Releases
1.5.0
Compare
Sorry, something went wrong.
No results found
[v1.5.0] - April 28th, 2025
Added
Event Classes
Added Application Security Posture Finding event class to the Findings category. #1357
Added Live Evidence Info event class to Discovery category. #1382
Dictionary Attributes
Added boot_uid as a string_t. #1335
Added cpid as a uuid_t. #1246
Added raw_data_size as a long_t. #1347
Added assessments as an array of assessment objects. #1343
Added meets_criteria as a boolean_t. #1343
Added display_name attribute as a string_t. #1341
Added is_directed as a boolean_t, relation as a string_t, query_language & query_language_id a sibling pair. #1343
Added resource_relationship of type graph, nodes of type node, edges of type edge. #1343
Added fix_coverage as string_t and fix_coverage_id as int_t. #1350
Added eid, iccid, and meid as string_t. #1346
Added is_backed_up, is_mobile_account_active, and is_shared as boolean_t. #1346
Added detection_pattern_type an detection_pattern_type_id as a string_t and int_t respectively. #1310
Added external_id as an string_t. #1310
Added intrusion_sets as an array string_t. #1310
Added uploaded_time as an timestamp_t. #1310
Added isp_org as string_t. #1351
Added ldap protocol to auth_protocol_id enum. #1359
Added observation_parameter, observation_type, observed_pattern as string_t and occurrences as an array of occurrence_details. #1358
Added analysis_targets as an array of type analysis_target. #1371
Added num_volumes, num_infected as int_t, unique_malware_count, volume as string_t. #1373
Added end_column and start_column as integer_t. #1357
Added dependency_chain, exploit_requirement, and exploit_type as string_t. #1357
Added exploit_ref_url, license_url, package_manager_url, and uri as url_t. #1357
Added transformation_info_list #1392
Added authentication_token as authentication_token, kerberos_flags as string_t and is_renewable as boolean_t. #1391
Added tickets as an array of ticket objects. #1402
Added is_read as boolean_t. #1406
Added query_type and query_type_id as string and integer_t respectively. #1382
Added tcp_state_id as integer_t. #1382
Added query_evidence as type query_evidence. #1382
Added checks as type check. #1369
Objects
Added assessment object to capture evaluations/assessments of configurations/signals. #1343
Added node, edge, graph objects. #1343
Added anomaly, anomaly_analysis, baseline, observation objects. #1358
Added trait object. #1363
Added mitigation object. #1348
Added analysis_target object. #1371
Added malware_scan_info object. #1373
Added application object. #1357
Added campaign object #1310
Added threat_actor object #1310
Added transformation_info #1392
Added authentication_token object. #1391
Added query_evidence object. #1382
Added check object #1369
Observables
Added process_entity.uid as an Observable type - type_id: 39. #1380
Added email.subject and email.uid as an Observable types - type_id: 40 and type_id: 41. #1380
Added message_uid as Observable type - type_id: 42. #1380
Added reg_value.name as an Observable type - type_id: 43. #1380
Added advisory.uid as Observable type type_id: 44. #1357
Updated resource_details.uid, web_resource.uid, and win_resource.uid to be observable type_id: 10 #1394
Added file_path_t as an Observable type - type_id: 45 and marked fields as this type #1381
lineage dictionary attribute
affected_package.path object attribute
file.path object attribute
image.path object attribute
kernel.path object attribute
malware.path object attribute
process_entity.path object attribute
Added extensions/windows/reg_key_path_t as an Observable type - type_id: 46 and marked fields as this type #1381
reg_key.path object attribute
reg_value.path object attribute
Improved
Event Classes
Added assessments to config_state. #1343
Added raw_data_size to base_event. #1347
Added anomaly_analyses to detection_finding. #1358
Added Detect value for activity_id in Remediation events. #1362
Added resources to user_access. #1374
Added malware_scan_info, malware to detection_finding. #1373
Added authentication_token to authentication. #1391
Objects
Added boot_uid to device object. #1335
Relaxed constraint to provide email_addr, phone_number, or security_questions on auth_factor. #1339
Added cpid to process_entity object. #1246
Added boot_uid to device object. #1335
Added meets_criteria and policy to assessment object. #1343
Added assessments to compliance object. #1343
Added data to policy object. #1343
Added display_name attribute to the user and ldap_person objects. #1341
Added resource_relationship to resource_details object. #1343
Added fix_coverage, fix_coverage_id to vulnerability object. #1350
Added eid, iccid, is_backed_up, is_mobile_account_active, is_shared, and meid to device. #1346
Added is_backed_up to resource_details. #1346
Added isp, isp_org to network_endpoint & whois objects. #1351
Reduced requirement of standards to recommended in the compliance object. #1352
Updated MITRE attack, tactic, technique, subtechnique captions, descriptions, references to include MITRE ATLAS. Used standard requirements for _entity extended objects. #1355 .
Added name, resources, uid, verdict, and verdict_id to evidences. #1337
Added algorithm to analytic object. #1358
Added 'Network Zone' type to the managed_entity object enum list. #1364
Added 'count' start_time end_time to timespan object. #1365
Added traits to related_event object. #1363
Updated timespan to include a Time Window type_id and start_time, end_time to the at_least_one constraint. #1372
Added mitigation to attack object. #1348
Added timespan object to observation object. #1371
Added end_column, rule, and start_column to affected_code object. #1357
Added category and desc to compliance object. #1357
Added uri to the file object. #1357
Added license_url, package_manager, package_manager_url, src_url, and uid to package object. #1357
Added type, type_id, uid, and version to sbom object. #1357
Added category, dependency_chain, exploit_ref_url, exploit_requirement, and exploit_type to vulnerability object. #1357
Added status, status_id, status_details to ticket object; uid_alt, created_time to _resource object; traits to finding_info object. #1402
Added modified_time to _resource object; zone to resource_details object. #1403
Added countermeasures to mitigation object. #1348
Added is_read to email object. #1406
Added cis_controls to remediation object #1369
Added check object to compliance object #1369
Profiles
Added malware_scan_info to security_control profile. #1373
Added campaign, category, created_time, creator, desc, expiration_time, external_id, labels, malware, modified_time, name, detection_pattern, detection_pattern_type, detection_pattern_type_id, intrusion_sets, risk_score, references, uploaded_time, severity, uid and threat_actor to osint object. #1310
Added tickets to incident profile. #1402
Deprecated
Deprecated usage of isp attribute in the location object. #1351
Deprecated usage of occurrence_details in favor of occurrences in discovery_details object. #1358
Deprecated usage of resource in favor of resources in the user_access class. #1374
Deprecated usage of ticket in favor of tickets in incident profile and incident_finding event class. #1402
Deprecated kernel_object_query, file_query, folder_query, admin_group_query, job_query, module_query, network_connection_query, networks_query, peripheral_device_query, process_query, service_query, user_session_query, user_query, startup_item_query, registry_key_query, registry_value_query, and prefetch_query classes in favor of the live_evidence_info class. #1382
Deprecated compliance_references and compliance_standards in favor of the check object. #1369
Deprecated cis_csc in favor of cis_control object. #1369
Deprecated the Device Config State class in favor of the Compliance Finding class. #1369
Misc
Updated description of config_state to reflect the addition of the assessments object. #1343
Updated description of hw_info.uuid to clarify usage especially in presence of new device.udid field. #1354
Updated dictionary descriptions and references of MITRE attacks, tactic, technique, subtechnique. #1355
Added enhanced descriptions and references to requirements, standards, control_parameters, and control in the compliance object for clarity and usage. #1369
You can’t perform that action at this time.