What's New in ThreatStream (2021)

Use this page to track 2021 ThreatStream updates and reference relevant articles in the online help center.

Update Date

DOWNLOADS

Log4J: A patch that addresses Log4J vulnerabilities for ThreatStream OnPrem and ThreatStream AirGap is available from the ThreatStream Downloads page.

See Downloads for more information.

12/21/2021

FEATURE

SSO: Provision and manage integration with SAML 2.0 and OKTA Marketplace identity providers to enable single sign-on (SSO) for ThreatStream. ThreatStream supports integration with SAML 2.0 and OKTA Marketplace identity providers.

See Configuring Single Sign On (SSO) for more information.

12/15/2021

DOWNLOADS

ThreatStream Integrator: The Latest Feature Release of ThreatStream Integrator, v7.3, is available from the ThreatStream Downloads page. ThreatStream Integrator v7.2.4 is available under Recommended Stable Release.

See Downloads for more information.

12/2/2021

FEATURE

Anomali Targeted Threat Monitoring: Anomali Targeted Threat Monitoring (ATTM) is now available from the APP Store. ATTM is a premium feed curated by the Anomali Threat Research team to identify threats to your organizational brand and assets.

See Anomali Targeted Threat Monitoring (ATTM) for more information.

11/30/2021

ENHANCEMENT

Enrichments: Enrichments are now available for activation from the ThreatStream APP Store. Previously, enrichments were managed from the Integrations tab of ThreatStream Settings.

See Subscribing to Anomali Feeds, Enrichments, and Intelligence Channels for more information.

11/30/2021

ENHANCEMENT

Enrichments: The GreyNoise enrichment has been updated.

See Enriching Data with GreyNoise for more information.

11/30/2021

FEATURE

ThreatStream TAXII Server: A new TAXII 2.1 discover URL enables you to poll data from your TAXII feeds on ThreatStream into TAXII clients in TAXII 2.1 format.

See Connecting to Your ThreatStream TAXII Server From a TAXII Client for more information.

11/23/2021

ENHANCEMENT

Advanced Search: The advanced observable and Threat Model search screens now automatically save the most recent advanced search query you executed. Simply select Last Search from the Search Filter menu to execute the search again.

See Performing Advanced Observable Searches for more information.

11/23/2021

ENHANCEMENT

Intelligence Initiatives: Rules and observables can now be associated with intelligence initiatives. Additionally, Threat Model entities can now be associated with intelligence initiatives through manual selection or using a saved Threat Model advanced search.

See Information in an Intelligence Initiative for more information.

11/22/2021

ENHANCEMENT

Hybrid Analysis Enrichment: The Hybrid Analysis enrichment has been updated. Returned observable values now link to observable details pages in ThreatStream. Additionally, a corresponding link to more information on the Hybrid Analysis user interface is available for each observable.

See Enriching Data with Hybrid Analysis for more information.

10/29/2021

DOWNLOADS

Zeek Integrator Extension: The initial release of the Zeek Integrator extension, v1.0, is available from the ThreatStream Downloads page.

See Downloads for more information.

10/22/2021

FEATURE

Workgroups Dashboard: Gain insight on the latest activity from the workgroups of which you are a member.

See Viewing the Workgroups Dashboard for more information.

10/25/2021

DOWNLOADS

FireEye Helix Integrator Extension: The latest version of the FireEye Helix Integrator extension, v1.0.1, is available from the ThreatStream Downloads page.

See Downloads for more information.

10/20/2021

DOWNLOADS

ThreatStream Splunk App: The latest version of the ThreatStream Splunk App, v6.5.4, is available from the ThreatStream Downloads page.

See Downloads for more information.

10/18/2021

DOWNLOADS

CrowdStrike Falcon Integrator Extension: The initial release of the CrowdStrike Falcon Integrator extension, v1.0, is available from the ThreatStream Downloads page.

See Downloads for more information.

10/14/2021

FEATURE

Enrichments: Added the Symantec Endpoint Security enrichment.

See Enriching Data with Symantec Endpoint Security for more information.

9/30/2021

ENHANCEMENT

Anomali Lens Trending Widgets: Add Anomali Lens trending widgets to custom dashboards that display data from the last 7 days. Anomali Lens trending widgets are available to Anomali Lens+ users only.

See Adding Anomali Copilot Trending Widgets to Custom Dashboards for more information.

9/29/2021

ENHANCEMENT

STIX Relationship Objects: Create STIX compliant relationship objects (SROs) can now be defined during Threat Model creation and observable import.

See Defining SROs Between Entities for more information.

9/28/2021

DOWNLOADS

Exabeam Fusion Integrator Extension: The initial release of the Exabeam Fusion Integrator extension, v1.0, is available from the ThreatStream Downloads page.

See Downloads for more information.

9/23/2021

FEATURE

MITRE ATT&CK: MITRE ATT&CK v7.2 and later techniques and sub-techniques are now available on the security control matrix and can be added to investigations. See MITRE ATT&CK v7.2 and later Techniques for more information.

In addition, you can now specify the MITRE ATT&CK version for your organization. See Specifying a Default MITRE ATT&CK Version for your Organization.

8/27/2021

DOWNLOADS

Anomali Lens: The latest version of the Anomali Lens plugin, v4.9.0, is available from the ThreatStream Downloads page.

See Downloads for more information.

8/27/2021

FEATURE

Intelligence Initiatives: Attribute organizational efforts to specific goals by centralizing related threat intelligence feeds (known within intelligence initiatives as Collections), investigations, and Threat Model entities.

See Attributing Organizational Goals with Intelligence Initiatives for more information.

8/25/2021

DOWNLOADS

Microsoft Defender for Endpoint Integrator Extension: The initial release of the Microsoft Defender for Endpoint Integrator extension, v1.0, is available from the ThreatStream Downloads page.

See Downloads for more information.

8/16/2021

DOWNLOADS

FireEye Helix Integrator Extension: The initial release of the FireEye Helix Integrator extension, v1.0, is available from the ThreatStream Downloads page.

See Downloads for more information.

8/16/2021

DOWNLOADS

Anomali Lens: Anomali Lens+ users can leverage an Anomali Lens Add-in for Excel. The first release of the Excel Add-in is available from the ThreatStream Downloads page. Anomali Lens+ Add-ins are available to Anomali Lens+ customers only. Interested in purchasing Lens+? Contact sales@anomali.com for more information.

See Downloads for more information.

8/6/2021

ENHANCEMENT

Sandbox: The Cuckoo implementation has been updated to a more recent supported platform. Note that the new Cuckoo sandbox supports Windows 7 but does not support Windows XP detonations.

See Analyzing Malware with the ThreatStream Sandbox for information about using sandboxes.

7/27/2021

ENHANCEMENT

Audit: The user interface for the Audit page has been redesigned to make it easy to apply filters and export audit log reports.

See User Activity Audit for more information.

7/27/2021

ENHANCEMENT

Enrichments: The GreyNoise enrichment has been updated.

See Enriching Data with GreyNoise for more information.

7/27/2021

ENHANCEMENT

Search: The user interface for constructing advanced search filters on the Observable and Threat Model search pages has been improved.

See Performing Advanced Observable Searches and Performing Advanced Threat Model Searches for illustrations and information about how to construct advanced search filters.

7/26/2021

FEATURE

User Administration: A new Submit Sandbox user permission can be used to control which users are allowed to submit to a sandbox detonation service.

See Managing Organization Users for more information.

7/26/2021

ENHANCEMENT

Sandbox: The API Endpoint for malware submissions to Joe Sandbox is now configurable. When you activate the Joe Sandbox integration, you are prompted to configure the Joe Sandbox API endpoint setting for your specific subscription.

See Activating Joe Sandbox for more information.

7/22/2021

DOWNLOADS

ThreatStream Integrator: The Latest Feature Release of ThreatStream Integrator, v7.2.4, is available from the ThreatStream Downloads page. ThreatStream Integrator v7.2.1 is available under Recommended Stable Release.

See Downloads for more information.

7/16/2021

DOWNLOADS

ThreatStream Integrator: The Latest Feature Release of ThreatStream Integrator, v7.2.3, is available from the ThreatStream Downloads page. ThreatStream Integrator v7.2.1 is available under Recommended Stable Release.

See Downloads for more information.

6/30/2021

DOWNLOADS

ThreatStream OnPrem: The latest release of ThreatStream OnPrem, v5.2, is available from the ThreatStream Downloads page.

See Downloads for more information.

6/30/2021

DOWNLOADS

Anomali Lens: Anomali Lens+ users can leverage an Anomali Lens Add-in for Word. The first release of the Word Add-in is available from the ThreatStream Downloads page. Anomali Lens+ Add-ins are available to Anomali Lens+ customers only. Interested in purchasing Lens+? Contact sales@anomali.com for more information.

See Downloads for more information.

6/30/2021

ENHANCEMENT

Streams: Streams curated by the Anomali Threat Research team have been renamed.

See Managing Feeds for more information.

6/30/2021

FEATURE

APP Store: The SEKOIA.IO Threat Intelligence and ThreatFabric Mobile Threat Intel feeds are available for activation in the APP Store.

See Subscribing to Anomali Feeds, Enrichments, and Intelligence Channels for more information.

6/29/2021

ENHANCEMENT

VirusTotal Enrichment: The Hash to Submitter ID and Url to Submitter ID pivots are now available for the VirusTotal v3 enrichment.

See Enriching Data with VirusTotal v3 for more information.

6/29/2021

FEATURE

STIX Import: A new STIX Imports screen enables you to view the status of STIX import jobs.

See Viewing STIX Import Jobs for more information.

6/28/2021

FEATURE

Custom Dashboard Export: Custom dashboards can be exported in PDF format. Additionally, individual dashboard widgets can be exported in PNG format.

See Exporting Custom Dashboards for more information.

6/25/2021

FEATURE

ReversingLabs - Ransomware and Related Tools Intel List: The ReversingLabs - Ransomware and Related Tools Intel List feed is available for activation in the APP Store.

See Subscribing to Anomali Feeds, Enrichments, and Intelligence Channels for more information.

6/25/2021

DOWNLOADS

Azure Sentinel Integrator Extension: The latest release of the Azure Sentinel Integrator extension, v1.1.1, is available from the ThreatStream Downloads page.

See Downloads for more information.

6/21/2021

FEATURE

Flashpoint Compromised Credentials: The Flashpoint Compromised Credentials feed is available for credentialed activation in the APP Store.

See Subscribing to Anomali Feeds, Enrichments, and Intelligence Channels for more information.

6/17/2021

FEATURE

Organization Settings: An Allow Observable Imports from Sandbox setting enables Org Admins to configure whether organization users can automatically import observables discovered during Sandbox detonations. When this setting is enabled, an additional option allows Org Admins to configure whether the Import Observables option is pre-selected on the Sandbox detonation window.

See Allow Observable Imports from Sandbox for more information.

6/7/2021

FEATURE

Indicator Types: Added the Hack Tool File Hash (hack_tool_md5) indicator type.

See Indicator Types in ThreatStream for more information.

6/2/2021

DOWNLOADS

Anomali Lens: Anomali Lens+ users can leverage an Anomali Lens Add-in for Outlook. The first release of the Add-in is available from the ThreatStream Downloads page. Anomali Lens+ Add-ins are available to Anomali Lens+ customers only. Interested in purchasing Lens+? Contact sales@anomali.com for more information.

See Downloads for more information.

6/1/2021

DOWNLOADS

Anomali Match: The latest version of Anomali Match, v4.4, is available from the ThreatStream Downloads page.

See Downloads for more information.

5/28/2021

DOWNLOADS

Anomali Match Links: The latest versions of Anomali Link for QRadar (v1.3.2), Anomali Link for RSA NetWitness (v1.0.2), Anomali Link for Splunk (v2.2.1), and Anomali Universal Link (4.4) are available from the ThreatStream Downloads page.

See Downloads for more information.

5/28/2021

DOWNLOADS

Anomali Lens: The latest version of the Anomali Lens plugin, v4.8.0, is available from the ThreatStream Downloads page.

See Downloads for more information.

5/28/2021

FEATURE

STIX Relationship Objects: Create STIX compliant relationship objects (SROs) that define relationships between entities in the Anomali Threat Model.

See Managing STIX Relationship Objects (SROs) for more information.

5/27/2021

FEATURE

SWIFT ISAC Threat Intelligence Feed: The SWIFT ISAC Threat Intelligence Feed is available for credentialed activation in the APP Store.

See Subscribing to Anomali Feeds, Enrichments, and Intelligence Channels for more information.

5/27/2021

ENHANCEMENT

MITRE ATT&CK: MITRE ATT&CK techniques and sub-techniques associated with v9 are available in the Anomali Threat Model.

See MITRE ATT&CK v7.2 and later Techniques for more information.

5/25/2021

FEATURE

Anomali Lens Trending Widgets: Anomali Lens+ users have access to additional custom dashboard widgets that surface information from Anomali Lens on trending threat intelligence.

See Adding Anomali Copilot Trending Widgets to Custom Dashboards for more information.

5/24/2021

ENHANCEMENT

Threat Model: Latest threat intelligence on Sunburst Supply Chain Attacks and recommendations to bolster your security controls and downstream integrations.

See Bolstering Your Security Controls Against the Sunburst Supply Chain Attacks for more information.

5/11/2021

FEATURE

Polyswarm Freemium Hot Malware: The Polyswarm Freemium Hot Malware feed is available for activation in the APP Store.

See Activating Free Feeds for more information.

5/11/2021

ENHANCEMENT

Qualys Vulnerability Management Enrichment: Additional configuration options enable you to specify which assets you want included in patch reports.

See Qualys Vulnerability Management Enrichment for more information.

4/28/2021

ENHANCEMENT

Enrichments: The HYAS Insight enrichment has been updated to v1.3.0.

See Enriching Data with HYAS Insight for more information.

4/28/2021

FEATURE

Enrichments: Added the CipherTrace Sentry enrichment.

See Enriching Data with CipherTrace Sentry for more information.

4/28/2021

ENHANCEMENT

Rules: An Enabled switch allows you to toggle whether the rule is enabled. If switched off, the rule is disabled and no longer matches for keywords in new intelligence.

See Rules for more information.

4/28/2021

FEATURE

Enrichments: Added the Deloitte Codex enrichment.

See Enriching Data with Deloitte Codex for more information.

4/27/2021

FEATURE

Indicator Types: Added the actor_subject, apt_subject, fraud_email_subject, malware_email_subject, phishing_email_subject, spam_email_subject, suspicious_email_subject, email_attachment_subject, and compromised_email_subject indicator types.

See Indicator Types in ThreatStream for more information.

4/27/2021

FEATURE

Custom Dashboards: Create custom dashboard widgets based on saved advanced Threat Model search filters.

See Custom Dashboards for more information.

4/26/2021

FEATURE

Investigation Export: Export a list of investigations in CSV format from the investigations list view screen.

See Exporting Investigations to a CSV File for more information.

4/26/2021

DOWNLOADS

ThreatStream Integrator: The Latest Feature Release of ThreatStream Integrator, v7.2.1, is available from the ThreatStream Downloads page. ThreatStream Integrator v7.1.1 is available under Previous Release.

See Downloads for more information.

4/13/2021

DOWNLOADS

Anomali Match Links: The latest versions of Anomali Link for RSA NetWitness (v1.0.1) and Anomali Link for Splunk (v2.2.1) are available from the ThreatStream Downloads page.

See Downloads for more information.

4/12/2021

ENHANCEMENT

Workgroups: Add Read Only users to workgroups. Previously, Read Only users could not be added to workgroups.

See Restricting Access to Intelligence with Workgroups for more information.

3/25/2021

FEATURE

Threat Model: Import STIX 2.1 compatible custom objects through the STIX tab of the import assistant.

See Adding STIX 2.1 Custom Objects to the Anomali Threat Model for more information.

3/25/2021

ENHANCEMENT

Sandbox: The ThreatStream Joe Sandbox service now provides the High Sierra 10.13.2, Ubuntu Linux 16.04 x64, and Android 9 for malware detonation.

See Analyzing Malware with the ThreatStream Sandbox for more information.

3/24/2021

DOWNLOADS

Anomali Lens: The latest version of the Anomali Lens plugin, v4.7.0, is available from the ThreatStream Downloads page.

See Downloads for more information.

3/17/2021

FEATURE

Group-IB: Group-IB customers can activate the Group-IB Anti-Phishing, Brand Abuse Add on, or Threat Intelligence feeds from the APP Store.

See Subscribing to Anomali Feeds, Enrichments, and Intelligence Channels for more information.

3/5/2021

FEATURE

Threat Model: Advanced search functionality has been added to the Anomali Threat Model. With advanced search, you can construct search filters for specialized searches. Search filters can be saved for later use.

See Performing Advanced Threat Model Searches for more information.

2/25/2021

ENHANCEMENT

Chat:ThreatStream Chat has been updated with a new user interface.

See Collaborating with ThreatStream Chat for more information.

2/25/2021

ENHANCEMENT

Investigations: A Bulk Add option has been added to the Explore pivoting chart and the table view on the investigations user interface. Bulk Add enables you to add candidate observables to the investigation from a PDF or TXT file at any time.

See Managing Investigation Entities for more information.

2/25/2021

ENHANCEMENT

Investigations: Add analysis to investigation entities in the Not Imported status.

See Managing Entities on the Table View for more information.

2/25/2021

ENHANCEMENT

Read Only Users: Read only users can now add shared custom dashboards to their home screens on ThreatStream and perform advanced observable and Threat Model searches.

See Read Only User Privileges for more information.

2/24/2021

ENHANCEMENT

Search: A Key Filters section has been added to the left filter for the Observable and Threat Model basic search screens. These filters enable you to quickly locate data created by your organization or open source feeds.

See Filtering Search Results for more information.

2/23/2021

FEATURE

Investigations: Leverage contextual data enrichments within from the Explore pivoting tool within investigations. Contextual enrichments, which are also available in the Enrichments section on observable details pages, provide qualitative information from third-party sources on individual observables.

See Using Automated Tasks in Investigations for more information.

2/22/2021

FEATURE

Organization Settings: Org Admins can restrict the email domains with which Threat Model entities can be shared.

See Email Report Distribution for more information.

2/22/2021

ENHANCEMENT

Enrichments: The ReversingLabs enrichment has been updated.

See Enriching Data with ReversingLabs Spectra Intelligence for more information.

2/17/2021

FEATURE

Enrichments: Added the GreyNoise enrichment.

See Enriching Data with GreyNoise for more information.

2/11/2021

DOWNLOADS

ThreatStream Splunk App: The latest version of the ThreatStream Splunk App, v6.5.3, is available from the ThreatStream Downloads page.

See Downloads for more information.

2/10/2021

FEATURE

Crowdstrike Falcon X: Crowdstrike customers can activate the Crowdstrike Falcon X intelligence feed from the APP Store.

See Subscribing to Anomali Feeds, Enrichments, and Intelligence Channels for more information.

2/8/2021

ENHANCEMENT

Search: The character limit for saved observable search filters has been increased to 2,000.

See Saving Observable Search Filters for more information.

2/1/2021

ENHANCEMENT

Qualys: The Qualys Vulnerability Management enrichment has been updated with a new Qualys Patch Report search option.

See Qualys Vulnerability Management Enrichment for more information.

1/28/2021

FEATURE

VirusTotal v3: A new enrichment leveraging the VirusTotal v3 API is available.

See Enriching Data with VirusTotal v3 for more information.

1/28/2021

FEATURE

Themed Custom Dashboards: Clone custom dashboards created by the Anomali Threat Research team, thus creating editable versions.

See for more information.

1/25/2021

ENHANCEMENT

MITRE ATT&CK: Configure a representation of your MITRE ATT&CK Security Control Framework using a JSON file generated by the MITRE ATT&CK Navigator tool.

See Configuring a Representation of your Security Coverage from a JSON File for more information.

1/25/2021