What's New in ThreatStream (2022)
Use this page to track 2022 ThreatStream updates and reference relevant articles in the online help center.
| Update | Date |
|---|---|
|
FEATURE Anomali Intelligence Channels: Get access to high-quality curated data optimized for specific threat intelligence initiatives such as malware and mobile threats. Anomali Intelligence Channels are powered by Anomali and partner intelligence feeds. See Managing Anomali Intelligence Channels for more information. |
12/21/2022 |
|
ENHANCEMENT MITRE ATT&CK: MITRE ATT&CK techniques and sub-techniques associated with v11.3 and v12.1 are now available in the Anomali Threat Model. See Using MITRE ATT&CK Frameworks in ThreatStream for more information. |
12/20/2022 |
|
NOTICE OF REMOVAL Premium Feeds: The Intel 471 Freemium Cybercrime Intelligence feed has been removed from the ThreatStream platform. If you have questions or concerns, please contact Anomali Customer Support. |
12/15/2022 |
|
ENHANCEMENT MITRE ATT&CK: Mobile and ICS types of MITRE ATT&CK Framework are now supported by ThreatStream and can be leveraged within Investigations. See Configuring Security Coverage of MITRE ATT&CK Profiles for more information. |
11/30/2022 |
|
ENHANCEMENT Trusted Circles: The Trusted Circles page has a new look and feel now. See Viewing Trusted Circles for more information. |
11/30/2022 |
|
ENHANCEMENT Import: The Import Job Details page has a new look and feel now. See Viewing Import Jobs Associated With Your Organization for more information. |
11/30/2022 |
|
ENHANCEMENT Feed Notifications: A recommended value for no data threshold has been added to feeds. See Viewing and Monitoring Health Information of Active Feeds and Intelligence Channels for more information. |
11/29/2022 |
|
ENHANCEMENT SSO: User self-provisioning of SSO has been improved to provide better flexibility in the way service or provider details are configured. See Configuring Single Sign On (SSO) for more information. |
11/29/2022 |
|
FEATURE Themed Custom Dashboards: The following custom dashboards developed by the Anomali Threat Research have been added to ThreatStream: Intelligence Insights - For Customers in AMER Region (Last 90 Days), Intelligence Insights - For Customers in APAC Region (Last 90 Days), Intelligence Insights - For Customers in EMEA Region (Last 90 Days). See for more information. |
11/29/2022 |
|
DOWNLOADS ThreatStream Integrator: The latest feature release of ThreatStream Integrator, v8.1.1, is available from the ThreatStream Downloads page. See Downloads for more information. |
11/09/2022 |
|
FEATURE Attack Flow Library: Visualize the sequence of techniques used in an attack, the relationships between techniques, and other information to stop or prevent attacks on your environment at an early stage of an attack flow. See Attack Flow Library for more information. |
11/3/2022 |
|
ENHANCEMENT OSINT: The Anomali Curated Twitter open source feed is now available in APP Store. See Managing Open Source Intelligence (OSINT) Feeds for more information. |
11/2/2022 |
|
FEATURE Description Templates: Create rich text description templates and manage them from ThreatStream Settings, Threat Models or investigations. See Managing Description Templates for more information. |
10/31/2022 |
|
ENHANCEMENT Health Feed Notifications: Set how frequently you want to receive feed error notifications. See Viewing and Monitoring Health Information of Active Feeds and Intelligence Channels for more information. |
10/31/2022 |
|
FEATURE Premium Feeds: The Cofense Triage premium feed is now available for activation in APP Store. See Managing Premium Feeds for more information. |
10/28/2022 |
|
FEATURE Bulk Edit Tags: Edit (add and remove) tags of the first 10,000 observables from the Observables Advanced search page. See Bulk Tag Management of Observables for more information. |
10/24/2022 |
|
ENHANCEMENT Sigma Signatures: Sigma is added to the list of signature types available in ThreatStream. See Editing Signatures for more information. |
10/24/2022 |
|
DOWNLOADS Anomali Match: The latest version of Anomali Match, v4.5, is available from the ThreatStream Downloads page. See Downloads for more information. |
10/23/2022 |
|
DOWNLOADS Anomali Match Links: The latest version of Anomali Universal Link (5.0) is available from the ThreatStream Downloads page. Universal Link 5.0 supports deployments with Match Cloud and Match OnPrem. See Downloads for more information. |
10/23/2022 |
|
NOTICE OF REMOVAL AlienVault ThreatCrowd: Due to observed problems with the AlienVault ThreatCrowd API service, Anomali has removed the enrichment from the ThreatStream platform. If you have concerns or wish to discuss this removal, please contact Anomali Customer Success. |
10/19/2022 |
|
ENHANCEMENT Retrospective Search: Run a Forensics & Retrospective search on your Match Cloud instance for a Threat Bulletin from ThreatStream. See Viewing Threat Bulletin Details for more information. |
10/14/2022 |
|
NEW OFFER Anomali Premium Digital Risk Protection: Now new Anomali customers can get access to a premium threat intelligence feed formerly known as ATTM+. See Anomali Premium Digital Risk Protection (PDRP) for more information. |
9/23/2022 |
|
NEW OFFER Attack Surface Assessment Report: Request an Attack Surface Assessment Report to get an insight into your organization's assets and evaluate their exposure to attacks in order to mitigate the risks and provide better security. See Accessing Attack Surface Assessment Report for more information. |
9/15/2022 |
|
FEATURE Feed Health Notification: Receive an email or in-app notification when a feed is down. This feature is now generally available. See Subscribing to Anomali Feeds, Enrichments, and Intelligence Channels for more information. |
9/30/2022 |
|
ENHANCEMENT Custom Dashboards: Now you can add up to 20 widgets to your custom dashboards. See Creating Custom Dashboards for more information. |
9/28/2022 |
|
ENHANCEMENT Preferred Tags: Allow non-admin users to add new tags and choose to include or exclude kill chain tags from the list of preferred tags. See Adding Preferred Tags to Intelligence for more information. |
9/27/2022 |
|
DOWNLOADS ThreatStream Integrator: The latest SDK-based extensions for ThreatStream Integrator v8.1 are available from the Downloads page within ThreatStream. See Downloads for more information. |
9/29/2022 |
|
DOWNLOADS ThreatStream OnPrem Red Hat: The latest feature releases of ThreatStream OnPrem v5.3 for Red Hat v7.9 and v8.4 are available from the Downloads page within ThreatStream. See Downloads for more information. |
9/14/2022 |
|
DOWNLOADS ThreatStream Splunk App: The latest version of the ThreatStream Splunk App, v6.6.1, is now available from the ThreatStream Downloads page. See Downloads for more information. |
9/9/2022 |
|
DOWNLOADS ThreatStream Integrator: The latest feature release of ThreatStream Integrator, v8.1, is available from the ThreatStream Downloads page. See Downloads for more information. |
8/31/2022 |
|
BETA RELEASE Feed Health Notification: Receive an email or in-app notification when a feed is down. See Subscribing to Anomali Feeds, Enrichments, and Intelligence Channels for more information. |
8/30/2022 |
|
FEATURE Automating Investigations Task: When you need to run several checks on an observable, you can use an automated task—a predefined sequence of enrichments applied to a specific type of the observable during the investigation. See Automating Investigation Tasks in ThreatStream for more information. |
8/25/2022 |
|
FEATURE Enrichments: Added the Intezer Analyze enrichment. See Enriching Data with Intezer Analyze for more information. |
8/25/2022 |
|
FEATURE Organization Settings: A new setting, Restrict TLP White Comments, restricts users in your organization from posting TLP White comments in Threat Models, Observables, and Sandbox Reports to prevent your organization’s comments from being shared publicly. See Restrict Public Comments for more information. |
8/3/2022 |
|
FEATURE Premium Feeds: The Cybersixgill Reports Premium feed is available for activation in the APP Store. See Managing Premium Feeds for more information. |
7/27/2022 |
|
ENHANCEMENT Matches/My Attacks: The Matches and My Attacks information (previously known as Sightings) provides a comprehensive view of the attack data received from your Anomali Match Cloud or Anomali Match on-premise, and integration destinations such as ArcSight ESM, LogRhythm, QRadar, and Splunk that are impacting your infrastructure. See Viewing Matches and My Attacks for more information. |
7/25/2022 |
|
FEATURE Premium Feeds: Bfore.Ai subscribers can activate the Bfore.Ai PreCrime Network feed from the APP Store. See Managing Premium Feeds for more information. |
7/25/2022 |
|
FEATURE Themed Custom Dashboards: The following custom dashboards developed by the Anomali Threat Research team are now available in ThreatStream: Malware Intelligence - Ransomware, Malware Intelligence - Remote Access Tools and Trojans, and Threat Actor Monitoring - China-based Actors. See Utilizing Themed Custom Dashboards from the Anomali Threat Research Team for more information. |
6/30/2022 |
|
FEATURE Premium Feeds: Mandiant subscribers can activate the Mandiant v4 feed from the APP Store. This integration provides access to contextually rich threat intelligence including indicators, threat actors, malware, and intelligence reports. Existing Mandiant feeds will remain active for some time, but Anomali encourages migrating to v4 to benefit from the improved integration. See Managing Premium Feeds for more information. |
6/29/2022 |
|
FEATURE Premium Feeds: The Cybersixgill Reports Freemium feed is available for activation in the APP Store. See Managing Premium Feeds for more information. |
6/14/2022 |
|
ENHANCEMENT OSINT: The following open source feeds have been added to the APP Store: Abuse.ch - MalwareBazaar, BruteForcer IP Blocklist, CyberCrime, Emerging Threats - Compromised, Emerging Threats C&C Server, Internet Storm Center - DShield Scanning IPs. You must enable them for your organization to start receiving threat intelligence from these feeds. See Managing Open Source Intelligence (OSINT) Feeds for more information. |
6/7/2022 |
|
FEATURE Feed Health: Feed Health is now generally available on ThreatStream. View the synchronization history of active feed sources listed in the APP Store from the last 30 days. See Subscribing to Anomali Feeds, Enrichments, and Intelligence Channels for more information. |
6/6/2022 |
|
ENHANCEMENT MITRE ATT&CK: MITRE ATT&CK techniques and sub-techniques associated with v10.0, v10.1, and v11.0 are available in the Anomali Threat Model. See MITRE ATT&CK v7.2 and later Techniques for more information. |
5/31/2022 |
|
FEATURE Indicator Types: Added the Infected Bot Domain Name (bot_domain), Infected Bot Hash (bot_md5), Infected Bot URL (bot_url), and Exploit Hash (exploit_md5) indicator types. See Indicator Types in ThreatStream for more information. |
5/31/2022 |
|
DOWNLOADS ThreatStream Splunk App: The latest version of the ThreatStream Splunk App, v6.5.8, is available from the ThreatStream Downloads page. This release is only applicable to the on-premise deployments of Splunk. See Downloads for more information. |
5/27/2022 |
|
ENHANCEMENT Sixgill Feeds: The Sixgill Darkfeed™ Freemium, Sixgill Darkfeed™ Premium, Sixgill Deep Insights, and Sixgill Financial Threat Intelligence feeds have been renamed to Cybersixgill Darkfeed™ Freemium, Cybersixgill Darkfeed™ Premium, Cybersixgill Deep Insights, and Cybersixgill Financial Threat Intelligence, respectively. If you are a current user of any Sixgill feeds, you do not need to take any action. Your current feeds will continue to work. See Managing Premium Feeds and Activating Free Feeds for more information. |
5/26/2022 |
|
ENHANCEMENT STIX Export: STIX 2.0 exports now support an additional See Export for more information. |
5/25/2022 |
|
DOWNLOADS Anomali Lens: The latest version of the Anomali Lens plugin, v5.0.1, is available from the ThreatStream Downloads page. See Downloads for more information. |
5/25/2022 |
|
FEATURE Manage Dashboards: A new dashboard management screen allows you to show, hide, and search for your dashboards all in one place. See Managing Dashboards for more information. |
5/24/2022 |
|
FEATURE Anomali Lens Trending Widgets: Anomali Lens trending widgets now provide additional context and relevant news on trending entities. Additionally, there are new widgets that display data on trending MITRE attack patterns. Anomali Lens trending widgets are available to Anomali Lens+ users only. See Adding Anomali Copilot Trending Widgets to Custom Dashboards for more information. |
5/24/2022 |
|
ENHANCEMENT Streams: New Streams can only be visible to your organization and not to Anomali Community. See Importing Feeds Using Basic Submission for more information. |
5/24/2022 |
|
ENHANCEMENT Rules: Rules may now have up to 100,000 matches in a 24-hour period. See Rules for more information. |
5/23/2022 |
|
FEATURE Premium Feeds: Recorded Future subscribers can activate the Recorded Future Analyst Notes feed from the APP Store. See Managing Premium Feeds for more information. |
5/13/2022 |
|
DOWNLOADS ThreatStream Integrator: The latest feature release of ThreatStream Integrator, v7.3.1, is available from the ThreatStream Downloads page. See Downloads for more information. |
4/28/2022 |
|
ENHANCEMENT SSO: Added the ability to enable single sign-on (SSO) and ThreatStream user administration through integration with any SAML 2.0-compliant identity provider. See Enabling User Management with SAML 2.0 IDP Services for more information. |
4/28/2022 |
|
BETA RELEASE Feed Health: View the synchronization history of active feed sources listed in the APP Store from the last 30 days. See Subscribing to Anomali Feeds, Enrichments, and Intelligence Channels for more information. |
4/28/2022 |
|
ENHANCEMENT ThreatStream TAXII Client: The ThreatStream TAXII Client can now receive data from TAXII 2.0 and 2.1 servers. Additionally, collections from specific API Roots on TAXII 2.0 and 2.1 sites can be configured. See Using ThreatStream as a TAXII Client for more information. |
4/27/2022 |
|
FEATURE Indicator Type: Added the Compromised Username (compromised_username) indicator type. Compromised Usernames are of type String, and are therefore available on ThreatStream only. They are not available on Security Analytics or ThreatStream Integrator. See Indicator Types in ThreatStream for more information. |
4/27/2022 |
|
ENHANCEMENT Threat Model: Threat Model entity attachment uploads can now include up to 15 files at once. Further, all Threat Model entity types besides Signatures and TTPs can contain file attachments. See Attachments for more information. |
4/26/2022 |
|
DOWNLOADS ThreatStream Integrator: The latest feature release of ThreatStream Integrator, v8.0, is available from the ThreatStream Downloads page. See Downloads for more information. |
4/5/2022 |
|
ENHANCEMENT Import: The Included tab on the Import Review screen has been enhanced with a Confidence filter and an easy to use Exclude button. See Approving Import Jobs for more information. |
3/28/2022 |
|
DOWNLOADS ThreatStream OnPrem:The latest release of ThreatStream OnPrem, v5.3b, is available from the ThreatStream Downloads page. See Downloads for more information. |
3/29/2022 |
|
ENHANCEMENT Rules: Advanced search-based rules can now be configured to match Campaigns, Courses of Action, Identities, Incidents, Infrastructure, Intrusion Sets, Malware, Tools, and Vulnerabilities. Additionally, email notifications are sent when rules are automatically disabled by ThreatStream, even in cases where the Notify Me setting is disabled. See Rules for more information. |
3/28/2022 |
|
ENHANCEMENT Threat Model: An Investigations tab has been added to Threat Model entity details pages that lists associated investigations. See Investigations for more information. |
3/25/2022 |
|
ENHANCEMENT Dashboards: Rearrange the order of the dashboards on your home screen by dragging and dropping the dashboard tabs. See Dashboards for more information. |
3/24/2022 |
|
DOWNLOADS McAfee DXL Integrator Extension: The initial release of the McAfee DXL Integrator extension, v1.0, is available from the ThreatStream Downloads page. See Downloads for more information. |
3/16/2022 |
|
ANNOUNCEMENT The Anomali Platform: The Anomali Platform, a Cloud-Native XDR Solution, is a suite of products that work together and easily integrate into existing security stacks across multi-cloud, on-premises, and hybrid deployments, to deliver new uniquely differentiated XDR use cases. Contact your Anomali Customer Support manager for a trial and more information. See The Anomali Platform for more information. |
3/1/2022 |
|
FEATURE Enrichments: Added the Tenable.sc vulnerability management enrichment. See Enriching Data with Tenable Security Center for more information. |
2/28/2022 |
|
ENHANCEMENT Import: Added the ability to delete errored import jobs. See Deleting Import Jobs for more information. |
2/28/2022 |
|
ENHANCEMENT Enrichments: The HYAS Insight enrichment has been updated to v1.5.0. See Enriching Data with HYAS Insight for more information. |
2/28/2022 |
|
DOWNLOADS Anomali Lens: The latest version of the Anomali Lens plugin, v5.0.0, is available from the ThreatStream Downloads page. See Downloads for more information. |
2/25/2022 |
|
ENHANCEMENT Rules: Rules can now be configured based on advanced observable or Threat Model search queries. See Creating Rules for more information. |
2/23/2022 |
|
ENHANCEMENT Intelligence Initiatives: Add intelligence requirements, which function as secondary intelligence initiatives, to open intelligence initiatives. Additionally, import sessions and sandbox detonations can now be associated with intelligence initiatives. See Attributing Organizational Goals with Intelligence Initiatives for more information. |
2/22/2022 |
|
DOWNLOADS ThreatStream Splunk App: The latest version of the ThreatStream Splunk App, v6.5.7, is available from the ThreatStream Downloads page. See Downloads for more information. |
2/18/2022 |
|
DOWNLOADS ThreatStream Local Transforms for Maltego: The latest version of the ThreatStream Local Transforms for Maltego, v1.1.0, is available from the ThreatStream Downloads page. See Downloads for more information. |
2/18/2022 |
|
DOWNLOADS ThreatStream Integrator: The latest version of the Crowdstrike Falcon Integrator extension, v1.1, is available from the ThreatStream Downloads page. See Downloads for more information. |
2/9/2022 |
|
DOWNLOADS ThreatStream Integrator: The Elastic Integrator extension is now available under Certified Partner Integrator Extensions on the ThreatStream Downloads page. See Downloads for more information. |
2/9/2022 |
|
DOWNLOADS ThreatStream Splunk App: the latest version of the ThreatStream Splunk App, v6.5.6, is available from the ThreatStream Downloads page. See Downloads for more information. |
2/9/2022 |
|
ENHANCEMENT Integrator Status: The Integrator Status widget on the Weekly Summary dashboard has been updated with a new interface and displays additional information on the health of your integrations. See ThreatStream Integrator Summaries for more information. |
1/27/2022 |
|
ENHANCEMENT APP Store: A new Feed Health column on the APP Store list view displays the current status of your feed sources. See Subscribing to Anomali Feeds, Enrichments, and Intelligence Channels for more information. |
1/27/2022 |
|
FEATURE User Administration: A new Can Use Match permission enables organizations participating in the Security Analytics Cloud beta release to control which organization users have access to the Security Analytics user interface. See Managing Organization Users for more information. |
1/26/2022 |
|
FEATURE Enrichments: Added the Query.AI enrichment. See Enriching Data with Query.AI for more information. |
1/26/2022 |
|
ENHANCEMENT Import: When importing observables using the Scrape from URL option, a new setting enables you to automatically exclude email, domain, or URL observables that share a domain with the source URL. See Importing Observables for more information. |
1/24/2022 |
|
DOWNLOADS ThreatStream Splunk App: The latest version of the ThreatStream Splunk App, v6.5.5, is available from the ThreatStream Downloads page. See Downloads for more information. |
1/12/2022 |
|
DOWNLOADS QRadar App and Content Package: The latest versions of the QRadar App (3.0.0) and the QRadar Content Package (1.2.0) are available from the ThreatStream Downloads page. See Downloads for more information. |
1/5/2022 |