What's New in ThreatStream (2019)
Use this page to track 2019 ThreatStream updates and reference relevant articles in the online help center.
| Update | Date |
|---|---|
|
ENHANCEMENT Threat Model: For Threat Model entities that originate from feeds, the feed name automatically populates the Source field. |
12/24/2019 |
|
ENHANCEMENT Import: Included and Excluded observables contained in import jobs can be filtered by Type of observable (Domain, Email, Hash, IP, IPv6, String, and URL) |
12/20/2019 |
|
FEATURE Import: Delete import jobs owned by your organization. See Deleting Import Jobs for more information. |
12/20/2019 |
|
ENHANCEMENT Enrichments: Updated the Reversing Labs enrichment. See Enriching Data with ReversingLabs Spectra Intelligence for more information. |
12/19/2019 |
|
ENHANCEMENT Tags: You can delete any public tag added to observables or Threat Model entities owned by your organization, regardless of the organization that added the tag. See Bulk Tag Management of Observables for more information. |
12/12/2019 |
|
ENHANCEMENT Investigations: Column selections on the Investigations list view are maintained after you navigate away from the page. |
12/10/2019 |
|
ENHANCEMENT Tags: All entity types in ThreatStream are limited to 200 tags per organization. Tags added by other organizations do not count towards this limit. |
12/9/2019 |
|
ENHANCEMENT Import: Moving observables from the Excluded tab to the Included tab on import jobs does not result in the observable becoming active immediately. Observables moved from the excluded tab become active when the import job is approved. See Manually Adding Excluded Observables for more information. |
12/5/2019 |
|
FEATURE Whitelist: Add entries to your Whitelist from a CSV file. See Adding Exclude List Entries from a CSV File for more information. |
12/5/2019 |
|
ENHANCEMENT Import: All associated investigations are displayed from the import job screen when import jobs are associated with multiple investigations. |
12/4/2019 |
|
FEATURE Import: An Auto-Approve option enables users with Approve Import privileges to automatically approve the import jobs they submit. See Importing Observablesfor more information. |
12/3/2019 |
|
ENHANCEMENT Import: Add additional observables to import jobs while the import job is in Ready to Review status. See Approving Import Jobs for more information. |
11/25/2019 |
|
ENHANCEMENT Import: Edit the values of observables listed on the Included and Excluded tabs of import jobs while the import job is in Ready to Review status. See Editing Observable Values Before Approval for more information. |
11/25/2019 |
|
ENHANCEMENT Threat Model: Added a page field to Threat Model entity details pages for entities created through PDF imports, thus improving the browsing experience for PDFs with high page counts. |
11/8/2019 |
|
ENHANCEMENT Search: Added an Expiration Date column to the observables search screen. The column is not shown by default and must be selected. |
11/7/2019 |
|
ENHANCEMENT Investigations: Added the ability to edit text fonts in Investigation descriptions. |
11/7/2019 |
|
ENHANCEMENT Import: URL Observables that contain special characters can now be imported. |
11/1/2019 |
|
ENHANCEMENT Rules: Rules can be configured to exclude observables that exist in your organization import whitelist. Additionally, notifications can be suppressed for observables imported by your organization. |
10/17/2019 |
|
ENHANCEMENT Search: Added the ability to filter advanced observable searches by Import Source ( See Intelligence Fields in ThreatStream for more information. |
10/16/2019 |
|
FEATURE Sandbox: Added the ability to specify passwords for protected files during sandbox submission. See Analyzing Malware with the ThreatStream Sandbox for more information. |
10/15/2019 |
|
ENHANCEMENT Threat Model: Customize the elements included in threat model entity PDF exports. See Exporting Threat Model Entities in STIX Format for more information. |
10/15/2019 |
|
FEATURE Enrichments: Added the Anomali GeoIP, DNSTwister, Pastebin Dump Collection, and URLScan.io enrichments. |
10/14/2019 |
|
ENHANCEMENT Enrichments: Updated the Reversing Labs and RiskIQ enrichments. |
10/14/2019 |
|
ENHANCEMENT Import: Users without Approve Import privileges can edit the parameters of import sessions they submit before they are approved. See Managing Import Jobs for more information. |
10/2/2019 |
|
ENHANCEMENT Sandbox: The Sandbox screen has been updated with a new user interface. See Viewing Sandbox Reports for more information. |
10/2/2019 |
|
ENHANCEMENT Explore: The Explore interface has been updated with an Auto-Arrange function, enabling users to select whether existing nodes remain static when additional nodes are added. See Analyzing Adversary Infrastructure with Explore for more information. |
10/2/2019 |
|
ENHANCEMENT APP Store: Updated the APP Store with a new user interface. See Subscribing to Anomali Feeds, Enrichments, and Intelligence Channels for more information. |
9/26/2019 |
|
FEATURE Organization Settings: Added Match Integration URL to the Organization tab within ThreatStream settings, thus enabling you to validate the Match systems which can make connections to your organization on ThreatStream. See Viewing and Editing Organization Settings for more information. |
9/24/2019 |
|
FEATURE Threat Model: Added the Malware threat model entity. See Viewing Malware Details for more information. |
9/4/2019 |
|
ENHANCEMENT Mailboxes: Added an intuitive Mailbox creation wizard. Phishing mailboxes can be configured to create both investigations and import sessions. |
9/4/2019 |
|
FEATURE Notifications: Added the ability to view a complete list of the notifications sent to you by ThreatStream on the Notifications List View. See Viewing Notifications on the Notifications List View for more information. |
8/30/2019 |
|
FEATURE Organization Settings: Added the ability for Org Admins whose organizations use ThreatStream OnPrem to restrict access to the ThreatStream Cloud user interface for non-admin users. See "Restrict ThreatStream Cloud Access" on Viewing and Editing Organization Settings for more information. |
8/30/2019 |
|
ENHANCEMENT Rules: Rules can be configured to search for keyword matches in Signatures. See Rules for more information. |
8/22/2019 |
|
FEATURE User Administration: Org Admins can export user information in CSV format. See Managing Organization Users for more information. |
8/21/2019 |
|
ENHANCEMENT Import Whitelist: Added the ability to associate contextual notes to import whitelist entries. See Updating Organization Exclude Listfor more information. |
8/16/2019 |
|
FEATURE Dashboard: Added the Investigation Task List dashboard widget, enabling you to view all investigation tasks assigned to you from the Overview dashboard. See A Tour of the ThreatStream Overview Dashboard for more information. |
8/15/2019 |
|
FEATURE Observables: Added an audit log to observable details pages, enabling you to track changes to observable confidence, expiration date, indicator type, tags, severity, status, and TLP. See Observables for more information. |
8/13/2019 |
|
FEATURE Sightings: Added the ability to manually manage Sightings data. See Viewing Matches and My Attacks for more information. |
8/12/2019 |
|
FEATURE Enrichments: Added the Shodan enrichment. See Enriching Data with Shodan for more information. |
8/12/2019 |
|
ENHANCEMENT Import: Added the ability to edit the expiration data of all observables included in an import session during review. See Approving Import Jobs for more information. |
8/8/2019 |
|
ENHANCEMENT Import: When an excluded observable is moved to the included table in an import session, its Reason for Exclusion is maintained in the Notes column of the Included table. |
8/8/2019 |
|
ENHANCEMENT Import: Added the ability to edit the expiration date of individual observables while reviewing import sessions. See Approving Import Jobs for more information. |
8/7/2019 |
|
ENHANCEMENT Rules: Added the ability to configure rules based on the exclusion specific indicator types. See Creating Rules for more information. |
8/7/2019 |
|
FEATURE Enrichments: Added the Farsight DNSDB enrichment. Updated the AlienVault ThreatCrowd enrichment. |
7/31/2019 |
|
FEATURE User Administration: Added the ability to create Read Only users on ThreatStream. See Read Only User Privileges for more information. |
7/29/2019 |
|
FEATURE Enrichments: Added the Web of Trust enrichment. Updated the Hybrid Analysis enrichment. See Enriching Data with Web Of Trust for more information. |
7/29/2019 |
|
ENHANCEMENT Enrichments: Updated the Have I Been Pwned? enrichment. See Enriching Data with Have I Been Pwned? for more information. |
7/22/2019 |
|
ENHANCEMENT Organization Settings: Threat Model Logo files are validated when uploaded. |
7/19/2019 |
|
ENHANCEMENT Observables: Updated the Enrichments section on observable details pages to include an Activate Enrichments... tab, which lists unactivated enrichments available to you on ThreatStream. See Observables for more information. |
7/17/2019 |
|
ENHANCEMENT Explore: Added an Activate Enrichments... menu to the list of actions on the Explore pivoting tool, which lists unactivated enrichments available to you on ThreatStream. See Analyzing Adversary Infrastructure with Explorefor more information. |
7/17/2019 |
|
ENHANCEMENT Observables: Added urlscan.io to the list of Analysis Links on observable details pages for Domain, IP address, and URL observables. See Observables for more information. |
7/17/2019 |
|
ENHANCEMENT Integrations: Updated the Integrations screen within ThreatStream settings to include a filter which improves the experience of browsing available integrations. Additionally, the activation process for enrichments available from the screen is more intuitive and provides links to vendor registration resources. |
7/16/2019 |
|
FEATURE Integrations: Added the IBM Resilient integration. See Integrating with IBM Resilient for more information. |
7/15/2019 |
|
FEATURE User Activity: Added the ability to export user activity in CSV format. See User Activity Audit for more information. |
7/15/2019 |
|
ENHANCEMENT Threat Model: Added the ability to filter threat model search results by Signature type. See Accessing Threat Models for more information. |
7/10/2019 |
|
ENHANCEMENT Enrichments: Updated the Silobreaker enrichment. See Enriching Data with Silobreaker for more information. |
7/9/2019 |
|
ENHANCEMENT Observables: Updated information for bulk Observable update. See Editing Observable Details for more information. |
7/5/2019 |
|
FEATURE Organization Settings: Added the ability to configure the number of days before expiration at which uses receive notification to reset their passwords. See Viewing and Editing Organization Settings for more information. |
6/28/2019 |
|
ENHANCEMENT Browser Plugin: The Anomali ThreatStream Plugin can search Threat Model entities in addition to observables. Additionally, you can drill down to observable details pages directly from the plugin. |
6/28/2019 |
|
ENHANCEMENT Import: File hashes are checked against an Anomali generated whitelist of known benign observables. |
6/26/2019 |
|
ENHANCEMENT Enrichments: Updated the VirusTotal and Risk IQ enrichments. See Enriching Data with VirusTotal v2 and Enriching Data with Risk IQ for more information. |
6/20/2019 |
|
FEATURE Enrichments: Added the AbuseIPDB enrichment. See Enriching Data with AbuseIPDB for more information. |
6/18/2019 |
|
ENHANCEMENT Observables: Added the ability to remove observable tags in bulk from the Observables search page. See Bulk Tag Management of Observables for more information. |
6/14/2019 |
|
FEATURE Password Management: Users receive in-app password expiration notifications. Org Admins can specify a number of days before expiration at which users are notified. See "Notify users before password expiration" in Viewing and Editing Organization Settings for more information. |
6/14/2019 |
|
FEATURE Enrichments: Added the Anomali Open Ports enrichment. See Enriching Data with Anomali Open Ports for more information. |
6/4/2019 |
|
FEATURE Threat Model: Added the ability to import existing content in the form of threat model entities. You can paste in rich text or upload PDF or TXT files which will serve as the basis for a new threat model entity. See Adding New Threat Model Entities for more information. |
5/28/2019 |
|
ENHANCEMENT Organization Settings: Increased the number of CIDRs to which you can grant exclusive access to your organization on ThreatStream to 1000. See Viewing and Editing Organization Settings for more information. |
5/28/2019 |
|
ENHANCEMENT Rules: Rules can be configured to search for keyword matches in Vulnerabilities. See Rules for more information. |
5/21/2019 |
|
ENHANCEMENT Import Whitelist: Import Whitelist entries are normalized so that all alphanumeric characters are made lower-case when entries are created, thus preventing the creation of duplicate entries. See Updating Organization Exclude List for more information. |
5/14/2019 |
|
ENHANCEMENT Threat Model: The ability to export observables associated with threat model entities has been extended to Actors, Campaigns, Incidents, Signatures, TTPs, and Vulnerabilities. |
5/8/2019 |
|
FEATURE Investigations: The new Investigations user interface is generally available ThreatStream. See Investigating Threats in ThreatStream for more information. |
5/7/2019 |
|
ENHANCEMENT Import: Users with Approve Import privileges can approve and reject import jobs in bulk from the Import list view screen. See Approving Import Jobs for more information. |
5/2/2019 |
|
FEATURE Enrichments: Added the Reversing Labs and DomainTools Iris enrichments. See Enriching Data with ReversingLabs Spectra Intelligence and Integrating with DomainTools for more information. |
5/1/2019 |
|
ENHANCEMENT Search: Added the ability to filter observable search results by observable value type. See Filtering Search Results for more information. |
4/30/2019 |
|
ENHANCEMENT Investigations: Added the ability to delete investigation tasks. See Understanding User Interface of Investigations for more information. |
4/30/2019 |
|
FEATURE Enrichments: Added the Have I Been Pwned? enrichment. |
4/26/2019 |
|
ENHANCEMENT Search: Users with Org Admin privileges can edit or delete any search filter that belongs to their organization. Non-admins can only edit or delete search filters that they themselves created. |
4/18/2019 |
|
ENHANCEMENT Observables: Added the ability to edit observables in bulk. See Editing Observable Details for more information. |
4/5/2019 |
|
FEATURE Organization Settings: Added the ability to restrict access to your organization on ThreatStream Cloud to IP addresses that fall within specified CIDRs. See Viewing and Editing Organization Settings for more information. |
3/26/2019 |
|
ENHANCEMENT Observables: Added the ability to assign a TLP color to observables during import and from observable details pages. See Importing Observablesand Editing Observable Details for more information. |
3/22/2019 |
|
FEATURE Enrichments: Added the Anomali Whois History enrichment. See Enriching Data with Anomali Whois History for more information. |
3/19/2019 |
|
ENHANCEMENT Enrichments: Consolidated the OpenDNS and OpenDNS Investigate integrations into a single enrichment. See Enriching Data with Cisco Umbrella Investigate for more information. |
3/19/2019 |
|
ENHANCEMENT Enrichments: Consolidated multiple VirusTotal integrations into a single enrichment. See Enriching Data with VirusTotal v2 for more information. |
3/19/2019 |
|
ENHANCEMENT Import: The threat model associations user interface on the Import Assistant has been updated. See Importing Observablesfor more information. |
3/14/2019 |
|
ENHANCEMENT Investigations: Investigations has been updated with a new user interface. |
3/13/2019 |
|
ENHANCEMENT Sandbox: Added the ability to edit the visibility of sandbox reports. |
2/15/2019 |
|
ENHANCEMENT Explore: Explore has been updated with a metadata search and the ability to manually link nodes. |
2/14/2019 |
|
FEATURE User Activity: Added ability to generate reports on user activity. See Generating User Activity Reports for more information. |
2/8/2019 |
|
ENHANCEMENT Sandbox: Org Admins can delete sandbox reports that are owned by their organizations. See Deleting a Sandbox Report for more information. |
2/7/2019 |
|
ENHANCEMENT Sandbox: Add the ability to set a default sandbox detonation platform. See Submitting Malware for Detonationfor more information. |
2/4/2019 |
|
FEATURE Enrichments: Added the Silobreaker enrichment. See Enriching Data with Silobreaker for more information. |
1/29/2019 |
|
ENHANCEMENT Observables: Observables can be deleted from observable details pages. See Deleting Observables for more information. |
1/17/2019 |
|
FEATURE Enrichments: Added AlienVault ThreatCrowd, Hybrid Analysis, OpenDNS, and VirusTotal enrichments. See Integrating with Third-Party Services for more information. |
1/9/2019 |