Skip to content

[DOCS] What's new in 8.5  #2515

@jmikell821

Description

@jmikell821

Detections & Response/CTI

OLM

Threat Hunting

Protections Experience

ResponseOps

AWP

Cloud Security Posture

  • EKS support for KSPM - Users can now use the Kubernetes Security Posture Management integration to test the security of their Kubernetes clusters managed by EKS, in addition to unmanaged clusters. [DOCS] KSPM docs reorg #2539

Endpoint

N/A

Asset Management

  • Osquery results can be added to a case - After users run Osquery from an alert, they can add Osquery results to a new or an existing case. [DOCS] Osquery features in 8.5 #2561

  • Osquery Response Action - Users can use the the Osquery Response Action to immediately query hosts that generate alerts. Response Actions are in technical preview. [DOCS] Osquery features in 8.5 #2561

  • Running Osquery from an investigation guide - Users can now add queries to a rule's investigation guide and run it as part of their investigative steps when analyzing an alert. [DOCS] Osquery features in 8.5 #2561

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions