You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
- Added the ability to create custom Event Dashboards in the Baselining and All Events sections. (AC-6)
53
-
- Added event insights by ChatGPT, enabling automatic analysis of THOR events with assessments and recommendations. Also, added the ability to ask ChatGPT to explain THOR events or terms within an event. (AC-89)
54
-
- Introduced a new 'Matched Signatures' section showing all matched signatures chronologically. (AC-83)
55
-
- Added the ability to collect files from an asset via the Management Center. (AC-10)
56
-
- Implemented a Data Retention Policy for retaining events for a specified period and automatically deleting them afterwards. (AC-12, AC-175)
57
-
- Added graphs and statistics to the Overview Dashboard. (AC-235, AC-299, AC-300, AC-301, AC-303, AC-309, AC-310, AC-316, AC-317)
68
+
- Added the ability to create custom Event Dashboards in the Baselining and All Events sections.
69
+
- Added event insights by ChatGPT, enabling automatic analysis of THOR events with assessments and recommendations. Also, added the ability to ask ChatGPT to explain THOR events or terms within an event.
70
+
- Introduced a new 'Matched Signatures' section showing all matched signatures chronologically.
71
+
- Added the ability to collect files from an asset via the Management Center.
72
+
- Implemented a Data Retention Policy for retaining events for a specified period and automatically deleting them afterwards.
73
+
- Added graphs and statistics to the Overview Dashboard.
58
74
59
75
----
60
76
61
77
* **Features**
62
78
63
-
- Added the ability to assign priorities to cases. (AC-84)
64
-
- Introduced a new field 'compromised' to track compromised assets. (AC-69)
65
-
- Added a detailed diagnostics status page showing system health and connectivity. (AC-182)
66
-
- Added a Diagnostics Pack that can be downloaded and sent to Nextron Systems for support. (AC-298)
67
-
- Included a base64 and hex decoder in the context menu of THOR events. (AC-18)
68
-
- Added a new field 'under investigation' to track ongoing investigations in cases. (AC-79)
69
-
- Added the ability to schedule reports, including the option to send them via email. (AC-229)
70
-
- Added the ability to enforce 2FA or password resets for users. (AC-231)
79
+
- Added the ability to assign priorities to cases.
80
+
- Introduced a new field 'compromised' to track compromised assets.
81
+
- Added a detailed diagnostics status page showing system health and connectivity.
82
+
- Added a Diagnostics Pack that can be downloaded and sent to Nextron Systems for support.
83
+
- Included a base64 and hex decoder in the context menu of THOR events.
84
+
- Added a new field 'under investigation' to track ongoing investigations in cases.
85
+
- Added the ability to schedule reports, including the option to send them via email.
86
+
- Added the ability to enforce 2FA or password resets for users.
71
87
72
88
----
73
89
74
90
* **Improvements**
75
91
76
-
- New index structure for events in Elasticsearch, significantly improving performance. (AC-313)
77
-
- Re-added the 'Incoming events' graph in Baselining and All Events sections. (AC-2, AC-289, AC-341)
78
-
- Improved the query for compromise assessment mode. (AC-348)
79
-
- Added the ability to edit case details and conditions in the 'Add to Case' dialog. (AC-28, AC-172)
80
-
- Added the ability to bulk merge cases, including merging cases with different assignment types. (AC-238, AC-167)
81
-
- Forwarded OS information to the Security Center now uses data from the Management Center. (AC-85)
82
-
- Display which users have set up 2FA in the user management section. (AC-13)
83
-
- Added a stop button for 'Auto Baselining'. (AC-14)
84
-
- Enhanced bulk actions in the case table, allowing editing of tags, priorities, and more. (AC-23)
85
-
- Automatically adjust heap size for Elasticsearch and MariaDB based on system memory. (AC-160)
86
-
- Re-added the 'Last 30 days' filter in the event table of an asset or case. (AC-196)
87
-
- Added a 'Delete' button in the table of connected Management Centers. (AC-197)
88
-
- Enhanced security by preventing API endpoint leaks and using a more secure password hash algorithm. (AC-215, AC-370)
89
-
- Refactored the case comments section. (AC-266)
90
-
- Display additional asset information like file systems and MAC addresses. (AC-286)
91
-
- Improved support for THOR 10.7, especially for case assignments using Auto Case IDs. (AC-287)
92
+
- New index structure for events in Elasticsearch, significantly improving performance.
93
+
- Re-added the 'Incoming events' graph in Baselining and All Events sections.
94
+
- Improved the query for compromise assessment mode.
95
+
- Added the ability to edit case details and conditions in the 'Add to Case' dialog.
96
+
- Added the ability to bulk merge cases, including merging cases with different assignment types.
97
+
- Forwarded OS information to the Security Center now uses data from the Management Center.
98
+
- Display which users have set up 2FA in the user management section.
99
+
- Added a stop button for 'Auto Baselining'.
100
+
- Enhanced bulk actions in the case table, allowing editing of tags, priorities, and more.
101
+
- Automatically adjust heap size for Elasticsearch and MariaDB based on system memory.
102
+
- Re-added the 'Last 30 days' filter in the event table of an asset or case.
103
+
- Added a 'Delete' button in the table of connected Management Centers.
104
+
- Enhanced security by preventing API endpoint leaks and using a more secure password hash algorithm.
105
+
- Refactored the case comments section.
106
+
- Display additional asset information like file systems and MAC addresses.
107
+
- Improved support for THOR 10.7, especially for case assignments using Auto Case IDs.
92
108
93
109
----
94
110
95
111
* **UX**
96
112
97
-
- Improved the error message when Elasticsearch aborts a query due to RAM issues. (AC-86)
98
-
- Prevented 'raw contains' search with an empty value. (AC-1)
99
-
- Enabled submitting a Lucene query with the 'Enter' key. (AC-39)
100
-
- Moved submit buttons from left to right. (AC-21)
101
-
- Enhanced the visibility of the right-click context menu for events. (AC-16)
102
-
- Improved the 'Merge case' dialog and positioning of search bubbles in the event table. (AC-34, AC-42)
103
-
- Show 'group scan' in the scan table. (AC-46, AC-47)
104
-
- Reuse the last status and type of the previous guided baselining case as the default for the next one. (AC-49)
105
-
- Added a description to unresolvable Auto Case IDs. (AC-51)
106
-
- Improved the column preferences dialog for tables with many columns. (AC-59)
107
-
- Removed links from breadcrumbs. (AC-62)
108
-
- Added dark mode for API documentation. (AC-71)
109
-
- Hide the Valhalla link for some YARA rules, e.g., external or custom rules. (AC-74, AC-27)
110
-
- Enabled dragging and dropping condition terms in the 'Create Case' dialog. (AC-102)
111
-
- Moved example events in 'Create Case' from top to bottom and made them expandable. (AC-103, AC-104)
112
-
- Improved error messages for login failures due to incorrect credentials. (AC-151)
113
-
- Enabled selecting asset labels and case tags from a dropdown when creating reports. (AC-228)
114
-
- Enhanced cosmetics for tooltips in event charts. (AC-177)
115
-
- Allowed searching for displayed text instead of numeric values in most tables. (AC-204, AC-282)
116
-
- Removed zero bytes ('\x00') from THOR events in the GUI. (AC-19)
117
-
- Preserved conditions when switching from guided to custom mode in the condition builder. (AC-36)
118
-
- Display version number and 'up-to-date' status on the overview page. (AC-223)
119
-
- Hide deleted Management Centers in the connected Management Centers table. (AC-251)
120
-
- Updated menu items for the sandbox. (AC-253)
121
-
- Showed actual values instead of numeric values in event charts (e.g., for case type). (AC-256)
122
-
- Improved change history for cases, showing the diff of conditions. (AC-259)
123
-
- Added THOR key highlighting in Guided Baselining. (AC-284)
124
-
- Rearranged menu items in the settings section. (AC-307)
125
-
- Enhanced cosmetics for the 'similar cases' dropdown in the 'Create Case' dialog. (AC-264)
126
-
- Optionally hide all non-favorite THOR keys. (AC-319)
127
-
- Moved manuals and API documentation to the navbar. (AC-339)
128
-
- Highlighted searched terms in the Event table. (AC-355)
113
+
- Improved the error message when Elasticsearch aborts a query due to RAM issues.
114
+
- Prevented 'raw contains' search with an empty value.
115
+
- Enabled submitting a Lucene query with the 'Enter' key.
116
+
- Moved submit buttons from left to right.
117
+
- Enhanced the visibility of the right-click context menu for events.
118
+
- Improved the 'Merge case' dialog and positioning of search bubbles in the event table.
119
+
- Show 'group scan' in the scan table.
120
+
- Reuse the last status and type of the previous guided baselining case as the default for the next one.
121
+
- Added a description to unresolvable Auto Case IDs.
122
+
- Improved the column preferences dialog for tables with many columns.
123
+
- Removed links from breadcrumbs.
124
+
- Added dark mode for API documentation.
125
+
- Hide the Valhalla link for some YARA rules, e.g., external or custom rules.
126
+
- Enabled dragging and dropping condition terms in the 'Create Case' dialog.
127
+
- Moved example events in 'Create Case' from top to bottom and made them expandable.
128
+
- Improved error messages for login failures due to incorrect credentials.
129
+
- Enabled selecting asset labels and case tags from a dropdown when creating reports.
130
+
- Enhanced cosmetics for tooltips in event charts.
131
+
- Allowed searching for displayed text instead of numeric values in most tables.
132
+
- Removed zero bytes ('\x00') from THOR events in the GUI.
133
+
- Preserved conditions when switching from guided to custom mode in the condition builder.
134
+
- Display version number and 'up-to-date' status on the overview page.
135
+
- Hide deleted Management Centers in the connected Management Centers table.
136
+
- Updated menu items for the sandbox.
137
+
- Showed actual values instead of numeric values in event charts (e.g., for case type).
138
+
- Improved change history for cases, showing the diff of conditions.
139
+
- Added THOR key highlighting in Guided Baselining.
140
+
- Rearranged menu items in the settings section.
141
+
- Enhanced cosmetics for the 'similar cases' dropdown in the 'Create Case' dialog.
142
+
- Optionally hide all non-favorite THOR keys.
143
+
- Moved manuals and API documentation to the navbar.
144
+
- Highlighted searched terms in the Event table.
129
145
130
146
----
131
147
132
148
* **Bugfixes**
133
149
134
-
- Fixed an issue where bulk updating cases with many events would fail. (AC-87)
135
-
- Fixed an error when creating a case without a name. (AC-95)
136
-
- Corrected the event count in the detailed view of the most frequent event values. (AC-35)
137
-
- Fixed sorting of the level by criticality instead of alphabetically. (AC-70)
138
-
- Fixed issues with hiding columns in the column preferences. (AC-157)
139
-
- Reduced occurrence of MariaDB deadlock errors. (AC-161)
140
-
- Fixed 'could not create GUI notification file' error. (AC-163)
141
-
- Resolved errors when downloading sandbox files. (AC-173)
142
-
- Made the 'Re-link' button visible in the connected Management Centers table. (AC-198)
143
-
- Corrected the event count in some Group Scans. (AC-203)
144
-
- Fixed typos in success and error messages. (AC-207, AC-208)
145
-
- Improved report generation speed by eliminating unnecessary data. (AC-25)
146
-
- Ensured the green loading indicator is always visible. (AC-220)
147
-
- Fixed the backup script. (AC-315)
148
-
- Resolved cut-off elements in the UI. (AC-326, AC-327)
149
-
- Corrected a typo in the version number in /etc/issue. (AC-217)
150
-
- Fixed issues with the http proxy configuration on fresh installations. (AC-545)
150
+
- Fixed an issue where bulk updating cases with many events would fail.
151
+
- Fixed an error when creating a case without a name.
152
+
- Corrected the event count in the detailed view of the most frequent event values.
153
+
- Fixed sorting of the level by criticality instead of alphabetically.
154
+
- Fixed issues with hiding columns in the column preferences.
155
+
- Reduced occurrence of MariaDB deadlock errors.
156
+
- Fixed 'could not create GUI notification file' error.
157
+
- Resolved errors when downloading sandbox files.
158
+
- Made the 'Re-link' button visible in the connected Management Centers table.
159
+
- Corrected the event count in some Group Scans.
160
+
- Fixed typos in success and error messages.
161
+
- Improved report generation speed by eliminating unnecessary data.
162
+
- Ensured the green loading indicator is always visible.
163
+
- Fixed the backup script.
164
+
- Resolved cut-off elements in the UI.
165
+
- Corrected a typo in the version number in /etc/issue.
166
+
- Fixed issues with the http proxy configuration on fresh installations.
151
167
152
168
----
153
169
154
170
* **Chore**
155
171
156
-
- Reduced the time range of signature feedback collection from 90 days to 30 days. (AC-131)
172
+
- Reduced the time range of signature feedback collection from 90 days to 30 days.
0 commit comments