Aug 01, 2023

This release includes improved analysis accuracy of Confidential Documents alerts, a new version (2.4.0) of the IntSights Splunk App, and the renewed Office 365 Integration.

Threat Command
Copy link

Improved
Copy link

  • Confidential Documents | Improve Analysis Accuracy: The Confidential Documents default Alert Profiler detection algorithm has been split into two rules - one detects DLP assets (enabled by default) and the other detects general DLP in document headers and footers (disabled by default). As a result, customers will see fewer FP Confidential Documents alerts.

Fixed
Copy link

IDCaseAreaDescription
CS-241804604282Leaked CredentialsPasswords appear as ‘NULL’.
CS-250504741047Leaked CredentialsThe number of exposed records in the alert title and in the attached spreadsheet is inconsistent.
BS-382204739207Alerts PagePreselected assets are hidden in the Assets filter.
CS-251004498790ADActive Directory policies do not function correctly.
IST-80004730391Remediation email updatesSome email remediation updates are not being sent to customers.

TIP
Copy link

New
Copy link

  • Integrations | Office 365 Integration Renewed: The Microsoft Office 365 integration is fully operational again. Users can see new configuration instructions in the online User Guide.

Improved
Copy link

  • New Splunk App Version 2.4.0 includes the following improvements:
    • Added a Macros Configuration page in UI to update macros.
    • Added an “IOC Status” filter in IOCs input configuration page to collect IOC data according to selected IOC status.
    • Added an IOC search filter and First Match Time column in the Correlation Details dashboard.
    • Updated the IOCs retirement logic to consider IOCLastSeen field for retirement.
    • Removed the “Verify SSL Certificate” checkbox from the configuration page.
    • Updated the retirement policy of IOCs for IOC type IP, Email, and Hash.
    • Added a default value for the index field while creating the input.
    • Made the Start date and Report date noneditable while editing input.
    • Enhanced the log messages.

Users can manage IOCs more efficiently through Splunk, while decreasing the FP rate.

Fixed
Copy link

IDCaseAreaDescription
TIP-709904681646IOC SourcesIOCs from an uploaded document were not sent to the integration.