Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

What's new in 8.7 #3028

Closed
24 of 25 tasks
jmikell821 opened this issue Feb 28, 2023 · 0 comments · Fixed by #3111
Closed
24 of 25 tasks

What's new in 8.7 #3028

jmikell821 opened this issue Feb 28, 2023 · 0 comments · Fixed by #3111
Assignees

Comments

@jmikell821
Copy link
Contributor

jmikell821 commented Feb 28, 2023

Please add your features/enhancements for 8.7. Don't forget to include the corresponding PR. Thanks!

Detections & Response/Platform

Alerts

Rules

Defend Workflows

Threat Hunting

Cloud Security

Integrations

  • Add which new integrations were added.

Protections Experience

  • Credential Access Events are now available in production
  • IoCs can be added to the blocklist: You can add indicators to the blocklist to prevent selected applications from running on your hosts. You can add indicators that have the file indicator type and hash values for the MD5, SHA-1, or SHA-256 fields. IoCs can be added to blocklists #3024
  • Changes to the Indicator details flyout that opens from cases: The Indicator details flyout now has the Overview and Table tabs when you open indicator details from a case comment. Overview and Table tabs added to Indicator details flyout in cases #3022
  • Improvements to the indicators feature: Timeframe for indicator Timeline query updated  #3034
    • When a user investigates an indicator in Timeline, the new Timeline that opens has a start and end date that's 7 days before and 7 days after the indicator's timestamp.
    • You can now delete values entered into the Stack by field in the Trend chart.
    • When you open the Indicator table's field browser, the agent, base, and event fields categories are already preselected.

ResponseOps

  • Cases can be shared: Each case has a universally unique identifier (UUID) that you can copy and share. You can access a case's UUID from the Cases page or the case details page. Changes to the case feature in 8.7  #3053
  • Improvements to cases: Changes to the case feature in 8.7  #3053
    • In the Overview dashboard, users can go to the Recent cases widget and sort by cases assigned to them.
    • Several improvements have been made to the Cases table:
    • Users can bulk edit assignees.
    • The Updated on column has been added and shows the last time cases were modified.
    • Users can sort the Status, Severity, and Name columns.
    • Filters and sorting changes are persisted in the browser.

Asset Management

  • Use placeholder fields in Osquery queries: Instead of hard-coding alert and event values into Osquery queries, you can use placeholder fields to dynamically pass this data into queries. Placeholder fields function like parameters. You can use placeholder fields to build flexible and re-usable queries. Placeholder fields and Osquery UI updates #3045
  • Easy way to add Osquery queries from rule's investigation guide to Osquery Response Action: Now, if a rule is using an Osquery query in it's investigation guide, you can quickly add the query to the rule's Osquery Response Action. Osquery UI changes in 8.7 #3070
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant