ThreatStream Documentation Updates
| Date | Description |
|---|---|
| Jul 23, 2026 | Updated Submitting Malware for Detonation. |
| Jul 8, 2026 |
Updated the activation process in Integrating with Zscaler. |
| Jun 24, 2026 |
Added Anomali PDRP Takedown Service. Added Activating the Anomali PDRP Enhanced Feed. Added the Added the URLhaus Hostlife open-source feed to Available Open Source Feeds. Added PIR system roles to Using System Roles. Added PIR permissions to Managing Roles . Added the Cognyte: Luminar IOCs, Leaked Credentials and AI Cyber Feeds premium feed to Available Premium Feeds. |
| Jun 10, 2026 | Added the following premium feeds to Available Premium Feeds: Intel 471 - Breach Alerts, Intel 471 - FINTEL Reports, Intel 471 - Geopolitical Reports, Intel 471 - Information Reports, Intel 471 - Malware Intelligence, Intel 471 - Spot Reports, Intel 471 -Vulnerability Reports, Intel 471 Verity - Credential Intelligence, Intel 471 Verity - Watcher Alerts, Check Point Exposure Management IoC Intelligence, Doppel, Added the Anomali C2 Detection, Anomali Credential Monitoring, and Anomali Early Warning. Added the Ransomfeed - Real-Time Ransomware Intelligence open-source feed to Available Open Source Feeds. Updated the integration process in Integrating with Zscaler. Updated the activation process in Activating the Anomali PDRP Enhanced Feed. |
| May 28, 2026 |
Updated the integration process in Integrating with Zscaler. Added the Anomali Threat Briefings and Anomali Dark Web Intelligence open-source feeds to Available Open Source Feeds. Updated Guidelines for Ingesting Phishing Emails. Updated Submitting Password Protected Archive Files to Joe Sandbox. Added information about the OCSF Filter field to Managing Roles . |
| May 13, 2026 |
Added Exporting Investigations to Existing Threat Models. Added RansomLook.io - Ransomware OSINT Feed to Available Open Source Feeds. |
| April 29, 2026 | Added Anomali Curated RSS OSINT, PhishHunt.io - Active Phishing Blocklist, PhishDestroy, ShadowWhisperer Malware Blocklist, and TweetFeed open source feeds to Available Open Source Feeds. |
| April 28, 2026 |
Updated the Intelligence and Threat Model Search API documentation about the new Added Workgroup API Resources. Added the |
| April 15, 2026 |
Added information about the following new indicator types: Updated General Guidelines for Importing Observables. Added information about the beta login page for signing in with SSO directly. For details, see Signing In to ThreatStream Using SSO. Updated Anomali Takedown Service to address the Takedown service enhancements. Added information about EPSS Score and EPSS Percentile to Viewing Vulnerability Details and Accessing Threat Models. Added the Anomali PDRP Enhanced section for the new PDRP service. |
| April 3, 2026 |
Added information about wildcard observables Guidelines for Structured Data. Added Wildcard Observables. |
| Mar 19, 2026 | Updated Using “update_id” to Retrieve Large Intelligence Datasets. |
| Mar 17, 2026 | Added information about the undo and redo chart options to Managing Investigation Entities. |
| Mar 9, 2026 | Added information about the Middle East Conflict - APT & Adversary Activity Monitor dashboard to Utilizing Themed Custom Dashboards from the Anomali Threat Research Team. |
| Mar 4, 2026 | Added information about including a full description in the email body when sharing threat model entities via email. For details, see Sharing Threat Model Entities via Email. |
| Mar 3, 2026 | Updated the Meta Attributes section in Import (without approval). |
| Mar 2, 2026 | Added information about the Middle East Conflict: Iran–Israel–USA Cyber Threat Monitor dashboard to Utilizing Themed Custom Dashboards from the Anomali Threat Research Team. |
| Feb 27, 2026 | Added Threat Bulletins Created From RSS Feeds. |
| Feb 26, 2026 | Added information about feeds to Limits in ThreatStream. |
| Feb 25, 2026 | Updated Credential Feed Activation. |
| Feb 20, 2026 | Updated the Comments section in Viewing Actor Details, Viewing Attack Pattern Details, Viewing Campaign Details, Viewing Course of Action Details, Viewing Custom Object Details, Viewing Identity Details, Viewing Incident Details, Viewing Infrastructure Details, Viewing Intrusion Set Details, Viewing Malware Details, Viewing Signature Details, Viewing TTP Details, Viewing Vulnerability Details, Viewing Tool Details, Viewing Threat Bulletin Details. |
| Feb 18, 2026 |
Added the DomainTools - Iris Detect premium feed to Available Premium Feeds. Added CERT.PL Malicious Domain Blocklist, Binary Defense, and Phishing Army open source feeds to Available Open Source Feeds. |
| Feb 10, 2026 | Added Selecting a User Interface Theme to Managing Your Profile Settings. |
| Feb 4, 2026 |
Added the ThreatStream API section to Online Help. See ThreatStream API. Added the new_domain itype to Indicator Types in ThreatStream. |
| Jan 28, 2026 | Added the SpyCloud Enterprise Protection premium feed to Available Premium Feeds. |
| Jan 26, 2026 |
Updated the integration activation process in Integrating with ServiceNow SecOps and Integrating with ServiceNow ITSM. Updated Information in a Sandbox Report. |
| Jan 21, 2026 |
Added GreyNoise - Benign IPv4 Scanner and GreyNoise Suspicious IPv4 Scanner premium feeds to Available Premium Feeds. Updated the note in Importing RSS Feeds. |
| Jan 6, 2026 |
Added information about MITRE ATT&CK v18.0 support to Using MITRE ATT&CK Frameworks in ThreatStream. Updated Receiving Rules Email Notifications. |
| Dec 10, 2025 |
Added information about the Lock SSO Configuration feature to Configuring Single Sign On (SSO). Added the VMRAY - UniqueSignal - Essentials premium feed to Managing Premium Feeds. |
| Dec 5, 2025 | Added rate limits for TAXII poll and push requests to Limits in ThreatStream and Connecting to Your ThreatStream TAXII Server From a TAXII Client. |
| Dec 4, 2025 | Updated the GreyNose documentation in Enriching Data with GreyNoise. |
| Dec 2, 2025 | Added Release Notes for Integrator 8.5.7. See Anomali ThreatStream Integrator Release History for details. |
| Nov 19, 2025 | Added the Abusix Threat Intelligence premium feed to Managing Premium Feeds. |
| Nov 11, 2025 | Updated Viewing Feed Details. |
| Nov 5, 2025 | Added the Falconfeeds.io premium feed to Managing Premium Feeds. |
| Oct 29, 2025 |
Removed the Anomali Adversary Intelligence and Anomali Vulnerability & Exploit Intelligence intelligence channels from Managing Anomali Intelligence Channels. Removed Anomali Botnets & C2 Intelligence premium feed from Managing Premium Feeds. |
| Oct 21, 2025 | Added support for Cisco Umbrella API v2 in Enriching Data with Cisco Umbrella Investigate. |
| Oct 15, 2025 | Added Upcoming Enhancements for a Faster Anomali Experience. |
| Oct 15, 2025 | Added Anomali Video Library. |
| Oct 13, 2025 | Added Group-IB ASM and Group-IB DRP premium feeds to Managing Premium Feeds. |
| Oct 13, 2025 | Added information about importing observables and Anomali Copilot summaries in RSS feed entries. See Importing RSS Feeds for details. |
| Oct 9, 2025 |
Added information about the What's New Panel to Navigating ThreatStream. |
| Oct 8, 2025 |
Added information about the Integrator Cloud link to Navigating ThreatStream. Updated Enabling User Management with Active Directory Federation Services and Azure Entra ID and Enabling User Management with SAML 2.0 IdP Services. |
| Oct 7, 2025 | Added the benign_domain indicator type to Indicator Types in ThreatStream and Threat Types in ThreatStream. |
| Oct 3, 2025 | Added Connecting Claude to ThreatStream MCP Using API Key. |
| Sep 30, 2025 |
Added a note to Importing RSS Feeds. Added Google Threat Intelligence to Managing Premium Feeds. |
| Sep 26, 2025 | Added information about the Passive DNS tab in Observables. |
| Sep 24, 2025 | Updated Anomali Copilot Chat. |
| Sep 23, 2025 | Added Importing RSS Feeds. |
| Sep 12, 2025 | Added Using the Anomali Platform in an MSSP Environment. |
| Sep 8, 2025 | Added Exporting MITRE ATT&CK Profiles. |
| Sep 2, 2025 | Updated Anomali ThreatStream Integrator Release History. |
| Aug 26, 2025 | Added Using Actor Profiles. |
| Aug 26, 2025 | Updated Creating Attack Flows. |
| Aug 20, 2025 | Updated ThreatStream Integrations. |
| Jul 29, 2025 | The Threatbook CTI feed has been renamed to SecAI CTI in Managing Premium Feeds. |
| Jul 28, 2025 |
Added Enriching Data with Google Threat Intelligence. Removed references to the Blueliv premium feed due to removal of the feed from the APP store. |
| Jul 23, 2025 |
Updated User Activity Audit.
Updated Enriching Data with Tenable Vulnerability Management. |
| Jul 15, 2025 |
Added information about the Attack Flow Layout in Managing Investigation Entities. |
| Jul 14, 2025 |
Added the following indicator types to Indicator Types in ThreatStream and Threat Types in ThreatStream: Updated Guidelines for Importing Observables Through STIX Data Import. |
| Jul 1, 2025 |
Added the |
| Jun 30, 2025 | Updated Guidelines for Advanced Search-Based Rules. |
| Jun 17, 2025 |
Added information about MITRE v17.0 and v17.1 support to Using MITRE ATT&CK Frameworks in ThreatStream. Added the Flexera Software Vulnerability Research premium feed to the list of available premium feeds. See Managing Premium Feeds. |
| Jun 16, 2025 |
Updated notes in Exporting Threat Model Entities in STIX Format. Removed references to the SEKOIA.IO Threat Intelligence premium feed due to deactivation of the feed. |
| Jun 10, 2025 | Added the Mandiant DTM premium feed to Managing Premium Feeds. |
| Jun 6, 2025 | Updated Using System Roles and Managing Roles . |
|
Jun 5, 2025 |
Updated Managing Free Feeds. |
| Jun 2, 2025 | Removed information about Mimecast premium feeds in Managing Premium Feeds. |
| May 22, 2025 | Updated the Analysis Links section in Observables. |
| May 20, 2025 |
Updated information about detonating malware on Polyswarm in Submitting Malware for Detonation. Added the User and Role Management on the Anomali Platformsection. |
| May 19, 2025 |
Removed the OpenPhish.com feed from Available Open Source Feeds. Removed the TeamT5 APT feed from Managing Premium Feeds. Added the ThaiCert and MITRE Attack feeds to Available Open Source Feeds. |
| May 16, 2025 |
Added Integrating with Microsoft Defender Threat Intelligence. Updated partner documentation to Enriching Data with IPQS Fraud and Risk Scoring. |
| May 6, 2025 | Removed references to the Cuckoo Sandbox integration, as this malware analysis service is no longer supported in ThreatStream. |
| Apr 30, 2025 | |
| Apr 11, 2025 |
Added new indicator types to Indicator Types in ThreatStream. Added new threat types to Threat Types in ThreatStream. |
| Mar 25, 2025 | Updated Anomali ThreatStream Integrator Release History. |
| Mar 12, 2025 | Updated ThreatStream Integrations. |
| Feb 26, 2025 | Added the note about supported Sigma rules versions to Evaluating Sigma Rules. |
| Feb 25, 2025 | Updated the list of open-source feeds. See Available Open Source Feeds for details. |
| Feb 19, 2025 |
Added Updated Threat Types in ThreatStream. |
| Feb 18, 2025 | Added the ShadowServer premium feed to the list of credentialed feeds in Managing Premium Feeds. |
| Jan 31, 2025 | Updated all how-to articles to reflect the platform navigation changes. |
| Jan 28, 2025 | Updated instructions on activating and using enrichments to reflect recent UI changes. |
| Jan 28, 2025 | Added the information about multiple stream IDs support by the Feedly for Threat Intelligence premium feed. For details, see Managing Premium Feeds. |
| Jan 24, 2025 | Updated ThreatStream Integrations. |
| Jan 24, 2025 | Added Enriching Data with Microsoft Defender Threat Intelligence. |
| Jan 21, 2025 | Removed the following articles: Enriching Data with Risk IQ; Integrating with Risk IQ. |
| Jan 17, 2025 | Updated Anomali ThreatStream Integrator Release History. |
| Jan 8, 2025 | Removed the following article: Bolstering Your Security Controls Against the Sunburst Supply Chain Attacks. |
| Dec 20, 2024 | Added instructions on how to find a data storage region to Enriching Data with InsightVM Vulnerability Management . |
| Dec 17, 2024 | Added the note to the Release History of the Anomali Copilot Extension and Office 365 Add-Ins. See Anomali Copilot Extension and Office 365 Add-Ins Release History for details. |
| Dec 17, 2024 | Removed the following article: Bolstering Your Security Controls Against COVID-19. |
| Dec 16, 2024 | Added Enriching Data with InsightVM Vulnerability Management . |
| Dec 5, 2024 | Added information about MITRE ATT&CK v16.1 support. See Using MITRE ATT&CK Profiles in ThreatStream for details. |
| Dec 4, 2024 | Added the links to Search, Dashboards, and Security Analytics Online Help Centers and PDF User Guides. See Welcome to Anomali documentation for details. |
| Dec 3, 2024 | Added the Search and Dashboards documentation to ThreatStream Online Help Center. See AQL Search and AQL Dashboards for details. |
| Dec 2, 2024 | Added the Polyswarm documentation for Anomali Polyswarm enrichment v1.6.8. See Enriching Data with PolySwarm for details. |
| Nov 19, 2024 | Added risk score information. See Using Copilot Asset Analyzer for details. |
| Nov 18, 2024 |
Added information about ServiceNow UI drop-down menu allowing you to select a ServiceNow user interface during the activation process of the ServiceNow integration. See Integrating with ServiceNow SecOps and Integrating with ServiceNow ITSM for more information. |
| Nov 7, 2024 | Added the required permission for user access control to Dashboards. See Enabling User Management with Active Directory and Active Directory Federation Services for details. |
| Nov 6, 2024 | Updated Anomali ThreatStream Integrator Release History. |
| Nov 31, 2024 | Updated guidelines for advanced search-based rules. See Rules for details. |
| Oct 28, 2024 | Updated ThreatStream OnPrem Release History. |