Threat Command / Nov 14, 2023

Nov 14, 2023

Platform

New

  • User Guide Migration to Rapid7 Docs: Threat Command Help documentation is now available on the same external-facing web page as all other Rapid7 products. Threat Command documentation can now be accessed and shared without logging in to Threat Command.
    Temporary limitations:
    • The Help links from inside Threat Command still lead to the legacy, online Help. We expect to redirect those soon.
    • Some formatting issues are still expected, we will gradually fix them.

Improved

  • IntSights SSO Disabled for Migrated Customers: IntSights SSO will be disabled for migrated customers (gradually over the next 2 weeks). Customers who are using IntSights SSO for JIT provisioning will need to start using SSO configured through the Rapid7 Insight Platform. To configure SSO through the Rapid7 Insight Platform, see the documentation.

VRA

Improved

  • New Sorting and Filtering Capabilities: To enhance the ability to swiftly identify and act on critical vulnerabilities, users can now:
    • Sort by number of affected hosts.
    • Filter by NVD publish and last modified date.
  • VRA | Filters Reorder: Filters were rearranged according to the anticipated sequence of utilizing the VRA analysis and user feedback.

Fixed

IDCaseAreaDescription
CS-264705265162VRAMOVEit CVE is not shown on the Vulnerabilities list.

Threat Command

Fixed

IDCaseAreaDescription
CS-270305478660AlertsLeaked credentials alerts are duplicated.
CS-263705137379AlertsCredentials leakage alerts are not processed by the policy.
PLT-68204501360IntellifindAlert query matched BIN numbers are not highlighted.