What's New in ThreatStream (2024)
Use this page to track 2024 ThreatStream updates and reference relevant articles in the online help center.
| Update | Date |
|---|---|
|
FEATURE APP Store: The InsightVM Vulnerability Management enrichment is available for activation in the APP Store. See Enriching Data with InsightVM Vulnerability Management for more information. |
Dec 16, 2024 |
|
ENHANCEMENT MITRE ATT&CK: MITRE ATT&CK techniques and sub-techniques associated with v16.1 are now supported by ThreatStream. See Using MITRE ATT&CK Frameworks in ThreatStream for more information. |
Dec 5, 2024 |
|
ENHANCEMENT Integrations: The ServiceNow UI drop-down menu allowing you to select a ServiceNow user interface is added to the activation process of the ServiceNow integration. See Integrating with ServiceNow SecOps and Integrating with ServiceNow ITSM for more information. |
Nov 18, 2024 |
|
FEATURE APP Store: The Resonanse by spiderSilk premium feed is available for activation in the APP Store. See Managing Premium Feeds for more information. |
Nov 14, 2024 |
|
DOWNLOADS Azure Sentinel Extension: The latest release of the Azure Sentinel extension, v2.0.4, is available from the ThreatStream Downloads page. See Downloads for more information. |
Nov 14, 2024 |
|
DOWNLOADS ThreatStream Integrator: The latest release of ThreatStream Integrator, v8.5.0, is available for download on the ThreatStream Downloads page. See Downloads for more information. |
Nov 6, 2024 |
|
DOWNLOADS ThreatStream OnPrem: The latest release of ThreatStream OnPrem, v5.8 Red Hat 8.10, is available for download on the ThreatStream Downloads page. See Downloads for more information. |
Oct 28, 2024 |
|
FEATURE MITRE ATT&CK: ThreatStream now allows you to create multiple MITRE ATT&CK profiles with their own respective security coverage representation. See Using MITRE ATT&CK Profiles in ThreatStream for more information. |
Oct 14, 2024 |
|
FEATURE APP Store: The Anomali Takedown Service enrichment is now available for activation in the APP Store. See Anomali Takedown Service for more information. |
Sep 24, 2024 |
|
FEATURE Enrichments: The ReversingLab Spectra Analyze enrichment is available for activation in the APP Store. See Enriching Data with ReversingLabs Spectra Analyze for more information. |
Sep 24, 2024 |
|
DOWNLOADS Microsoft Defender for Endpoint Integrator Extension: The latest release of the Microsoft Defender for Endpoint Integrator extension, v1.4.2, is available from the ThreatStream Downloads page. See Downloads for more information. |
Sep 24, 2024 |
|
ANNOUNCEMENT Intelligence Channels: The Anomali Phishing & Fraud Intelligence channel is no longer available for activation for new ThreatStream users. |
Sep 23, 2024 |
|
DOWNLOADS Cofense Vision Extension: The initial release of the Cofense Vision extension, v1.0.0, is available from the ThreatStream Downloads page. See Downloads for more information. |
Sep 18, 2024 |
|
FEATURE APP Store: The Anomali Botnets & C2 Intelligence and IBM X-Force premium feeds are now available for activation in the APP Store. See Managing Premium Feeds for more information. |
Sep 4, 2024 |
|
DOWNLOADS Azure Sentinel Extension: The latest release of the Azure Sentinel extension, v2.0.3, is available from the ThreatStream Downloads page. See Downloads for more information. |
Sep 4, 2024 |
|
FEATURE APP Store: The ReversingLabs Spectra Intelligence enrichment is available for activation in the APP Store. See Enriching Data with ReversingLabs Spectra Intelligence for more information. |
Sep 3, 2024 |
|
ENHANCEMENT Integrations: The domain drop-down menu allowing you to select a ServiceNow domain is added to the activation process of the ServiceNow integration. See Integrating with ServiceNow SecOps and Integrating with ServiceNow ITSM for more information. |
Aug 27, 2024 |
|
ENHANCEMENT MITRE ATT&CK: MITRE ATT&CK techniques and sub-techniques associated with v15.1 are now supported by ThreatStream. See Using MITRE ATT&CK Frameworks in ThreatStream for more information. |
Aug 22, 2024 |
|
FEATURE APP Store: The ThreatBook CTI and Mandiant v4 (non OSINT) premium feeds are now available for activation in the APP Store. See Managing Premium Feeds for more information. |
Aug 15, 2024 |
|
FEATURE Indicator Types: The following indicator types are added to the list of indicator types available in ThreatStream: actor_phone_number, actor_username, ransomware_group, ransomware_victim_domain, ransomware_victim_name, ransomware_victim_url. See Indicator Types in ThreatStream for more information. |
Aug 13, 2024 |
|
DOWNLOADS ThreatStream Integrator: The latest release of ThreatStream Integrator, v8.4.2, is available from the ThreatStream Downloads page. See Downloads for more information. |
Jul 22, 2024 |
|
FEATURE Indicator Types: The following indicator types are added to the list of indicator types available in ThreatStream: gaming_device_id, gaming_device_name, gaming_game_id, gaming_game_name, gaming_player_country, gaming_player_email, gaming_player_id, gaming_player_nickname, gaming_player_phone, social_forum_name, social_media_name, social_messaging_services. See Indicator Types in ThreatStream for more information. |
Jul 18, 2024 |
|
DOWNLOADS VMWare Carbon Black Cloud Extension: The latest release of the VMWare Carbon Black Cloud Extension, v1.3.0, is available from the ThreatStream Downloads page. See Downloads for more information. |
Jul 18, 2024 |
|
ENHANCEMENT Advanced Search: The character limit for advanced search queries is increased to 4,000 characters. See Limits in ThreatStream for more information. |
Jul 16, 2024 |
|
FEATURE Integrations: The bidirectional integration with ServiceNow ITSM is added to ThreatStream. See Integrating with ServiceNow ITSM for more information. |
Jul 15, 2024 |
|
ENHANCEMENT Intelligence Fields: The Target Industry field is added to the Import Assistant. The values of the existing Target Industry field in observables and threat models are now defined by the STIX 2.1 Industry Sector vocabulary. See Updates to the Target Industry Field and Importing Observables for more information. |
Jul 9, 2024 |
|
FEATURE Premium Feeds: The Feedly for Threat Intelligence premium feed is now available for activation in the APP Store. See Managing Premium Feeds for more information. |
Jul 9, 2024 |
|
DOWNLOADS ThreatStream OnPrem: The latest release of ThreatStream OnPrem, v5.8 Ubuntu, is available on the ThreatStream Downloads page. See Downloads for more information. |
Jul 8, 2024 |
|
FEATURE Indicator Types: The suspicious_md5 indicator type is added to the list of supported indicator types. See Indicator Types in ThreatStream for more information. |
Jul 3, 2024 |
|
ENHANCEMENT APP Store: The Limit field allowing you to set a maximum number of entities per a transform request is added to the activation wizard of the Virus Total v3 enrichment. See Enriching Data with VirusTotal v3 for more information. |
Jul 2, 2024 |
|
FEATURE Sandbox: Polyswarm is added to ThreatStream as one of the sandbox services available for malware detonation. See Activating Polyswarm for more information. |
Jun 12, 2024 |
|
ENHANCEMENT My Profile: Read Only users can now be granted a permission to view their API Key on the My Profile tab of the Settings page. See Read Only User Privileges for more information. |
Jun 7, 2024 |
|
FEATURES APP Store: The following Copilot RSS feeds are available for activation in the APP Store: News - Facebook, News - Intezer Blog, Research - Duskrise Blog, Research - Infoblox, Research - Recorded Future, Research - Red Canary Blog, Research - Redsense, Research - SecureWorks, Research - Symantec, Research - The Diffreport Blog. See Managing Anomali Copilot RSS Feeds for more information. |
Jun 4, 2024 |
|
FEATURE Intelligence Fields: The Source Locations field is added to the Import Assistant, observables, and threat models. The Location field in the Import Assistant is renamed to Target Locations. The Locations attribute and the Locations search filter of threat models are renamed to Target Locations. See Importing Observables and Adding New Threat Model Entities for more information. |
May 21, 2024 |
|
FEATURE APP Store: The Tenable.io enrichment is available for activation in the APP Store. See Enriching Data with Tenable Vulnerability Management for more information. |
May 20, 2024 |
|
FEATURE Import: The location field is added to the Import Assistant allowing you to assign target locations when importing observables and creating threat models. See Importing Observables and Adding New Threat Model Entities for more information. |
May 10, 2024 |
|
FEATURE Investigations: The Export MITRE ATT&CK to JSON option is added to the Export menu of investigation details pages. See Exporting MITRE ATT&CK Models to a JSON File for more information. |
Apr 23, 2024 |
|
ANNOUNCEMENT Match: Anomali Security Analytics is the new name for Anomali Match Cloud. |
Apr 22, 2024 |
|
FEATURE STIX 2.1: Location is now supported for STIX 2.1 imports and exports. The Target Region filter used for observables and threat models is replaced by the Locations filter allowing you to filter intelligence by regions, countries, or US States as defined by STIX 2.1. See Importing STIX Data into the Anomali Threat Model for more information. |
Apr 15, 2024 |
|
DOWNLOADS ThreatStream Integrator: The latest feature release of ThreatStream Integrator, v8.4.0, is available from the Downloads page. See Downloads for more information. |
Apr 9, 2024 |
|
ENHANCEMENT Sigma Signatures: You can initiate Sigma rule evaluation in AQL Search from a Sigma signature details page. See Evaluating Sigma Rules for more information. |
Mar 12, 2024 |
|
FEATURE Rules: The Add to New (for each rule match) action allowing you to create investigations for every rule match is added to rules. See Creating Rules for more information. |
Feb 27, 2024 |
|
FEATURES APP Store: The Symantec Malicious Files and Symantec Malicious URLs premium feeds are now available for activation in the APP Store. See Managing Premium Feeds for more information. |
Feb 27, 2024 |
|
FEATURE STIX/TAXII:ThreatStream now supports STIX 2.1 Notes. See Supported Attributes for STIX Entities for more information. |
Feb 20, 2024 |
|
ENHANCEMENT Investigations: When starting an investigation for observables, you can now view other open investigations associated with selected observables. See Creating Investigations for more information. |
Feb 12, 2024 |
|
ENHANCEMENT Investigations: Investigations details pages have a new look and feel. See Understanding User Interface of Investigations for more information. |
Feb 12, 2024 |
|
FEATURE Settings: The Can Audit permission control setting is added to the User Admin tab in ThreatStream settings. See Managing Organization Users for more information. |
Feb 8, 2024 |
|
DOWNLOADS ThreatStream OnPrem: The latest release of ThreatStream OnPrem, v5.7 Ubuntu, is available from the ThreatStream Downloads page. See Downloads for more information. |
Feb 2, 2024 |
|
ENHANCEMENT STIX/TAXII: Resolved the issue related to import of embedded relationships defined by the STIX 2.x/TAXII object_refs attribute for Threat Bulletins. See Supported Attributes for STIX Entities for more information. |
Jan 31, 2024 |
|
ENHANCEMENT MITRE ATT&CK: MITRE ATT&CK techniques and sub-techniques associated with v14.1 are now supported by ThreatStream. See Using MITRE ATT&CK Frameworks in ThreatStream for more information. |
Jan 30, 2024 |
|
ANNOUNCEMENT ThreatStream OnPrem: Due to the changes in ThreatStream Cloud, the Community Threats dashboard accessed via ThreatStream OnPrem v5.6/5.6a will not display any data when the Remote Only option is selected. |
Jan 5, 2024 |
|
DOWNLOADS ThreatStream Splunk App: The latest version of the ThreatStream Splunk App, v6.7.1, is now available from the Downloads page within ThreatStream. See Downloads for more information. |
Jan 4, 2024 |