What's New in ThreatStream (2024)

Use this page to track 2024 ThreatStream updates and reference relevant articles in the online help center.

Update Date

FEATURE

APP Store: The InsightVM Vulnerability Management enrichment is available for activation in the APP Store.

See Enriching Data with InsightVM Vulnerability Management for more information.

Dec 16, 2024

ENHANCEMENT

MITRE ATT&CK: MITRE ATT&CK techniques and sub-techniques associated with v16.1 are now supported by ThreatStream.

See Using MITRE ATT&CK Frameworks in ThreatStream for more information.

Dec 5, 2024

ENHANCEMENT

Integrations: The ServiceNow UI drop-down menu allowing you to select a ServiceNow user interface is added to the activation process of the ServiceNow integration.

See Integrating with ServiceNow SecOps and Integrating with ServiceNow ITSM for more information.

Nov 18, 2024

FEATURE

APP Store: The Resonanse by spiderSilk premium feed is available for activation in the APP Store.

See Managing Premium Feeds for more information.

Nov 14, 2024

DOWNLOADS

Azure Sentinel Extension: The latest release of the Azure Sentinel extension, v2.0.4, is available from the ThreatStream Downloads page.

See Downloads for more information.

Nov 14, 2024

DOWNLOADS

ThreatStream Integrator: The latest release of ThreatStream Integrator, v8.5.0, is available for download on the ThreatStream Downloads page.

See Downloads for more information.

Nov 6, 2024

DOWNLOADS

ThreatStream OnPrem: The latest release of ThreatStream OnPrem, v5.8 Red Hat 8.10, is available for download on the ThreatStream Downloads page.

See Downloads for more information.

Oct 28, 2024

FEATURE

MITRE ATT&CK: ThreatStream now allows you to create multiple MITRE ATT&CK profiles with their own respective security coverage representation.

See Using MITRE ATT&CK Profiles in ThreatStream for more information.

Oct 14, 2024

FEATURE

APP Store: The Anomali Takedown Service enrichment is now available for activation in the APP Store.

See Anomali Takedown Service for more information.

Sep 24, 2024

FEATURE

Enrichments: The ReversingLab Spectra Analyze enrichment is available for activation in the APP Store.

See Enriching Data with ReversingLabs Spectra Analyze for more information.

Sep 24, 2024

DOWNLOADS

Microsoft Defender for Endpoint Integrator Extension: The latest release of the Microsoft Defender for Endpoint Integrator extension, v1.4.2, is available from the ThreatStream Downloads page.

See Downloads for more information.

Sep 24, 2024

ANNOUNCEMENT

Intelligence Channels: The Anomali Phishing & Fraud Intelligence channel is no longer available for activation for new ThreatStream users.

Sep 23, 2024

DOWNLOADS

Cofense Vision Extension: The initial release of the Cofense Vision extension, v1.0.0, is available from the ThreatStream Downloads page.

See Downloads for more information.

Sep 18, 2024

FEATURE

APP Store: The Anomali Botnets & C2 Intelligence and IBM X-Force premium feeds are now available for activation in the APP Store.

See Managing Premium Feeds for more information.

Sep 4, 2024

DOWNLOADS

Azure Sentinel Extension: The latest release of the Azure Sentinel extension, v2.0.3, is available from the ThreatStream Downloads page.

See Downloads for more information.

Sep 4, 2024

FEATURE

APP Store: The ReversingLabs Spectra Intelligence enrichment is available for activation in the APP Store.

See Enriching Data with ReversingLabs Spectra Intelligence for more information.

Sep 3, 2024

ENHANCEMENT

Integrations: The domain drop-down menu allowing you to select a ServiceNow domain is added to the activation process of the ServiceNow integration.

See Integrating with ServiceNow SecOps and Integrating with ServiceNow ITSM for more information.

Aug 27, 2024

ENHANCEMENT

MITRE ATT&CK: MITRE ATT&CK techniques and sub-techniques associated with v15.1 are now supported by ThreatStream.

See Using MITRE ATT&CK Frameworks in ThreatStream for more information.

Aug 22, 2024

FEATURE

APP Store: The ThreatBook CTI and Mandiant v4 (non OSINT) premium feeds are now available for activation in the APP Store.

See Managing Premium Feeds for more information.

Aug 15, 2024

FEATURE

Indicator Types: The following indicator types are added to the list of indicator types available in ThreatStream: actor_phone_number, actor_username, ransomware_group, ransomware_victim_domain, ransomware_victim_name, ransomware_victim_url.

See Indicator Types in ThreatStream for more information.

Aug 13, 2024

DOWNLOADS

ThreatStream Integrator: The latest release of ThreatStream Integrator, v8.4.2, is available from the ThreatStream Downloads page.

See Downloads for more information.

Jul 22, 2024

FEATURE

Indicator Types: The following indicator types are added to the list of indicator types available in ThreatStream: gaming_device_id, gaming_device_name, gaming_game_id, gaming_game_name, gaming_player_country, gaming_player_email, gaming_player_id, gaming_player_nickname, gaming_player_phone, social_forum_name, social_media_name, social_messaging_services.

See Indicator Types in ThreatStream for more information.

Jul 18, 2024

DOWNLOADS

VMWare Carbon Black Cloud Extension: The latest release of the VMWare Carbon Black Cloud Extension, v1.3.0, is available from the ThreatStream Downloads page.

See Downloads for more information.

Jul 18, 2024

ENHANCEMENT

Advanced Search: The character limit for advanced search queries is increased to 4,000 characters.

See Limits in ThreatStream for more information.

Jul 16, 2024

FEATURE

Integrations: The bidirectional integration with ServiceNow ITSM is added to ThreatStream.

See Integrating with ServiceNow ITSM for more information.

Jul 15, 2024

ENHANCEMENT

Intelligence Fields: The Target Industry field is added to the Import Assistant. The values of the existing Target Industry field in observables and threat models are now defined by the STIX 2.1 Industry Sector vocabulary.

See Updates to the Target Industry Field and Importing Observables for more information.

Jul 9, 2024

FEATURE

Premium Feeds: The Feedly for Threat Intelligence premium feed is now available for activation in the APP Store.

See Managing Premium Feeds for more information.

Jul 9, 2024

DOWNLOADS

ThreatStream OnPrem: The latest release of ThreatStream OnPrem, v5.8 Ubuntu, is available on the ThreatStream Downloads page.

See Downloads for more information.

Jul 8, 2024

FEATURE

Indicator Types: The suspicious_md5 indicator type is added to the list of supported indicator types.

See Indicator Types in ThreatStream for more information.

Jul 3, 2024

ENHANCEMENT

APP Store: The Limit field allowing you to set a maximum number of entities per a transform request is added to the activation wizard of the Virus Total v3 enrichment.

See Enriching Data with VirusTotal v3 for more information.

Jul 2, 2024

FEATURE

Sandbox: Polyswarm is added to ThreatStream as one of the sandbox services available for malware detonation.

See Activating Polyswarm for more information.

Jun 12, 2024

ENHANCEMENT

My Profile: Read Only users can now be granted a permission to view their API Key on the My Profile tab of the Settings page.

See Read Only User Privileges for more information.

Jun 7, 2024

FEATURES

APP Store: The following Copilot RSS feeds are available for activation in the APP Store: News - Facebook, News - Intezer Blog, Research - Duskrise Blog, Research - Infoblox, Research - Recorded Future, Research - Red Canary Blog, Research - Redsense, Research - SecureWorks, Research - Symantec, Research - The Diffreport Blog.

See Managing Anomali Copilot RSS Feeds for more information.

Jun 4, 2024

FEATURE

Intelligence Fields: The Source Locations field is added to the Import Assistant, observables, and threat models. The Location field in the Import Assistant is renamed to Target Locations. The Locations attribute and the Locations search filter of threat models are renamed to Target Locations.

See Importing Observables and Adding New Threat Model Entities for more information.

May 21, 2024

FEATURE

APP Store: The Tenable.io enrichment is available for activation in the APP Store.

See Enriching Data with Tenable Vulnerability Management for more information.

May 20, 2024

FEATURE

Import: The location field is added to the Import Assistant allowing you to assign target locations when importing observables and creating threat models.

See Importing Observables and Adding New Threat Model Entities for more information.

May 10, 2024

FEATURE

Investigations: The Export MITRE ATT&CK to JSON option is added to the Export menu of investigation details pages.

See Exporting MITRE ATT&CK Models to a JSON File for more information.

Apr 23, 2024

ANNOUNCEMENT

Match: Anomali Security Analytics is the new name for Anomali Match Cloud.

Apr 22, 2024

FEATURE

STIX 2.1: Location is now supported for STIX 2.1 imports and exports. The Target Region filter used for observables and threat models is replaced by the Locations filter allowing you to filter intelligence by regions, countries, or US States as defined by STIX 2.1.

See Importing STIX Data into the Anomali Threat Model for more information.

Apr 15, 2024

DOWNLOADS

ThreatStream Integrator: The latest feature release of ThreatStream Integrator, v8.4.0, is available from the Downloads page.

See Downloads for more information.

Apr 9, 2024

ENHANCEMENT

Sigma Signatures: You can initiate Sigma rule evaluation in AQL Search from a Sigma signature details page.

See Evaluating Sigma Rules for more information.

Mar 12, 2024

FEATURE

Rules: The Add to New (for each rule match) action allowing you to create investigations for every rule match is added to rules.

See Creating Rules for more information.

Feb 27, 2024

FEATURES

APP Store: The Symantec Malicious Files and Symantec Malicious URLs premium feeds are now available for activation in the APP Store.

See Managing Premium Feeds for more information.

Feb 27, 2024

FEATURE

STIX/TAXII:ThreatStream now supports STIX 2.1 Notes.

See Supported Attributes for STIX Entities for more information.

Feb 20, 2024

ENHANCEMENT

Investigations: When starting an investigation for observables, you can now view other open investigations associated with selected observables.

See Creating Investigations for more information.

Feb 12, 2024

ENHANCEMENT

Investigations: Investigations details pages have a new look and feel.

See Understanding User Interface of Investigations for more information.

Feb 12, 2024

FEATURE

Settings: The Can Audit permission control setting is added to the User Admin tab in ThreatStream settings.

See Managing Organization Users for more information.

Feb 8, 2024

DOWNLOADS

ThreatStream OnPrem: The latest release of ThreatStream OnPrem, v5.7 Ubuntu, is available from the ThreatStream Downloads page.

See Downloads for more information.

Feb 2, 2024

ENHANCEMENT

STIX/TAXII: Resolved the issue related to import of embedded relationships defined by the STIX 2.x/TAXII object_refs attribute for Threat Bulletins.

See Supported Attributes for STIX Entities for more information.

Jan 31, 2024

ENHANCEMENT

MITRE ATT&CK: MITRE ATT&CK techniques and sub-techniques associated with v14.1 are now supported by ThreatStream.

See Using MITRE ATT&CK Frameworks in ThreatStream for more information.

Jan 30, 2024

ANNOUNCEMENT

ThreatStream OnPrem: Due to the changes in ThreatStream Cloud, the Community Threats dashboard accessed via ThreatStream OnPrem v5.6/5.6a will not display any data when the Remote Only option is selected.

Jan 5, 2024

DOWNLOADS

ThreatStream Splunk App: The latest version of the ThreatStream Splunk App, v6.7.1, is now available from the Downloads page within ThreatStream.

See Downloads for more information.

Jan 4, 2024