Skip to main content

Popular Updates

featured-image
featured-image
featured-image
featured-image

Devo SOAR Release m113.8

New SOAR release includes new functionality, vulnerability and bug fixes! Geo AvailabilityRegion Status CA Released US Released EU Released APAC Released  Table of ContentsNew features New Actions for Sailpoint New to Zendesk Integration Improvements Bug Fixes New featuresNew Actions for SailpointSailpoint Integration has added 6 new actions:Search List Accounts Delete Account Get Account Activity List Account Activities Get AccountNew to Zendesk IntegrationAdded token-based authentication at the connection level. ImprovementsDestination: Added retries and visibility of the result of forwarding.Improved performance of loading detection under My UseCases section.Disabled Query section when we run/update SQL node.Changed from Python2 to Python3 for vulnerability fix in the following integrations:GRR Nmap UtilitiesCode vulnerability fix by removing the usage of the static jar from:JDBC Microsft SQL ServerBug FixesIf a user’s password expires (per system security settings), or if an admin resets a user’s password and gives them a temporary password, that password can still be used for whatever the user wants in scripting without authorization being denied. We have fixed this now. Update Case/ Create Case action failing for field( type single select) update with an invalid value of integration Case Management. We have fixed this now. Showing proper error message when some error occurs in connecting the server or retrieving the message of integration Exchange (Quarantine Messages).

Related products:Devo SOAR
featured-image
featured-image

Collector Catalog Update: July

The Integrations team has released in this update, a selection of new collectors and updates to existing ones documented below! Geo availabilityRegion Status CA Released US Released EU Released APAC Released  Table of ContentsNew Collectors Spycloud Collector 1.0.0 Proofpoint CASB Collector 1.0.1 CyberArk EPM Collector 1.0.0 Taxii Collector 1.0.0 Collectors Updated Azure Collector 1.6.0 MS Graph 1.6.2 Google Workplace Alerts (aka Gsuite Alerts) 1.6.0 CrowdStrike API Resource Collector 1.4.2 Spycloud 1.0.1 Okta Collector 1.7.0 Cisco eStreamer collector 1.3.0 Rapid7 Insights 2.0.0 Office 365 Exchange Message Tracing 2.1.0  New CollectorsSpycloud Collector 1.0.0The SpyCloud collector can help fraud prevention teams stay ahead of customer ATO fraud by detecting and resetting exposed consumer passwords early in the breach lifecycle, heading off account takeover attempts. Full details here.Proofpoint CASB Collector 1.0.1Proofpoint Cloud App Security Broker (Proofpoint CASB) helps you secure applications such as Microsoft Office 365, Google Workspace, Box, and more. It gives you people-centric visibility and control over your cloud apps, so you can deploy cloud services with confidence. Full details here.CyberArk EPM Collector 1.0.0CyberArk is an Identity Security Platform that enables secure access for any identity — human or machine — to any resource or environment from anywhere, using any device. Full details here.Taxii Collector 1.0.0Trusted Automated Exchange of Intelligence Information (TAXII™) is an application protocol for exchanging CTI over HTTPS. ​TAXII defines a RESTful API (a set of services and message exchanges) and a set of requirements for TAXII Clients and Servers. Full details here. Collectors UpdatedAzure Collector 1.6.0» DetailsMS Graph 1.6.2» DetailsGoogle Workplace Alerts (aka Gsuite Alerts) 1.6.0» DetailsCrowdStrike API Resource Collector 1.4.2» DetailsSpycloud 1.0.1» DetailsOkta Collector 1.7.0» DetailsCisco eStreamer collector 1.3.0» DetailsRapid7 Insights 2.0.0» DetailsOffice 365 Exchange Message Tracing 2.1.0» Details

Related products:Devo Integrations
featured-image

Devo Exchange Catalog Update: July

Devo Exchange and SciSec Teams hare happy to announce the Content update for July for Devo Exchange! Geo AvailabilityRegion Status CA Released US Released EU Released APAC Released  Table of ContentLookups MitreAlertsExtendedDefinition Activeboards Cloud Azure Summary Office365 Active Directory Proxy Zxcaler Activity Office365 Overview Use Cases Office365 Overview Use Case Content Packs 14 MITRE Tactics Content Packs 97 MITRE Technique Alert Packs  LookupsMitreAlertsExtendedDefinitionThis lookup will allow you to add Alerts to your MITRE ATT&CK Adviser mapped to multiple tactics and techniques.  You can still use SecOpsAlertDescription to and alerts with a single mapping. ActiveboardsCloud Azure SummaryGive a summary to clients about their Azure events like geolocalization, severities, average duration, critical events...Office365 Active DirectoryOverview of Office 365 Active Directory user and login eventsProxy Zxcaler ActivityGeneral overview of Zscaler Proxy solution and activity.Office365 OverviewShows a summary of all Microsoft Office 365 activity: Active Directory, SharePoint, OneDrive, Teams and Exchange. Use CasesOffice365 Overview Use CaseWorks with the Office365 Management Injection synthetic data and the Office365 Overview activeboard Content Packs14 MITRE Tactics Content PacksFull List available here.97 MITRE Technique Alert PacksFull list available here 

Related products:Devo Exchange
featured-image
featured-image

Devo Platform release 8.2.15

The next release of the Devo Product is almost here.   You might have noticed more update announcements more often,  the team is working hard to make sure you have the right information at the right time!   Here are the coming changes to the product! Geo AvailabilityRegion Status CA Released US Released EU Released APAC Released  Table of ContentsNew Features Built-in application preferences at the domain level New Sensitive data handling Deprecated Action Improvements X.509 New status Bug Fixes New FeaturesBuilt-in application preferences at the domain levelAllows the user to manage “application preferences” at the domain level for applications that have built-in preferences. New Sensitive data handlingTo address the problem of sensitive data being exposed to any user role and provide flexibility in audit actions the team has created the following rule:Only hide those parameters coming from requests with URL-encoded content and using HTTP verbs other than “GET”. Deprecated ActionRemoved add data from Dropbox action due to lack of user adoptions. ImprovementsX.509 New statusX.509 Certificates gain new status “Expired” in UI. In addition to this new status expired certificates:Cannot be downloaded. Will display a “---” in all columns except name and dates.Bug FixesFixed User Session invalidates prematurely Fixed Support form Send Fixed incorrect translation into Spanish in Autoparser.  

Related products:Devo Platform
featured-image
featured-image

Devo Platform 8.2.8 Release

This release of the Devo Platform brings you new features to Activeboards, Scheduled reports and User interaction improvements.Geo AvailabilityRegion Status CA Released US Released EU Released APAC Released  Table of contentsNew Features Activeboards Unified Y axis Two new methods added to Activeboads language Improvements Scheduled Reports - Hidden Recipients Scheduled reports - New Information fields Additional Improvements Bug Fixes New FeaturesActiveboards Unified Y axisThis new feature added in the Line/Column/Area widgets, will allow the user to have all the metrics in the same Y axis and with the same scale. The current behavior (a different Y axis/scale for each metric) will be also available.Two new methods added to Activeboads languageMethod Syntax Description Take take (query, N) Takes the first N elements from a data set Sort sort(query, columnName, ‘ASC’ | ‘DESC’) Sorts a dataset by column with ASC/DESC order  ImprovementsScheduled Reports - Hidden RecipientsThe To: field will now display as empty when sending Scheduled reports, maintaining privacy for all users.Scheduled reports - New Information fieldsNew information fields added:Field Name Available in Environment Subject and Content Domain Subject and Content Activeboard Name Content Creation Date Timezone Content (specified in Scheduling) Activeboard ID Content exclusive to error emails  Additional ImprovementsSpeed up Activeboard display times.  When opening activeboards, the default activeboard will be loaded, if no default is set, the first activeboard will be loaded. The full activeboard list can be requested from the Activeboard manager. Added new notification to Clone Activeboard command to notify user when an Activeboard is cloned successfully without opening. Improve Activeboad cloning operation, faster and a new spinner added notifying the user of continued action progress in background. Added a description field max character counter to Create new Activeboard dialog. UX improvements to reordering in Table Widget.Bug FixesFlickering issue fixed with the vertical scrollbar in the Activeboad Manager. Fixed issue with session timeouts Fixed issue with values missing when Menu Always Open was selected.View the full release in Docs!

Related products:Devo Platform
featured-image

Security Operations Release 3.27.3

This release of Security Operations brings in new functionality that improves analyst workflows in the triage and investigations workbenches and updates to the content manager!Geo AvailabilityRegion Status CA Released US Released EU Released APAC Released  Table of ContentsNew features Open in Dedicated tabs Improvements Increased Visible Alerts Content Manager expanded to support All alert types Content Manager Subquery Support Triage Filtering Increased security of investigations and Enigma Endpoints  New featuresOpen in Dedicated tabsWe have enhanced SecOps to allow you to open the entire application and sections in separate tabs, increasing the modularity of your workflow.SecOps - You can open SecOps in a new tab from the General Menu.Alerts from the Triage Page can now be launched in a new tab by right-clicking on the alert and choosing “open in a new tab”.Investigations can be opened in a new tab from the Triage page by right-clicking on the alert and selecting “open in a new tab”.Investigations can also be launched in a new tab from the investigations page by right-clicking on an alert and choosing “open in a new tab”ImprovementsIncreased Visible AlertsWe have increased the visible alerts displayed in the Triage page.View Count No Grouping View 10,20,30,50 (Default 20) Entity Grouping View 5,10,20,30 (Default 10) Alert Type Grouping View 5,10,20 (Default 10) Investigations Table View 5,10,20 (Default 10)  Content Manager expanded to support All alert typesIt is now possible to install all alert types not just “each” from Content Manager.Rolling Deviation Gradient Several EachContent Manager Subquery SupportSubqueries are now supported by adding these parameters:externalOffset internalOffset internalPeriodTriage FilteringTriage can now filter Entities using AND / OR conditions.Increased security of investigations and Enigma EndpointsUpdates to internal APIs are adapted to Devo roles with the associated End Points. Learn more in our Docs page!

Related products:Devo SecOps
featured-image
featured-image

Devo Platform release 8.1.6

This update brings you a ton of API improvements, new role permissions and tons of fixes! Region Status GovCloud Released CA Released US Released EU Released APAC Released  Table of contentsAdministration Multitenancy  Aggregation Alerts Summary and Description areas DeepTrace information visual improvements Data Search Depreciated Operations API New features Aggregation Tasks API Lookups API Query API Bug fixes AdministrationRole PermissionsMultitenancy We’ve added a new role permission Multitenancy administration –> Custom data access with Edit mode able to allow/restrict the access to the Administration → Multitenancy → Custom data access tab.AggregationNew Token permission added to allow the use of the new Aggregation Tasks Token (detailed below) AlertsSummary and Description areasWe’ve increased the area width up to a maximum of 90 standard characters (since not all characters are the same size, some lines may show more than 90 characters and others less, depending on the type of characters included in the line). We now display the full content of both areas (Summary and Description).DeepTrace information visual improvementsRenamed the heading “Auto-investigation status” as “Trace status”. Renamed DeepTrace statuses : Status “No trace found” renamed as “No trace”. Status “Success” renamed as “Trace found”. DeepTrace icon moved to the first place in the Actions column. We’ve also made some small improvements to error messages across the platform. Data SearchDepreciated OperationsDepreciated Operation New Equivalent Operation mmcoordinates mm2coordinates mmlatitude mm2latitude mmlongitude mm2longitude mmcity mm2city mmcountry mm2country mmpostalcode mm2postalcode mmregion mm2subdivision1 mm2subdivision2 mmregionname There is no exact equivalent. You can use: Geolocated level 1 Subdivision with Maxmind GeoIP2 (mm2subdivision1) Geolocated Level 2 Subdivision with Maxmind GeoIP2 (mm2subdivision2) mmisp mm2ips mmorg mm2org mmasn mm2asn mmasowner mm2asorg mmspeed mm2con reputation N/A reputationscore N/A sbl N/A  What does Depreciated mean? The operation is still valid, but no longer updated. The operation will not be displayed in the Data search wizard nor in the Smart Editor autocompletion function. When the operation is used in a query, the notification “<ope> operation is deprecated” will be displayed. When you try to edit a query breadcrumb that contains one of those operations, it won’t be allowed and the notification “<ope> operation is deprecated. It can only be edited manually in the query editor” will be displayed. API New featuresAggregation Tasks APIWe’ve added the new token type “Aggregation Tasks API” in Administration → Credentials → Authentication tokens to only manage Aggregation Tasks API.From this release on, the tokens that allow you to manage Aggregation Tasks API are:For new tokens: only the ones created with “Aggregation Tasks API” type. For already-created tokens : all tokens that are currently used to manage Aggregation Tasks API.Furthermore, we’ve added a new role permission with View/Edit modes.Lookups APIAutofill domain in query when it is missing for my.* tablesAutofill domain in query when it is missing for my.* tables. Create/update lookup:Now you can create/upload a lookup from a CSV located in S3. Lookup id in the request body is not required anymore. If not informed, it takes the lookup name and domain from the path.GET lookup/domain and GET lookup/domain/name:Domain owner is not shown for each lookup. Improvements in GET/lookup/job.Lookup ownership vs lookup visibility: A lookup is owned by a domain but it can be created to be visible by other domains. Visibility is assigned when creating/updating a lookup: (i)creator_only: lookup will only be visible by the owner (ii)all-subdomains: only for multitenant admin domains. All domains inside the multitenant will see the lookup. Get list of lookups based on lookup ownership: GET lookup/<domain_name> GET lookup/<domain_name>?owner=THIS_DOMAIN → default value GET lookup/<domain_name>?owner=OTHER_DOMAINS GET lookup/<domain_name>?owner=ANY_DOMAIN Query API Time control support using “timeRangeFilter” configuration: "by" default to “eventdate“. Use “creationdate” for event creation time selection. Optional "allowedLateness": Default to "now" Allows duration expressions like: 1d, 1h, etc. Bug fixesIn Data search, the formatdate operation would display its results according to the computer’s time zone instead of according to the web time zone.. The Alert page vertical scroll wasn’t working correctly, resulting in some alerts not being shown. The Alert page vertical scroll wasn’t always visible. In domains with a large amount of alert sending policies, the Alert policies page was unresponsive at times.  There was an issue that affected Lookups with the same name in different domains, whereby if one was updated then the “last updated” date in both domains would be the same.  Shared Lookups would be incorrectly displayed as private once they were updated.  In the Administration → Users → Access details tab, when searching for a Permission/Activeboard/Lookup/Alert that doesn’t exist, the search box disappears and the following error message was displayed: “There are no Permissions/Activeboards/Lookups/Alerts for the assigned role”

Related products:Devo Platform
featured-image

Flow 1.25 Now Available

Flow has been updated with new functionality and features.  New tooltips and module functionality await! Region Status CA Released US Released EU Released APAC Released GovCloud Released  Table of ContentsNew Features and Functionality Informative variables Delete Template AutoSave implemented New Module Functionality Indicators Module HTTP Module DevoSource Module Additional ImprovementsNew Features and Functionality Informative variablesNew tool tips were added to variables providing a description and best practices.Delete TemplateYou can now delete Templates from the Flow ManagerAutoSave implementedWhen you create a new instance, Flow will now trigger an autosave of the instance. New Module Functionality Indicators ModuleA new port was added to the Indicators Module that will allow for discarded events.  When events have dates that do not fit the active time window, they can now be discarded through this new port named; indicator1.out.discardedHTTP ModuleNew port added to allow you to Retry connection.  2 New tabs where also added to help configure retry attempts.General Tab - Configure all errors that are not affected by a rule (Default retries configuration). The retries will be configured by an input that represents if retries are enabled and the number of retries (greater than zero). Rules Tab - Each rule needs an input to configure if retries are enabled and the number of retries (greater than zero).DevoSource ModuleDevSource now support SubQueries! Additional ImprovementsGeneral Usability and bug fixes. Check out the full release notes in our Docs.

Related products:Devo Platform
featured-image

Devo Exchange 1.5 release

Devo is happy to present the latest version of Devo Exchange!  In this update, you will find a new way to find and install MITRE Alerts as well as a collection of quality improvements!Video Preview UI Redesign Alert Pack and Content redefinition for MITRE Alerts New MITRE SectionVideo Preview UI RedesignThe design team has done a great job of improving the Devo Exchange experience with a new Header, submenus, easier navigation and a host of other visual improvements.Content can now include video elements and guides!In addition:New & Noteworthy renamed to Newest Recently visited can now be found in Discover Use cases and Most popular section removed from Discover Alert Pack and Content redefinition for MITRE AlertsAlerts will continue to be published in packs but now you have to install each alert individually.  Giving you complete control of which alerts to install and when.Each alert inside a pack will be listed with information and code buttons showing the purpose of the alert as well as the code so you can examine the queries.Through the Alert Pack panel, you can also manage the install/uninstall for each alert in the pack. New MITRE SectionExchange’s main window now has a MITRE Section tab, collecting all the content relating to MITRE ATT&CK.   If you are new to the MITRE ATT&CK framework, it is a guideline for classifying and describing cyberattacks and intrusions.MITRE Section IncludesMITRE ATT&CK Adviser App - A must-have application detailing the coverage of your current alerts as compared to the MITRE ATT&CK Techniques available. Content Packs - This group corresponds to the MITRE ATT&CK Tactic and all the content available for that tactic. Alert Packs - Containers filled with Alerts that correspond with the techniques used for a particular MITRE ATT&CK tactic. Lookups - Enrichments required for the installation of certain alerts. Visit our Docs for the complete release notes.

Related products:Devo Exchange
featured-image

Flow 1.18

Flow, Devo’s correlation engine has received a major update with the release of Devo Platform 8.0!  This new version includes new Templates and Instances.Table of ContentsNew Features Templates & Instances Example  Convert Flow to Template New Open window with Filters Flow Manager updated Bug FixesNew FeaturesTemplates & InstancesTemplates define the general layout, design and pattern of a flow.  Modified templates are instances of the parent template.ExampleIn the context of an alert system, a Template for an ‘each’ alert defines the flow structure then you can create an instance for the “each” type of alert.Modifying a Template updates the existing instances.  Modifying an instance only affects that instance.The benefits of this new features are many.  You can quickly edit many flows by updating the template.  You can also quickly address many similar use cases with instances of a template. Convert Flow to TemplateNew Edit menu option to convert existing Flows into Templates.  The existing flow can be converted to a Template + Instance flow, preserving your work while taking advantage of the new Template system.New Open window with FiltersYou can no open a Flow, Template or Instance with sort and filter commands for Name, Creator, Type and Status columns.Flow Manager updatedIncludes new tab for Templates and new column for identifying the type of the context, be it Flow or Instance. Bug FixesEvent Section Closing on Delete - Fixed! File/Recent long context names - Fixed! Unclickable unit description - Fixed! Link to Release notes in Documentation.

Related products:Devo Platform
featured-image

Devo Platform 8.0 Release

Devo is proud to present the latest version of the Devo Platform.  Version 8.0 is a major update with a focus on unifying the User Interface and cleaning up the User Experience for ease of usability and consistency. In addition to this major overhaul, there are additional improvements to Activeboards, Web and Multitenancy features. Geo Availability <Region Status GovCloud Released CA Released US Released EU Released APAC Released  Table of ContentsNew Features New Devo UI Design Additional features of the new UI New Color Palette that provides support for Color Blind use Overall reduction of visual stress Alert anti-flooding User Inactivity Management New Activeboard features Added Stacked Column Widget Added Stacked Area Widget Added Dependency Wheel Widget Scheduled Reports improvements Delete Scheduled Reports New View Policy New “Scheduled” Filter New Clone Activeboard options Devo Flow 1.18 Bug Fixes  New FeaturesNew Devo UI DesignWhen you launch 8.0, you’ll find everything where you remember it but you will notice huge improvements in speed, accessibility and design familiarity between all the sections.The goals of this redesign are to make the Devo Platform:Faster to learn and use Provide a Modern unified design experience Scale consistently across all use cases  Additional features of the new UINew Color Palette that provides support for Color Blind useConfigurable Color system overlay to address the needs of users with Color Blindness.Overall reduction of visual stressThe UI color palette has been analyzed to reduce eye strain.Alert anti-floodingAlert notifications will now collapse into stacks including any similar alert notifications that where triggered within a specific timeframe.User Inactivity ManagementA new configurable user inactivity management interface has been added to settings.And more!(also, I know which visual mode you will immediately ask about and it is coming!)  New Activeboard featuresAdded Stacked Column WidgetThe Stacked Column widget visualizes a stacked bar chart.   A stacked bar chart is an extension of a column chart where each cluster of “n” categorical values, instead of being represented by a set of “n” columns is represented by just one column divided into “n” sections, where each section represents one of those categorical values within the cluster. The sections are stacked on top of each other and the section height represents the proportion of the categorical value within the cluster. Added Stacked Area WidgetSame description of the Stacked columns, but now in Area!Added Dependency Wheel WidgetThe dependency wheel diagram, also known as chord diagram, is a type of flow chart where data (two categorical variables) is arranged radially as two sectors of a circle (source and target) connected by arcs that represents the magnitude (a numerical value or “weight”) that makes up the relationship between both sectors. Scheduled Reports improvementsDelete Scheduled ReportsPreviously only through API but with this update you can now delete Scheduled reports through Web through the new option “Delete scheduled report”.New View PolicyNew view policy in role permission “Activeboards report scheduler” will allow the user to See and Filter Activeboards that have a scheduled report associated.New “Scheduled” FilterAdded a new “Scheduled” filter that will allow the user to filter those Activeboards with an associated schedule (regardless if it’s enabled or not).  Only users with role permission “Activeboards report scheduler” (“View” or “Manage”) will have this new filter available.New Clone Activeboard optionsYou can now “clone and close” or “clone and open” a cloned activeboard. Devo Flow 1.18Add Templates and Instances, read more here. Bug FixesFixed - “Last 5 Alerts” widget gets empty when Alert definition of an unread alert is deleted. Fixed - Error when trying to edit the details of the “Default” Finder Fixed - “Maximize window” in Query not working Fixed - Dragging a column in Cross-search table join makes column label unable to be edited. Fixed - Unable to delete column row if column value contains commasLink to release notes in Documentation.

Related products:Devo Platform

Endpoint Agent release 1.5.0

The latest Endpoint Agent release is now available!Geo AvailabilityRegion Status CA Pending US Released EU Released APAC Released  Table of ContentsGeo Availability New Features Compatibility with ARM architecture EPEL checks in Amazon Linux 2 Inventory checks include dependencies New outputs towards Devo Additional Changes Vulnerability fixing Improved Security Pipeline New Golang Version Update Procedure  New FeaturesCompatibility with ARM architectureThe deployment process of Endpoint Agent 1.5.0 generates extra packages for ARM architectures. Users can download an ARM-compatible package from the service available in port 8081.EPEL checks in Amazon Linux 2Extra Packages for Enterprise Linux checks are performed during installation, avoiding reinstallation in certain cases, which contributes to a reduced deployment time in Amazon Linux 2.Inventory checks include dependenciesEA deployment package includes a tool that helps check the state of the environment before starting the deployment process. The checkinvt tool now checks the status of required dependencies to ensure that the environment is ready for deployment.New outputs towards DevoExpose the configuration of the number of sockets that will be established toward Devo.By default, EA Manager opens five sockets toward Devo, and when events are sent, it selects one of the available sockets to send the data to. In the case that the thread cannot retrieve an available socket, an error is sent back to the Endpoint Agent and buffering occurs on the client side. To allow users to tune this scenario where the EA Manager has enough resources to allow for more outbound sockets, new configurations are exposed at EA Manager level.This parameter can be configured to solve congestion issues.  Additional ChangesVulnerability fixing The following vulnerabilities have been fixed in the EA Manager: CVE-2022-24999 CVE-2022-37601 CVE-2022-41723 Improved Security PipelineDelivered changes to the pipeline to be able to detect and fix vulnerabilities faster.New Golang VersionUpgraded golang version to 1.20.2 for EA Manager. Update ProcedureFollow the documented upgrade procedure listed here.

Related products:Devo Platform