What's New in ThreatStream (2020)

Use this page to track 2020 ThreatStream updates and reference relevant articles in the online help center.

Update Date

FEATURE

Themed Custom Dashboards: Utilize a Sunburst Backdoor rapid response dashboard developed by the Anomali Threat Research team to stay current on the latest intelligence relating to the Sunburst Backdoor supply chain attacks.

See for more information.

12/21/2020

DOWNLOADS

Anomali Lens: The latest version of the Anomali Lens plugin, v4.6.0, is available from the ThreatStream Downloads page.

See Downloads for more information.

12/21/2020

BETA RELEASE

MITRE ATT&CK: Configure a representation of your organization security controls using the MITRE ATT&CK Framework. After configuring your security controls, you can overlay them on MITRE ATT&CK models within investigations to get a snapshot of your coverage for a particular threat.

See Configuring Security Coverage of MITRE ATT&CK Profiles for more information.

12/17/2020

FEATURE

Private Investigations: Create investigations that are visible only to you.

See Visibility for more information.

12/17/2020

FEATURE

Investigation Collaboration: To enable collaboration within investigations, ThreatStream locks investigations when an edits are made. Other users with access to the investigation are prevented from making edits until the editor saves the investigation or leaves the page.

See Collaborating on Investigations for more information.

12/17/2020

FEATURE

Explore in Investigations: The Explore pivoting tool on the investigations user interface has been enhanced with a new Selection Details panel. The panel enables you to search nodes on the chart and view more details about selected nodes without drilling down to entity details pages.

See Collaborating on Investigations for more information.

12/17/2020

FEATURE

Themed Custom Dashboards: Add custom dashboards created by the Anomali Threat Research team to your home screen on ThreatStream.

See for more information.

12/17/2020

ENHANCEMENT

Anomali Lens in ThreatStream: The on-board version of Anomali Lens has been updated. The flame icon, which indicates a term highlighted by Lens is trending, is now displayed next to highlighted entities on the page.

See Context at the point of use for more information.

12/17/2020

DOWNLOADS

QRadar Content Package: The latest version of the Anomali QRadar Content Package, v1.1.1, is available from the ThreatStream Downloads page.

See Downloads for more information.

12/17/2020

ENHANCEMENT

Risk IQ Enrichment: The Risk IQ enrichment has been updated.

See Enriching Data with Risk IQ for more information.

12/15/2020

ENHANCEMENT

Overview Dashboard: The Indicators by Type dashboard widget has been enhanced with Deselect All and Select All options, granting you greater control over the indicator types displayed on the chart.

See Indicators by Type for more information.

12/15/2020

DOWNLOADS

ThreatStream Integrator: The Latest Feature Release of ThreatStream Integrator, v7.1.1, is available from the ThreatStream Downloads page.

See Downloads for more information.

12/11/2020

DOWNLOADS

ThreatStream Splunk App: The latest version of the ThreatStream Splunk App, v6.5.2, is available from the ThreatStream Downloads page.

See Downloads for more information.

12/1/2020

DOWNLOADS

Azure Sentinel Integrator Extension: The latest release of the Azure Sentinel Integrator extension, v1.1, is available from the ThreatStream Downloads page.

See Downloads for more information.

12/1/2020

DOWNLOADS

ThreatStream OnPrem: The latest release of ThreatStream OnPrem, v5.1, is available from the ThreatStream Downloads page.

See Downloads for more information.

11/20/2020

DOWNLOADS

QRadar App: The latest release of the QRadar App, v2.1.0, is available from the ThreatStream Downloads page.

See Downloads for more information.

11/18/2020

DOWNLOADS

IBM Resilient App: The Latest Feature Release of the IBM Resilient App, v2.3.0, is available from the ThreatStream Downloads page.

See Downloads for more information.

11/10/2020

DOWNLOADS

Anomali Lens: The latest version of the Anomali Lens plugin, v4.5.0, is available from the ThreatStream Downloads page.

See Downloads for more information.

11/9/2020

ENHANCEMENT

Anomali Lens in ThreatStream: The on-board version of Anomali Lens has been updated with the ability to jump to highlighted entities by clicking an entity name on the Anomali Lens user interface.

See Scanning Pages with Anomali Lens for more information.

11/6/2020

DOWNLOADS

ThreatStream Integrator: The Latest Feature Release of ThreatStream Integrator, v7.1.0, is available from the ThreatStream Downloads page.

See Downloads for more information.

10/5/2020

DOWNLOADS

Anomali Lens: The latest version of the Anomali Lens plugin, v4.4.0, is available from the ThreatStream Downloads page.

See Downloads for more information.

9/30/2020

ENHANCEMENT

APP Store: The APP Store has been enhanced with an alternate list view user interface. You can toggle between the traditional tile view and the new list view. Additionally, you can leverage a search function to quickly locate streams by name.

See Subscribing to Anomali Feeds, Enrichments, and Intelligence Channels for more information.

9/30/2020

ENHANCEMENT

Investigations: The maximum file size for investigation attachments has been increased to 20MB.

See Understanding User Interface of Investigations for more information.

9/30/2020

FEATURE

Anomali Lens: Org Admins can manage a central Never Scan list for users in their organization that use the Anomali Lens plugin.

See Managing Organization Never Scan Lists for Anomali Copilot for more information.

9/30/2020

FEATURE

Threat Model: Set a default PDF Report template. Default templates are displayed at the top of the template list when you create PDF Reports. Default template is a user-level setting and does not impact other users in your organization.

See Managing Report Templates for more information.

9/29/2020

ENHANCEMENT

Threat Model: The PDF Report creation window has been updated with a new user interface.

See Exporting Threat Model Entities in PDF Format for more information.

9/29/2020

FEATURE

Threat Model: Leverage a Default Anomali Template for PDF Report creation.

See Exporting Threat Model Entities in PDF Format for more information.

9/29/2020

ENHANCEMENT

Threat Model: When you share Threat Model entities through email, you can optionally attach a PDF export of the Threat Model entities to the email. PDFs are generated based on a template of your choosing.

See Sharing Threat Model Entities via Email for more information.

9/29/2020

ENHANCEMENT

Audit: Org Admins can audit PDF Report creation activity from the Audit screen within ThreatStream settings.

See User Activity Audit for more information.

9/29/2020

DOWNLOADS

Anomali Match Lens+ Edition: The latest version of Anomali Match Lens+ Edition, v4.3, is available from the ThreatStream Downloads page.

See Downloads for more information.

9/29/2020

ENHANCEMENT

STIX Export: STIX 1.x Indicator exports now include tags associated with observables in ThreatStream. Tags are exported as Cybox:Keywords in the resulting file. Exports can include up to 250 tags.

See Export for more information.

9/28/2020

ENHANCEMENT

Investigations: The Explore pivoting chart has been enhanced. A "Search All" pivot has been added to each enrichment pivot menu. When you click this option, all pivots for the enrichment are executed on the selected nodes.

See Using Explore In Investigations for more information.

9/28/2020

FEATURE

Enrichments: Added the Spur IP Context enrichment.

See Enriching Data with Spur IP Context for more information.

9/28/2020

FEATURE

Indicator Types: Added the fraud_domain, fraud_email, fraud_ip, fraud_md5, and fraud_url indicator types.

See Indicator Types in ThreatStream for more information.

9/28/2020

ENHANCEMENT

Investigations: The Explore pivoting chart has been enhanced. When you zoom in on a section of the chart and add a new node, the current zoom setting persists after the node is added.

See Using Explore In Investigations for more information.

9/24/2020

FEATURE

Maximum Session Lifetime: Org Admins can specify a maximum session lifetime for users in their organization. When this setting is enabled, active ThreatStream sessions are terminated after the specified length of time.

See Maximum Session Lifetime for more information.

9/23/2020

FEATURE

Search: Observable Search supports entering defanged domain, email address, IP address, and URL observable queries. When you enter a defanged value, ThreatStream queries and returns non-defanged observable values.

See Searching for Defanged Observable Values for more information.

9/23/2020

ENHANCEMENT

Investigations: The search function on the on-board Explore pivoting tool within investigations has been enhanced to display observable sources in the search results. With this enhancement, you can select an instance of the observable based on the source of your choosing.

See Using Explore In Investigations for more information.

9/23/2020

ENHANCEMENT

Sandbox: Remaining sandbox submissions for the current 24 hour period are listed at the bottom of the sandbox submission windows for all vendors. Previously, this count was not available for Cuckoo sandbox submissions.

See Submitting Malware for Detonation for more information.

9/23/2020

ENHANCEMENT

Investigations: The maximum file size for candidate observable PDF uploads during investigation creation has been increased to 20MB.

See Creating Blank Investigations for more information.

9/23/2020

ENHANCEMENT

Import: After rejecting an import job, observables listed in the Included and Excluded tables of the import job are maintained for future reference.

See Rejecting Import Jobs for more information.

9/23/2020

BETA RELEASE

Custom Dashboards: Create custom dashboards to surface Threat Intelligence data of interest in customizable widgets. When you create a custom dashboard, you choose whether the dashboard is visible only to you or made available to all users in your organization.

See Custom Dashboards for more information.

8/31/2020

FEATURE

Rules: A new Notify Me setting enables you to opt in or out of email notifications for individual rules. Notify Me is a user level setting and does not impact notification preferences for other users in your organization.

See Receiving Rules Email Notifications for more information.

8/31/2020

FEATURE

Threat Model: Add labels to Threat Model and observables associations to track contextual information. Additionally, an Associated Creation Date timestamp is added when you create associations.

See Adding Labels to Associations for more information.

8/31/2020

ENHANCEMENT

Anomali Lens in ThreatStream: The on-board version of Anomali Lens has been updated with the ability to create Threat Bulletins from the Lens interface when no entities are detected. Additionally, for Anomali Lens+ users, Anomali Lens now leverages Actor and Malware entities created by your organization on ThreatStream. When you scan a web page which contains any of these entities, they are no longer classified as Unknown to ThreatStream.

See Using Anomali Lens in ThreatStream for more information.

8/31/2020

ENHANCEMENT

Investigations: Added the ability to delete investigation attachments.

See Understanding User Interface of Investigations for more information.

8/31/2020

ENHANCEMENT

Investigations: The Explore pivoting chart has been enhanced. You can zoom using your mouse wheel by clicking inside the chart and holding the control key on your keyboard. Additionally, zoom centers on specific nodes when you select nodes and zoom in or out.

See Using Explore In Investigations for more information.

8/31/2020

ENHANCEMENT

Investigations: Investigation and tasks within investigations can now be set to "Unassigned" after being assigned to a specific user or workgroup. Previously, investigations and tasks could only be reassigned to different users or workgroups after initial assignment.

See Understanding User Interface of Investigations for more information.

8/31/2020

DOWNLOADS

Anomali Lens: The latest version of the Anomali Lens plugin, v4.3.0, is available from the ThreatStream Downloads page.

See Downloads for more information.

8/28/2020

ENHANCEMENT

Threat Model: PDF Reports, the template-based PDF export feature for the Anomali Threat Model, has been enhanced. You can now specify colors using hex codes, enjoy a simplified margin configuration experience, and clone templates to create editable versions while preserving the original.

See Creating PDF Reports for more information.

8/28/2020

ENHANCEMENT

STIX Import: Cybox:Keywords are now added as observable tags during STIX 1.2 imports. Cybox:Keywords are not supported for STIX 1.2 exports.

See Supported Attributes for Indicators for more information.

8/28/2020

FEATURE

Enrichments: Added the HYAS Insight enrichment.

See Enriching Data with HYAS Insight for more information.

8/27/2020

ENHANCEMENT

Sandbox: Cuckoo sandbox detonations are now limited to 150 submissions per 24 hours.

See Analyzing Malware with the ThreatStream Sandbox for more information.

8/19/2020

ENHANCEMENT

Observable Search: Added hash as a valid value for the type field to filter observables on the search screen. Previously, the only acceptable value for this field was md5, which led to user confusion that only hashes of type md5 were being filtered and displayed.

See Filtering Hash Observables for more information.

8/17/2020

DOWNLOADS

ThreatStream Integrator: The latest version of the VMWare Carbon Black Enterprise EDR Integrator extension, v1.0.1, is available from the ThreatStream Downloads page.

See Downloads for more information.

8/7/2020

DOWNLOADS

ThreatStream Integrator: The Latest Feature Release of ThreatStream Integrator, v7.0.2, is available from the ThreatStream Downloads page.

See Downloads for more information.

8/5/2020

DOWNLOADS

ThreatStream Splunk App: The latest version of the ThreatStream Splunk App, v6.5.1, is available from the ThreatStream Downloads page.

See Downloads for more information.

8/3/2020

ENHANCEMENT

Rules: Create and edit rules using an intuitive wizard.

See Creating Rules for more information.

7/31/2020

ENHANCEMENT

Rules: Matched intelligence can be added to a new or existing investigation. Previously, intelligence could only be added to new investigations. Additionally, you can configure an assignee for investigations created as a result of rule matches and restrict investigation visibility to organization workgroups.

See Creating Rules for more information.

7/31/2020

ENHANCEMENT

Rules: Create rules which are visible only to selected workgroups.

See Creating Rules for more information.

7/31/2020

FEATURE

ADFS Support: Added the ability to integrate with Microsoft Active Directory Federation Services (ADFS), thus enabling single sign-on (SSO) and ThreatStream user administration from Microsoft Active Directory (AD) or Azure AD.

See Enabling User Management with Active Directory and Active Directory Federation Services for more information.

7/31/2020

DOWNLOADS

Anomali Lens: The latest version of the Anomali Lens plugin, v4.2.0, is available from the ThreatStream Downloads page.

See Downloads for more information.

7/31/2020

FEATURE

Streams: The ability to create tags that are private to your organization has been added to the Streams configuration workflow.

See Importing Feeds Using Basic Submission for more information.

7/31/2020

FEATURE

Investigations: Added the ability to rename node groups on the on-board Explore pivoting tool within investigations.

See Using Explore In Investigations for more information.

7/27/2020

FEATURE

Investigations: Links can now be created between individual nodes and groups. Additionally, when you add a link between a node or group with a group, links are created with each node contained within the group. Thus, if you ungroup nodes in a group, the original link is maintained with each ungrouped node.

See Using Explore In Investigations for more information.

7/27/2020

FEATURE

Enrichments: Added the PolySwarm enrichment.

See Enriching Data with PolySwarm for more information.

7/21/2020

DOWNLOADS

Anomali Match Lens+ Edition: The latest version of Anomali Match Lens+ Edition, v4.2.3, is available from the ThreatStream Downloads page.

See Downloads for more information.

7/21/2020

ENHANCEMENT

Threat Model: Added the ability to specify Source Created and Source Modified timestamps during Threat Model entity creation.

See Adding New Threat Model Entities for more information.

7/7/2020

ENHANCEMENT

Import: Added the ability to specify Source Created and Source Modified timestamps for observables during import.

See Importing Observables for more information.

7/7/2020

FEATURE

Overview Dashboard: A new Investigations dashboard widget enables you to view investigations assigned to you or a workgroup to which you belong by status. You can filter Investigations on the widget by Assignee.

See A Tour of the ThreatStream Overview Dashboard for more information.

6/30/2020

ENHANCEMENT

Reporting Dashboard: All four investigation statuses—Unassigned, In Progress, Pending, and Complete—are now displayed on the Investigations widget on the Reporting Dashboard. You can also view counts of investigations created by the user.

See Generating User Activity Reports for more information.

6/30/2020

FEATURE

Chat: Chat is now generally available on ThreatStream. Leverage instant messaging within ThreatStream to chat with Organization and Trusted Circle members.

See Collaborating with ThreatStream Chat for more information.

6/30/2020

BETA RELEASE

OSINT: Org Admins can disable and enable the open source intelligence feeds feeding your threat intelligence on ThreatStream from the APP Store. This is a beta feature. Contact your Anomali Customer Support representative to participate in the beta release.

See Activating and Deactivating OSINT Feeds for more information.

6/30/2020

FEATURE

Kaspersky APT Intelligence Reporting: Kaspersky subscribers can activate the Kaspersky APT Intelligence Reporting feed from the APP Store. The feed can be activated by uploading an SSL certificate from the Kaspersky tile.

See Subscribing to Anomali Feeds, Enrichments, and Intelligence Channels for more information.

6/30/2020

FEATURE

Recorded Future Intelligence Feed: Recorded Future subscribers can activate the Recorded Future feed from the APP Store.

See Subscribing to Anomali Feeds, Enrichments, and Intelligence Channels for more information.

6/30/2020

FEATURE

Workgroups: Restrict the visibility of observables, Threat Model entities, and investigations to specific workgroups within your organization.

See Restricting Access to Intelligence with Workgroups for more information.

6/29/2020

ENHANCEMENT

Investigations: The Imports list on Investigation details pages has been updated with a "Reviewed By" column.

See Imports: View Import Sessions associated with the investigation. for more information.

6/29/2020

ENHANCEMENT

Anomali Lens in ThreatStream: The on-board version of Anomali Lens has been updated with a streamlined investigations workflow, the capability to filter highlighted entities by highlight type, and improved TTP detection.

See Using Anomali Lens in ThreatStream for more information.

6/26/2020

ENHANCEMENT

APP Store: APP Store tiles have been improved for better readability and usability.

See Subscribing to Anomali Feeds, Enrichments, and Intelligence Channels for more information.

6/26/2020

FEATURE

Custom SSO Authentication Error Message: Organizations that leverage SSO for ThreatStream authentication can configure a custom error message displayed when users attempt to authenticate using an account that does not exist in ThreatStream.

See Custom SSO Authentication Error Message for more information.

6/25/2020

FEATURE

VMRay Freemium: A new freemium integration with VMRay enables all ThreatStream users to leverage VMRay for malware detonation from the ThreatStream user interface. ThreatStream users can activate the freemium VMRay sandbox service at no additional charge.

See Activating VMRay for more information.

6/25/2020

ENHANCEMENT

Rules: The rule configuration workflow has been enhanced with the ability to add multiple keywords in a comma separated or line broken list. Additionally, the indicator type selection workflow has been simplified.

See Creating Rules for more information.

6/24/2020

ENHANCEMENT

Rules: Keywords now appear in a comma separated list on the Edit Rule window, thus simplifying the process of modifying existing keywords.

See Editing Rules for more information.

6/24/2020

DOWNLOADS

ThreatStream Splunk App: The legacy supported version of the ThreatStream Splunk App, v6.4.2, is now available on the ThreatStream Downloads page.

See Downloads for more information.

6/15/2020

DOWNLOADS

Anomali Lens: The latest version of the Anomali Lens plugin, v4.1.0, is available from the ThreatStream Downloads page.

See Downloads for more information.

6/12/2020

DOWNLOADS

Anomali Match Lens+ Edition: The latest version of Anomali Match Lens+ Edition, v4.2.2, is available from the ThreatStream Downloads page.

See Downloads for more information.

6/5/2020

FEATURE

Dragos: Dragos subscribers can receive threat intelligence from Dragos on ThreatStream through a dedicated feed. You can also subscribe to Dragos on a trial basis.

See Subscribing to Anomali Feeds, Enrichments, and Intelligence Channels for more information.

6/2/2020

FEATURE

ZeroFOX: ZeroFOX subscribers can receive threat intelligence from ZeroFOX on ThreatStream through a dedicated feed. You can also subscribe to ZeroFOX on a trial basis.

See Subscribing to Anomali Feeds, Enrichments, and Intelligence Channels for more information.

6/2/2020

ENHANCEMENT

VMRay: The VMRay integration configuration process has been updated. To activate the VMRay integration, you must now enter the URL of the VMRay host where your account is based. No action is required from users that have already activated VMRay. However, if you want to make changes to your VMRay configuration in the future, you must enter this URL.

See Activating VMRay for more information.

6/1/2020

BETA RELEASE

Investigations: Pending import sessions associated with investigations are now available from the Entity Overview section of the investigations user interface. You can click the Pending Import Session link to view pending import sessions in a pop-up window, from which you can approve or reject the import sessions.

See Understanding User Interface of Investigations for more information.

5/30/2020

FEATURE

Integrator Resynchronization: A new setting enables Org Admins to configure whether ThreatStream Integrator performs a full intelligence resynchronization each time your organization joins a new Trusted Circle or subscribes to a new intelligence feed.

See Resync Integrators when joining a new Trusted Circle or Feed for more information.

5/29/2020

FEATURE

Timezone: A new setting enables Org Admins to configure a default timezone for timestamps displayed on the ThreatStream user interface for your organization.

See Timezone for more information.

5/29/2020

ENHANCEMENT

Import: The Import list view has been updated with a Reviewed By column, which contains the username of the user who approved the import session. This column is not displayed by default and can be selected by clicking the settings wheel.

See Viewing Import Jobs Associated With Your Organization for more information.

5/29/2020

FEATURE

JIRA Integration: A new integration with JIRA enables you to create and update JIRA tickets from the Investigations user interface within ThreatStream.

See Integrating with JIRA for more information.

5/28/2020

ENHANCEMENT

Rules: Email notifications for observable matches now contain timestamps of the most recent import which the rule matched. Previously, only timestamps of initial imports for observables were displayed.

See Receiving Rules Email Notifications for more information.

5/27/2020

ENHANCEMENT

MITRE ATT&CK: The Investigation Entities filter on the MITRE ATT&CK model has been enhanced to include all investigation entity types, including ASNs, metadata, and tags. Additionally, all investigation entities—including those without MITRE TTP associations—now appear in the filter.

See Using the MITRE ATT&CK Framework in Investigations for more information.

5/27/2020

ENHANCEMENT

Import: Observables can be associated with Signatures during import by clicking Add Association on the Import Assistant. Previously, Signatures could not be associated with observables during import.

See Importing Observables for more information.

5/26/2020

ENHANCEMENT

Sandbox: The maximum number of Sandbox Reports included in CSV exports has been increased to 10,000.

See Exporting Sandbox Reports in CSV Format for more information.

5/26/2020

ENHANCEMENT

Open Source Observables: A new observable search filter, Open Source Intelligence, enables you filter on observables provided by open source intelligence feeds aggregated by ThreatStream.

See Filtering Open Source Observables for more information.

5/14/2020

ENHANCEMENT

Open Source Threat Model Entities: A new search filter on the Threat Model list view, Show Only Open Source Threat Models, enables you to search Threat Model entities provided by open source intelligence streams exclusively.

See Accessing Threat Models for more information.

5/14/2020

FEATURE

Qualys Enrichment: Render vulnerable assets in your network from Qualys on details pages of CVE compliant vulnerabilities in ThreatStream.

See Qualys Vulnerability Management Enrichment for more information.

5/11/2020

FEATURE

PDF Reports: Template-based PDF report generation for Threat Model entities, previously available as part of a beta release, is now generally available on ThreatStream.

See Creating PDF Reports for more information.

5/6/2020

DOWNLOADS

ThreatStream OnPrem Red Hat: The latest feature release of ThreatStream OnPrem Red Hat, v5.0, is available from the Downloads page within ThreatStream.

See ThreatStream OnPrem Release History for more information.

4/30/2020

ENHANCEMENT

MITRE ATT&CK: Create ad-hoc connections between investigation entities and MITRE ATT&CK TTPs within an investigation. This feature enables you to map investigation entities on the MITRE ATT&CK heatmap at will.

See Managing MITRE ATT&CK Technique Associations Within Investigations for more information.

4/30/2020

ENHANCEMENT

MITRE ATT&CK: A new option on the on-board Explore pivoting chart within investigation enables you to automatically add MITRE TTPs associated with entities that result from pivots.

See Automatically Adding MITRE ATT&CK Techniques to Investigations for more information.

4/30/2020

ENHANCEMENT

Notifications: Subscribe to email and in app investigations notifications based on a granular list of events. Previously, a single subscription was available for investigation notifications.

See Receiving Notifications from ThreatStream for more information.

4/30/2020

FEATURE

Indicator Types: Added the Compromised Service Account (compromised_service_account) indicator type.

See Indicator Types in ThreatStream for more information.

4/30/2020

FEATURE

Threat Model: Share Threat Model entities with ThreatStream users (within or outside your organization) or non-ThreatStream users through email from the Threat Model List View screen.

See Sharing Threat Model Entities via Email for more information.

4/29/2020

FEATURE

Threat Model: User information is displayed next to actions listed in Threat Model entity history. Previously, only actions were displayed.

See Viewing Threat Model Entity History for more information.

4/28/2020

ENHANCEMENT

Threat Model: Threat Model search results can be filtered by entity Owner (the user who created the entity). Previously, this information was only visible on Threat Model entity details pages.

See Accessing Threat Models for more information.

4/28/2020

FEATURE

Sandbox: Export Sandbox Reports in CSV format.

See Exporting Sandbox Reports in CSV Format for more information.

4/27/2020

ENHANCEMENT

Investigations: Observable whitelists are not applied to Not Yet Imported observables in investigations, thus giving you an expanded view of the data under investigation. Previously, whitelists were applied to these observables before explicit action was taken to import them.

See Not Yet Imported Observables in Investigations for more information.

4/27/2020

DOWNLOADS

Anomali Match Lens+ Edition: The latest version of Anomali Match Lens+ Edition, v4.2.1, is available from the ThreatStream Downloads page.

See Anomali Downloads for more information.

4/24/2020

ENHANCEMENT

Observable Search: Added MD5, SHA1, SHA256, and SHA512 hash type filters to the observables search screen. Filters are available when you select Hash in the Type filter section. Filtering hashes with this level of granularity was previously unavailable.

See Filtering Hash Observables for more information.

4/23/2020

FEATURE

Anomali Lens in ThreatStream: Use an on board version of Anomali Lens within the ThreatStream platform.

See Using Anomali Lens in ThreatStream for more information.

4/14/2020

ENHANCEMENT

Threat Model: STIX 2 and 2.1 imports and exports support additional STIX2 Cyber Object types: file (file_name), email-message, mutex, and windows-registry_key.

See Importing STIX Data into the Anomali Threat Model for more information.

4/8/2020

ENHANCEMENT

Threat Model: The Threat Model list view has been updated with CVSS 2.0 and CVSS 3.0 columns. These columns are not displayed by default and can be selected by clicking the settings wheel.

See Accessing Threat Models for more information.

4/8/2020

DOWNLOADS

ThreatStream Integrator: The Latest Feature Release of ThreatStream Integrator, v7.0.0, is available from the ThreatStream Downloads page. ThreatStream Integrator v6.9.6 is available under Recommended Stable Release. The Downloads page has also been updated to include the VMWare Carbon Black Enterprise EDR Integrator extension.

See Downloads for more information.

4/1/2020

FEATURE

VMRay: A new integration with VMRay enables VMRay customers to leverage the VMRay commercial service for malware detonation within the ThreatStream platform.

See Activating VMRay for more information.

3/31/2020

BETA RELEASE

PDF Reports: Generate PDFs based on customizable templates for sharing with a wider audience outside of ThreatStream.

See Creating PDF Reports for more information.

3/31/2020

ENHANCEMENT

Rules: Restrict rule email notifications to a specific user workgroup.

See Creating Rules for more information.

3/30/2020

ENHANCEMENT

Threat Model: Nation State is an available Victim for Actors on ThreatStream.

See Viewing Actor Details for more information.

3/30/2020

ENHANCEMENT

Import: Associate observables with Vulnerabilities during import.

See Importing Observables for more information.

3/27/2020

ENHANCEMENT

Streams: Export stream details in CSV format.

See Exporting Feeds to a CSV File for more information.

3/26/2020

ENHANCEMENT

User Admin: The email notification sent to the organization administrator when a new user is added to the organization now includes permissions that were assigned to the user.

3/26/2020

ENHANCEMENT

Hash Subtypes: The subtypes field provides additional metadata on the type of hash associated with hash observables. Possible values include MD5, SHA1, SHA256, SHA512.

See Intelligence Fields in ThreatStream for more information.

3/24/2020

ENHANCEMENT

Threat Model: Latest threat intelligence on COVID-19 and recommendations to bolster your security controls and downstream integrations.

See Bolstering Your Security Controls Against COVID-19 for more information.

3/23/2020

FEATURE

Splunk Sightings: A new integration with Splunk Sightings enables you view sightings from your Splunk cloud instance on observable details pages in ThreatStream.

See Enriching Data with Splunk Sightings for more information.

3/20/2020

BETA RELEASE

MITRE ATT&CK: All ThreatStream Enterprise users can leverage the MITRE ATT&CK Framework within Investigations.

See Using the MITRE ATT&CK Framework in Investigations for more information.

3/10/2020

ENHANCEMENT

Sandbox: The character limit of URLs supported for submission has been increased to 2000.

See Submitting Malware for Detonation for more information.

3/3/2020

BETA RELEASE

Chat: Leverage instant messaging within ThreatStream to chat with Organization and Trusted Circle members. Contact Anomali Customer Support to participate in this beta release.

See Collaborating with ThreatStream Chat for more information.

3/2/2020

FEATURE

STIX 2.0 and 2.1 Import: Import STIX 2.0 and STIX 2.1 compatible Threat Model entities and Indicators. For STIX 2.0 and 2.1 Observable imports, only basic patterns are supported. Basic patterns contain one Observation Expression which consists of a single Comparison Expression.

See Importing STIX Data into the Anomali Threat Model for more information.

2/28/2020

FEATURE

STIX 2.0 and 2.1 Export: Export STIX 2.0 and STIX 2.1 compatible Threat Model entities and Observables.

See Exporting Threat Model Entities in STIX Format for more information.

2/28/2020

FEATURE

STIX 2.0 and 2.1 Support: Attack Patterns, Courses of Action, Identities, Infrastructure, Intrusion Sets, and Tools have been added to the ThreatStream Threat Model.

See Using the Anomali Threat Model for more information.

2/28/2020

FEATURE

MITRE ATT&CK:Anomali Lens+ customers can leverage the MITRE ATT&CK Framework within Investigations.

See Using the MITRE ATT&CK Framework in Investigations for more information.

2/24/2020

DOWNLOADS

Anomali Lens: The latest version of the Anomali Lens plugin, v4.0.0, is available from the ThreatStream Downloads page. Anomali Lens+ customers can also download Match Lens+ Edition from the Downloads page.

See Downloads for more information.

2/24/2020

DOWNLOADS

ThreatStream Splunk App: The latest version of the ThreatStream Splunk App, v6.4.1, is available from the ThreatStream Downloads page.

See Downloads for more information.

2/24/2020

FEATURE

FireEye Mandiant: FireEye Mandiant subscribers can receive threat intelligence from FireEye on ThreatStream through a dedicated feed.

See Subscribing to Anomali Feeds, Enrichments, and Intelligence Channels for more information.

2/24/2020

ENHANCEMENT

Recorded Future: The Recorded Future enrichment has been updated with a new user interface.

See Enriching Data with Recorded Future for more information.

2/7/2020

FEATURE

What's New: View the five most recent features or enhancements added to the ThreatStream platform by clicking the gift icon in the top navigation bar.

See Navigating ThreatStream for more information.

1/31/2020

FEATURE

Public Tags: Prevent users from outside your organization from adding Anomali Community (public) tags to data owned by your organization.

See Allow public tags on data owned by my organization for more information.

1/30/2020

ENHANCEMENT

Tags: When adding tags to an entity on ThreatStream, you can select multiple tags from the tag suggestion dropdown.

See Adding Preferred Tags to Intelligence for more information.

1/27/2020

ENHANCEMENT

OpenDNS Umbrella: Send up to 10,000 domains to OpenDNS in a single snapshot.

See Integrating with OpenDNS Umbrella for more information.

1/24/2020

ENHANCEMENT

Streams: The Streams page has been updated with a new UI.

See Managing Feeds for more information.

1/22/2020

ENHANCEMENT

User Admin: Org Admins can grant or revoke API key access for individual users from the User Admin tab within ThreatStream settings.

See Managing Organization Users for more information.

1/14/2020

FEATURE

Product Improvement Program: Help Anomali improve ThreatStream and customize your user experience by consenting to ThreatStream usage data collection.

See "Help Improve ThreatStream" on Viewing and Editing Organization Settings for more information.

1/13/2020

ENHANCEMENT

Rules: The number of rules an organization can create is limited to 300.

See Creating Rules for more information.

1/9/2020

ENHANCEMENT

Import: Filter import jobs on the Import page by Owner.

See Viewing Import Jobs Associated With Your Organization for more information.

1/7/2020

ENHANCEMENT

Observables: Explore pivoting tools on Observable details pages include an additional Export icon, thus enabling you to export charts in PNG format.

1/6/2020

ENHANCEMENT

Investigations: Explore pivoting tools within Investigations include an additional Export icon, thus enabling you to export charts in PNG format.

1/6/2020

ENHANCEMENT

Investigations: Filter Investigations on the Investigations list view screen by Modified Date.

1/3/2020