What's New in ThreatStream (2018)

Use this page to track 2018 ThreatStream updates and reference relevant articles in the online help center.

Update Date

ENHANCEMENT

Explore: Added the ability to limit the maximum nodes returned for a single search in Explore.

See Analyzing Adversary Infrastructure with Explore for more information.

12/19/2018

ENHANCEMENT

Mailboxes: Added the ability to specify a Proxy User for threat intelligence mailboxes.

See Mailboxes for Receiving Observables for more information.

11/15/2018

ENHANCEMENT

Privacy: Added ability to anonymize user and organization information for Actors, Campaigns, Incidents, Observables, Signatures, Threat Bulletins, TTPs, and Vulnerabilities that belong to your organization.

11/12/2018

ENHANCEMENT

Observables: Added the "phish_md5" indicator type.

11/1/2018

ENHANCEMENT

Explore: Explore has been updated with a new user interface and the ability to run Passive SSL searches.

See Analyzing Adversary Infrastructure with Explore for more information.

10/1/2108

ENHANCEMENT

Observables: Tags added to intelligence due to rule matches can be made private to your organization.

See Creating Rules for more information.

9/4/2018

ENHANCEMENT

Threat Model: Private tags can be added to all threat model entities.

8/28/2018

ENHANCEMENT

Dashboard: The Latest Activity dashboard widget displays information on submissions to import and phishing mailboxes.

See A Tour of the ThreatStream Overview Dashboard for more information.

8/22/2018

ENHANCEMENT

User Administration: Users are immediately logged out upon changing their passwords from the My Profile tab within ThreatStream settings.

8/16/2018

ENHANCEMENT

Sandbox: Malware can be submitted to the sandbox in a user-friendly pop-up modal on the Sandbox user interface.

See Submitting Malware for Detonationfor information on submitting Malware.

8/13/2018

ENHANCEMENT

Sandbox: Individual Joe Sandbox subscriptions are activated using API keys exclusively.

See Activating Joe Sandbox for more information.

8/13/2018

ENHANCEMENT

Import: Tags with the My Organization visibility setting can be added to observables when importing via CSV.

See Guidelines for Structured Data for more information.

8/9/2018

ENHANCEMENT

Enrichments: OpenDNS Umbrella integrations send threat intelligence to OpenDNS based on a custom search filter specified by users.

See Integrating with OpenDNS Umbrella for more information.

8/9/2018

ENHANCEMENT

User Administration: Added ability to set user permissions upon user creation.

See Managing Organization Users for more information.

8/3/2018

ENHANCEMENT

Observables: URLs parsed from phishing emails can be submitted for detonation to the sandbox.

See Mailboxes for Receiving Observables for more information.

6/29/2018

FEATURE

Organization Settings: Org admins can configure a Message of the Day that is displayed in a banner across the top of the screen to all organization users.

See Viewing and Editing Organization Settings for more information.

6/25/2018

FEATURE

Organization Settings: Org admins can configure an account lockout policy for consecutive failed login attempts.

See Password Lockout for more information.

6/20/2018

ENHANCEMENT

Threat Model: Threat model search enables searching of complete phrases.

See Accessing Threat Models for more information.

6/14/2018

ENHANCEMENT

Threat Model: Threat model search queries threat model entity descriptions.

See Accessing Threat Models for more information.

6/4/2018

ENHANCEMENT

Sandbox: Added ability for Org Admins to configure the amount of time that the sandbox records runtime activity of detonated files after execution.

See Analysis Time for more information.

6/1/2018

ENHANCEMENT

Search: Advanced search suggests valid operators and fields as you type.

See Constructing Advanced Observable Search Filters for more information.

5/24/2018

ENHANCEMENT

Investigations: Added ability to edit investigation titles.

See Understanding User Interface of Investigations for more information.

5/14/2018

FEATURE

Integrations: Added Zscaler integration.

See Integrating with Zscaler for more information.

5/8/2018

FEATURE

Organization Settings: Added ability to customize new user emails.

See Customizing Emails for New Users for more information.

5/4/2018