Activeboard display times.  When opening activeboards, the default activeboard will be loaded, if no default is set, the first activeboard will be loaded. The full activeboard list can be requested from the Activeboard manager. Added new notification to Clone Activeboard command to notify user when an Activeboard is cloned successfully without opening. Improve Activeboad cloning operation, faster and a new spinner added notifying the user of continued action progress in background. Added a description field max character counter to Create new Activeboard dialog. UX improvements to reordering in Table Widget.Bug FixesFlickering issue fixed with the vertical scrollbar in the Activeboad Manager. Fixed issue with session timeouts Fixed issue with values missing when Menu Always Open was selected.View the full release in Docs!

Related products:Devo Platform

Security Operations Release 3.27.3

This release of Security Operations brings in new functionality that improves analyst workflows in the triage and investigations workbenches and updates to the content manager!Geo AvailabilityRegion Status CA Released US Released EU Released APAC Released  Table of ContentsNew features Open in Dedicated tabs Improvements Increased Visible Alerts Content Manager expanded to support All alert types Content Manager Subquery Support Triage Filtering Increased security of investigations and Enigma Endpoints  New featuresOpen in Dedicated tabsWe have enhanced SecOps to allow you to open the entire application and sections in separate tabs, increasing the modularity of your workflow.SecOps - You can open SecOps in a new tab from the General Menu.Alerts from the Triage Page can now be launched in a new tab by right-clicking on the alert and choosing “open in a new tab”.Investigations can be opened in a new tab from the Triage page by right-clicking on the alert and selecting “open in a new tab”.Investigations can also be launched in a new tab from the investigations page by right-clicking on an alert and choosing “open in a new tab”ImprovementsIncreased Visible AlertsWe have increased the visible alerts displayed in the Triage page.View Count No Grouping View 10,20,30,50 (Default 20) Entity Grouping View 5,10,20,30 (Default 10) Alert Type Grouping View 5,10,20 (Default 10) Investigations Table View 5,10,20 (Default 10)  Content Manager expanded to support All alert typesIt is now possible to install all alert types not just “each” from Content Manager.Rolling Deviation Gradient Several EachContent Manager Subquery SupportSubqueries are now supported by adding these parameters:externalOffset internalOffset internalPeriodTriage FilteringTriage can now filter Entities using AND / OR conditions.Increased security of investigations and Enigma EndpointsUpdates to internal APIs are adapted to Devo roles with the associated End Points. Learn more in our Docs page!

Related products:Devo SecOps

Devo Platform release 8.1.6

This update brings you a ton of API improvements, new role permissions and tons of fixes! Region Status GovCloud Released CA Released US Released EU Released APAC Released  Table of contentsAdministration Multitenancy  Aggregation Alerts Summary and Description areas DeepTrace information visual improvements Data Search Depreciated Operations API New features Aggregation Tasks API Lookups API Query API Bug fixes AdministrationRole PermissionsMultitenancy We’ve added a new role permission Multitenancy administration –> Custom data access with Edit mode able to allow/restrict the access to the Administration → Multitenancy → Custom data access tab.AggregationNew Token permission added to allow the use of the new Aggregation Tasks Token (detailed below) AlertsSummary and Description areasWe’ve increased the area width up to a maximum of 90 standard characters (since not all characters are the same size, some lines may show more than 90 characters and others less, depending on the type of characters included in the line). We now display the full content of both areas (Summary and Description).DeepTrace information visual improvementsRenamed the heading “Auto-investigation status” as “Trace status”. Renamed DeepTrace statuses : Status “No trace found” renamed as “No trace”. Status “Success” renamed as “Trace found”. DeepTrace icon moved to the first place in the Actions column. We’ve also made some small improvements to error messages across the platform. Data SearchDepreciated OperationsDepreciated Operation New Equivalent Operation mmcoordinates mm2coordinates mmlatitude mm2latitude mmlongitude mm2longitude mmcity mm2city mmcountry mm2country mmpostalcode mm2postalcode mmregion mm2subdivision1 mm2subdivision2 mmregionname There is no exact equivalent. You can use: Geolocated level 1 Subdivision with Maxmind GeoIP2 (mm2subdivision1) Geolocated Level 2 Subdivision with Maxmind GeoIP2 (mm2subdivision2) mmisp mm2ips mmorg mm2org mmasn mm2asn mmasowner mm2asorg mmspeed mm2con reputation N/A reputationscore N/A sbl N/A  What does Depreciated mean? The operation is still valid, but no longer updated. The operation will not be displayed in the Data search wizard nor in the Smart Editor autocompletion function. When the operation is used in a query, the notification “<ope> operation is deprecated” will be displayed. When you try to edit a query breadcrumb that contains one of those operations, it won’t be allowed and the notification “<ope> operation is deprecated. It can only be edited manually in the query editor” will be displayed. API New featuresAggregation Tasks APIWe’ve added the new token type “Aggregation Tasks API” in Administration → Credentials → Authentication tokens to only manage Aggregation Tasks API.From this release on, the tokens that allow you to manage Aggregation Tasks API are:For new tokens: only the ones created with “Aggregation Tasks API” type. For already-created tokens : all tokens that are currently used to manage Aggregation Tasks API.Furthermore, we’ve added a new role permission with View/Edit modes.Lookups APIAutofill domain in query when it is missing for my.* tablesAutofill domain in query when it is missing for my.* tables. Create/update lookup:Now you can create/upload a lookup from a CSV located in S3. Lookup id in the request body is not required anymore. If not informed, it takes the lookup name and domain from the path.GET lookup/domain and GET lookup/domain/name:Domain owner is not shown for each lookup. Improvements in GET/lookup/job.Lookup ownership vs lookup visibility: A lookup is owned by a domain but it can be created to be visible by other domains. Visibility is assigned when creating/updating a lookup: (i)creator_only: lookup will only be visible by the owner (ii)all-subdomains: only for multitenant admin domains. All domains inside the multitenant will see the lookup. Get list of lookups based on lookup ownership: GET lookup/<domain_name> GET lookup/<domain_name>?owner=THIS_DOMAIN → default value GET lookup/<domain_name>?owner=OTHER_DOMAINS GET lookup/<domain_name>?owner=ANY_DOMAIN Query API Time control support using “timeRangeFilter” configuration: "by" default to “eventdate“. Use “creationdate” for event creation time selection. Optional "allowedLateness": Default to "now" Allows duration expressions like: 1d, 1h, etc. Bug fixesIn Data search, the formatdate operation would display its results according to the computer’s time zone instead of according to the web time zone.. The Alert page vertical scroll wasn’t working correctly, resulting in some alerts not being shown. The Alert page vertical scroll wasn’t always visible. In domains with a large amount of alert sending policies, the Alert policies page was unresponsive at times.  There was an issue that affected Lookups with the same name in different domains, whereby if one was updated then the “last updated” date in both domains would be the same.  Shared Lookups would be incorrectly displayed as private once they were updated.  In the Administration → Users → Access details tab, when searching for a Permission/Activeboard/Lookup/Alert that doesn’t exist, the search box disappears and the following error message was displayed: “There are no Permissions/Activeboards/Lookups/Alerts for the assigned role”

Related products:Devo Platform

Flow 1.25 Now Available

Flow has been updated with new functionality and features.  New tooltips and module functionality await! Region Status CA Released US Released EU Released APAC Released GovCloud Released  Table of ContentsNew Features and Functionality Informative variables Delete Template AutoSave implemented New Module Functionality Indicators Module HTTP Module DevoSource Module Additional ImprovementsNew Features and Functionality Informative variablesNew tool tips were added to variables providing a description and best practices.Delete TemplateYou can now delete Templates from the Flow ManagerAutoSave implementedWhen you create a new instance, Flow will now trigger an autosave of the instance. New Module Functionality Indicators ModuleA new port was added to the Indicators Module that will allow for discarded events.  When events have dates that do not fit the active time window, they can now be discarded through this new port named; indicator1.out.discardedHTTP ModuleNew port added to allow you to Retry connection.  2 New tabs where also added to help configure retry attempts.General Tab - Configure all errors that are not affected by a rule (Default retries configuration). The retries will be configured by an input that represents if retries are enabled and the number of retries (greater than zero). Rules Tab - Each rule needs an input to configure if retries are enabled and the number of retries (greater than zero).DevoSource ModuleDevSource now support SubQueries! Additional ImprovementsGeneral Usability and bug fixes. Check out the full release notes in our Docs.

Related products:Devo Platform

Devo Exchange 1.5 release

Devo is happy to present the latest version of Devo Exchange!  In this update, you will find a new way to find and install MITRE Alerts as well as a collection of quality improvements!Video Preview UI Redesign Alert Pack and Content redefinition for MITRE Alerts New MITRE SectionVideo Preview UI RedesignThe design team has done a great job of improving the Devo Exchange experience with a new Header, submenus, easier navigation and a host of other visual improvements.Content can now include video elements and guides!In addition:New & Noteworthy renamed to Newest Recently visited can now be found in Discover Use cases and Most popular section removed from Discover Alert Pack and Content redefinition for MITRE AlertsAlerts will continue to be published in packs but now you have to install each alert individually.  Giving you complete control of which alerts to install and when.Each alert inside a pack will be listed with information and code buttons showing the purpose of the alert as well as the code so you can examine the queries.Through the Alert Pack panel, you can also manage the install/uninstall for each alert in the pack. New MITRE SectionExchange’s main window now has a MITRE Section tab, collecting all the content relating to MITRE ATT&CK.   If you are new to the MITRE ATT&CK framework, it is a guideline for classifying and describing cyberattacks and intrusions.MITRE Section IncludesMITRE ATT&CK Adviser App - A must-have application detailing the coverage of your current alerts as compared to the MITRE ATT&CK Techniques available. Content Packs - This group corresponds to the MITRE ATT&CK Tactic and all the content available for that tactic. Alert Packs - Containers filled with Alerts that correspond with the techniques used for a particular MITRE ATT&CK tactic. Lookups - Enrichments required for the installation of certain alerts. Visit our Docs for the complete release notes.

Related products:Devo Exchange

Flow 1.18

Flow, Devo’s correlation engine has received a major update with the release of Devo Platform 8.0!  This new version includes new Templates and Instances.Table of ContentsNew Features Templates & Instances Example  Convert Flow to Template New Open window with Filters Flow Manager updated Bug FixesNew FeaturesTemplates & InstancesTemplates define the general layout, design and pattern of a flow.  Modified templates are instances of the parent template.ExampleIn the context of an alert system, a Template for an ‘each’ alert defines the flow structure then you can create an instance for the “each” type of alert.Modifying a Template updates the existing instances.  Modifying an instance only affects that instance.The benefits of this new features are many.  You can quickly edit many flows by updating the template.  You can also quickly address many similar use cases with instances of a template. Convert Flow to TemplateNew Edit menu option to convert existing Flows into Templates.  The existing flow can be converted to a Template + Instance flow, preserving your work while taking advantage of the new Template system.New Open window with FiltersYou can no open a Flow, Template or Instance with sort and filter commands for Name, Creator, Type and Status columns.Flow Manager updatedIncludes new tab for Templates and new column for identifying the type of the context, be it Flow or Instance. Bug FixesEvent Section Closing on Delete - Fixed! File/Recent long context names - Fixed! Unclickable unit description - Fixed! Link to Release notes in Documentation.

Related products:Devo Platform