What's New in ThreatStream Next Gen

ThreatStream Next Gen is regularly updated with new features and enhancements. You can use this page to track most recent ThreatStream Next Gen updates and reference relevant articles in the online help center. For documentation only updates, refer to ThreatStream Next Gen Documentation Updates.

Note: Limited Availability indicates a feature or enhancement that is not available to all Anomali customers. Contact your Anomali Sales representative if you are interested in enabling it for your organization.
Update Date

ANNOUNCEMENT

Anomali Agentic SOC: Anomali Agentic SOC capabilities in Security Analytics (the Anomali Unified Security Data Lake) is now generally available. These capabilities help security teams automate and accelerate workflows from raw security telemetry through alert triage, incident investigation, and case management. AURA (Anomali Unified Response Agent), the orchestrator behind the Agentic Fleet and the agentic SOC Operations workflow, triages alerts, investigates incidents, and builds case narratives, reducing repetitive analyst effort while keeping analysts in control. When human review is required, agent recommendations are routed for review and approval with visibility into the supporting evidence, confidence, reasoning, and decision history.

See Security Operations Overview for more information.

Aug 31, 2026

ANNOUNCEMENT

Entity Management: The Entity Management capabilities unify identities and assets from identity and asset management providers such as Microsoft Entra ID, Google Workspace, Tenable, Qualys, scoring each for risk to surface high-risk users and machines instantly.

See Entity Management for more information.

Watch video

Aug 31, 2026

ENHANCEMENT

PIR: On the Output step of the PIR creation wizard, you can now choose to append PIR findings to an existing threat model instead of generating a new one after every PIR run. Each PIR run updates the selected threat model with the latest analysis and adds new associations while preserving existing ones.

See PIR: Output Step for more information.

Aug 5, 2026

ENHANCEMENT

PIR: The PIR History tab now includes a summary banner showing clickable counts for collected, tagged, and generated items. Clicking any count takes you directly to the corresponding filtered view.

See History Tab for more information.

Aug 5, 2026

ENHANCEMENT

PIR: The History tab displaying a per-run diagnostic log has been added to PIR details pages. Each log entry displays timestamped tool calls, result counts, and output delivery status, so you can see exactly what happened during any PIR execution.

See History Tab for more information.

Jul 23, 2026

ENHANCEMENT

PIR: The PIR creation wizard includes a new Output Tags option on the Description step. Output tags let you configure tags that are automatically applied to selected outputs generated by a PIR run.

See PIR: Description Step for more information.

Jul 15, 2026

ENHANCEMENT

Security Reports: Added support for tag creation and tag filtering in security reports. Reports generated by PIRs automatically receive an output tag containing the name of the PIR that generated them.

See Accessing Organization Reports for more information.

Jul 15, 2026

ENHANCEMENT

PIR (Limited Availability): Observables collected during PIR execution can be associated with the resulting threat model or investigation. This association can be enabled or disabled independently for each PIR output type, giving you control over which outputs carry these associations.

See PIR: Output Step for more information.

Jul 15, 2026

ENHANCEMENT

PIR (Limited Availability): The PIR creation wizard now includes the Collection Tags option on the Description step. Collection Tags let you configure tags that are automatically applied to observables, threat models, and investigations matched during PIR execution.

See PIR: Description Step for more information.

Jul 15, 2026

FEATURE

PIR: PIRs now have permission-based controls and per-PIR sharing. Organization Administrators can configure which users can create, edit, run, and delete PIRs. PIR owners can set individual PIRs to Private or grant Read or Write access to specific roles via the Manage Access feature.

See Managing Access to PIRs for more information.

Jun 24, 2026

ENHANCEMENT

Browser Support: ThreatStream Next Gen now supports Safari and Edge browsers.

See Supported Browsers for more information.

Jun 10, 2026

ENHANCEMENT

PIR: You can now configure a lookback window on the Inputs step of the PIR creation wizard, allowing the PIR to consider only intelligence records from the selected time range.

See PIR: Inputs Step for more information.

Jun 10, 2026

FEATURE

PIR: You can now set an expiry date on a PIR at creation time or by editing an existing PIR.

See PIR: Description Step for more information.

May 27, 2026

ENHANCEMENT

Command Center: Threat Landscape now covers 26 industry verticals combining STIX 2.1 and CISA critical infrastructure sectors. Select your vertical to see threats relevant to your industry.

See Command Center: Global Threat Landscape for more information.

May 27, 2026

ANNOUNCEMENT

ThreatStream Next Gen: ThreatStream Next Gen is now generally available, featuring a modernized platform experience with AI-powered capabilities, automated operations, and unified intelligence workflows that enable faster threat detection and response.

See ThreatStream Next Gen Overview for more information.

Apr 30, 2026