Release 25 - Out-of-the-box alerts
Overview
In this latest update, we're thrilled to introduce a suite of enhancements to our SIEM detection capabilities. Benefit from enhanced performance with improved default filtering, ensuring faster and more precise threat identification. Our source_ipv4
field parsing has undergone a significant update, enhancing accuracy in pinpointing IP addresses within your network.
Additionally, we've revamped our Windows endpoint tools, equipping you with the latest features for robust threat monitoring and response. Furthermore, our field extraction methods have been fine-tuned, enabling more efficient extraction of actionable insights from your logs. Stay ahead of threats effortlessly with these comprehensive improvements.
Alert updates
Alert name | Update |
| Updated tools that are detected on the endpoint using the alert |
| Updated field extraction login based on logging parsing change |
| Improved default filtering |
| Improved default filtering |
| Improved default filtering |
| Improved default filtering |
| Improved default filtering |
| Update |