What is New in This Release
- Supports webhook-based alert ingestion with vendor-specific integrations.
- Enhanced deduplication logic for avoiding redundant alert processing.
- Advanced enrichment workflows, including integration with Knowledge Base Articles (KBAs) and observables.
- Introduces cron-based scheduling for automated alert retrieval.
- Standardizes alerts into TEDS objects for downstream processing.
- Integrates deduplication, enrichment, and correlation workflows.
- Automates phishing email retrieval, processing, and triage using cron scheduling.
- Extracts and adds custom fields to phishing email workflows for advanced customization.
- Includes correlation logic to identify related CIM records.
- Enriches observables with Threat Intelligence (TI) data for contextual analysis.
- New Modular Components:
- SOC - Link Knowledge Base Articles
- SOC - Enrich Observables
- SOC - Correlate
- Custom Alert Data Extension
- Hero AI Native Action Update:
- Hero AI generated Case Summerization and Recommended Actions updated to the new platform native Hero AI Canvas action.
- Hero AI generated Executive Summary updated to the new platform native Hero AI Canvas action.
This release ensures a streamlined, customizable, and scalable approach to SOC workflows, providing improved operational efficiency and effectiveness.
For additional details, refer to the updated SOC Solutions BundleSOC Solutions Bundle documentation or contact your Swimlane representative.