Anomali ThreatStream Integrator Release History
|
ThreatStream Integrator v8.5.8 includes the following improvements:
In addition, this release fixes the following issues in the previous release: INTS-13249: Updated cryptography and SSL components to address OpenSSL vulnerabilities CVE-2025-15467 and CVE-2025-68160 in Integrator version 8.5.7. INTS-13369: Resolved an issue where Integrator could display a blank page when the appliance was under heavy connection load, such as during frequent Nessus scans or sustained firewall polling. Additionally, the destination web server has been upgraded from HTTP/1.0 to HTTP/1.1 with persistent connections, reducing connection churn and improving throughput. |
|
ThreatStream Integrator v8.5.7 includes the following improvements:
In addition, this release fixes the following issues in the previous release: INTS-13180: QRadar sync to tag-based reference sets fails when the restricted iTypes are missing. INTS-13205: SDK/Extension based destinations show success status even if sync gets ignored due to previous sync failure. INTS-13211: Integrator remote login and snapshot API auth checks incorrectly use the proxy when it’s configured but not enabled for source sync, risking connectivity failures. |
|
ThreatStream Integrator v8.5.6 includes the following improvements:
|
|
ThreatStream Integrator v8.5.4 includes the following improvements:
|
|
ThreatStream Integrator v8.5.2 includes the following improvements:
|
|
ThreatStream Integrator v8.5.1 includes the following improvements:
|
|
ThreatStream Integrator v8.5.0 includes the following improvements:
In addition, this release fixes the following issues in the previous release: INTS-12837: In Maintenance Mode, opening and closing the manual instructions may have caused the Upgrade Now button to b enabled when no extensions had been selected for upgrade during Auto Upgrade. INTS-12811: Using an AWS SES (Simple Email Service) for an SMTP server when sending alerts generated an error if using an on-premise Integrator instance. INTS-12796: When using the Alerts option, the details were shown but disappeared leaving a blank page if the alert emails contained any user emails that became read-only user or inactive. INTS-12747: In previous versions, the remote threat model count was not included in the total listed in the Integrator user interface. |
|
ThreatStream Integrator v8.4.2 includes a number of security improvements.
|
|
ThreatStream Integrator v8.4.1 fixes the following issue in the previous release: INTS-12687 - There was an issue using trusted_circle_id in the source filter if you were using version 1 of the Intelligence API. This has been fixed in this release. |
|
ThreatStream Integrator v8.3.4 includes the following enhancements/improvements:
In addition, this release fixes the following issues in the previous version:
|
|
ThreatStream Integrator v8.3.1 fixes the following issues in the previous release:
|
|
ThreatStream Integrator v8.3 includes the following enhancements/improvements:
|
|
ThreatStream Integrator v8.2 includes the following improvements:
In addition, this version also fixes the issue with purging QRadar reference sets (no indication that the purge had completed) which was causing a problem with the sync process. Integrator now ensures that the purge is complete before proceeding with the sync. |
|
ThreatStream Integrator v8.1.2 fixes a number of issues in the previous release. The following issues have been fixed:
|
|
ThreatStream Integrator v8.1.1 includes the following improvements:
|
|
ThreatStream Integrator v8.1 includes the following features and enhancements:
|
|
ThreatStream Integrator v8.0 includes the following features and enhancements:
|
|
ThreatStream Integrator 7.3.1 provides a fix for a security issue (CVE-2022-0778). It also fixes a bug present in the previous version. |
|
ThreatStream Integrator 7.3 is the next release for the ThreatStream Integrator product line. This release includes the following features and enhancements:
|
|
ThreatStream Integrator 7.2.4 fixes the following issue (INTS-10443): If the option to push URLs with parameters to the destination was disabled (default), use of the HEAD or SORT operators in the destination filter caused the filter to fail for Splunk, BlueCoat, Cisco ASA, Forcepoint, and Palo Alto Networks destinations. |
|
ThreatStream Integrator 7.2.3 is the next release for the ThreatStream Integrator product line. This release includes the following enhancements:
|
|
Version 7.2.2 was a limited availability release that provided targeted fixes for specific customers. These fixes are rolled up into version 7.2.3. |
|
ThreatStream Integrator 7.2.1 fixes the following issue (INTS-10353): Setting ”type=ip” in the source filter did not work on Integrator 7.2. When "type=ip" was specified, Integrator did not download any of the IP observables. |
|
ThreatStream Integrator 7.2.0 is the next release for the ThreatStream Integrator product line. This release includes the following enhancements:
|
|
ThreatStream Integrator 7.1.1 fixes bugs in the previous version. |
|
ThreatStream Integrator 7.1.0 is the next release for the ThreatStream Integrator product line. This release includes the following enhancements:
|
|
ThreatStream Integrator 7.0.2 is the next release for the ThreatStream Integrator product line. This release includes the following enhancement: SDK Destination: A new parameter has been added to the configuration file that allows you to redact JSON values for specific keys. |
|
|
This patch release fixes bugs (INTS-8004 and INTS-9020) in the previous version. It also fixes a performance issue relating to the Snapshot destination when integrating with Splunk. Release: 6/30/2020 |
|
This patch release fixes a bug (INTS-8851) in the previous version. Release: 1/7/2020 |
|
This patch release fixes a bug present in the previous version. Release: 11/28/2019 |
|
This patch release provides a fix for a security issue. Release: 11/20/2019 |
|
This patch is the next release for the ThreatStream Integrator product line. Release: 11/11/2019 |
Release: 10/31/2019 |
|
This release fixes an issue that caused configured QRadar destinations to display an error message on the dashboard widget. Release: 10/4/2019 |
|
This release provides a fix for an issue (INTS-8424) in which Integrator would not process the destination filter containing pipe (|) correctly when both, a source and destination filter, were specified on the Integrator. Additional functionality has been added to correctly handle pipes within the destination indicator filter field and resolve the issue. Release: 9/4/2019 |
|
This release adds a new feature, Allowed Tags, to MISP destinations. The new feature enables users to forward events matching the specified tags. Release: 8/9/2019 |
|
This release adds a new destination, MISP, to the list of available integrations. The new integration provides a seamless experience with MISP support directly available within Integrator interface. Release: 7/23/2019 |
Release: 7/8/2019 |
|
This patch is the next release for the ThreatStream Integrator product line. Release: 4/30/2019 |
This patch is the next release for the ThreatStream Integrator product line. Release: 1/24/2019 |
|
This release is designed to provide a solution to an issue in which large number of matches on the QRadar App were resulting in the subsequent download of threat intelligence to the app being skipped. To fix the issue, ThreatStream Integrator is now configured to allow the app to match event data from the past 30 days only. For most customers this fix will mitigate the issue. However, if the issue persists in your environment, contact Anomali Customer Support for further tuning of your setup. Release: 10/18/2018 |
|
This release includes support for FireEye HX version 4.x and several bug fixes. ThreatStream does not support Tanium 6.2. Therefore, do not migrate to this release if you are running Tanium 6.2.
Release: 8/22/2018 |
|
This release includes a back-end fix to an issue experienced by customers using a proxied environment and also has refined the indicator ingest process. Despite this, there is no noticeable difference in the user interface. ThreatStream Integrator does not support Tanium 6.2. Therefore, do not migrate to this release if you are running Tanium 6.2.
Release: 7/11/2018 |
|
This release includes reduced indicator download times, additional integration versions supported (Cloudera) and a minor bug fix. ThreatStream Integrator does not support Tanium 6.2. Therefore, do not migrate to this release if you are running Tanium 6.2.
Release: 5/25/2018 |
|
This limited availability release includes a fix for a destination filters issue affecting a small number of customers. Only customers with Linux-based systems will receive this update.
ThreatStream Integrator does not support Tanium 6.2. Therefore, do not migrate to this release if you are running Tanium 6.2.
Release: 4/9/2018 |
ThreatStream Integrator does not support Tanium 6.2. Therefore, do not migrate to this release if you are running Tanium 6.2.
Release: 3/27/2018 |
|
ThreatStream Integrator 6.4 is the next release for the ThreatStream Integrator product line. This release includes support for Windows installation. ThreatStream does not support Tanium 6.2. Therefore, do not migrate to this release if you are running Tanium 6.2.
Release: 2/23/2018 |
|
This release includes support for Cisco ASA firewalls. ThreatStream Integrator does not support Tanium 6.2. Therefore, do not migrate to this release if you are running Tanium 6.2.
Release: 12/7/2017 |
Release: 10/3/2017 |
|
This release includes support for the following integration destinations:
Release: 8/11/2017 |
Release: 7/13/2017 |
Release: 6/12/2017 |
|
This patch provides a fix for an issue in which a proxy server configured to use NTLM authentication was not being used correctly by ThreatStream Integrator. Release: 5/26/2017 |
|
ThreatStream Integrator 6.0 is the first generally available release of ThreatStream Integrator. It includes integration support for Splunk and Custom Destinations. A Custom Destination enables you to access downloaded threat intelligence in CSV, JSON, or SNORT format from an endpoint on ThreatStream Integrator using a utility such as Release: 5/14/2017 |