Anomali Release Notes – 2026.07.R2

Note: Major new features are released through a phased rollout and may take up to two weeks to become generally available. Bug fixes, parser updates, and minor UI improvements are typically available immediately upon deployment.

ThreatStream

New Features and Enhancements

  • The PolySwarm sandbox now supports scanning password-protected PDF files. (OP-41696)
  • The PolySwarm sandbox now displays the number of remaining detonations available. (OP-41601)
  • Added in-browser video playback for PolySwarm sandbox recordings on the Screenshots tab, including standard playback controls, a poster frame, and a graceful fallback to the existing download link for unsupported browsers. (OP-41635)
  • The Weekly Summary page now displays the Integrator Last Sync time in the user's local time zone instead of UTC. (OP-41638)

Fixed Issues

  • Fixed an issue where the cursor in the Investigation description editor would unexpectedly jump to the top of the text box while typing. (OP-41709)
  • Fixed an issue where malformed HTML in ingested emails could cause the Investigation view to become unresponsive. (OP-41712)
  • Fixed an issue where Anomali Threat Briefing PDF downloaded without a proper file name and .pdf extension. (OP-41668)
  • Fixed an issue where certain investigations could cause the page to go blank when adding or editing observables. (OP-41602)
  • Fixed additional cases where observables containing certain special characters failed to load or behaved inconsistently on import. (OP-41482)
  • Fixed an error that prevented configuring a TAXII feed when polling certain collections on an interval. (OP-41722)

Security Analytics – Search, Dashboards, and Alerts

New Features and Enhancements

  • The Field Summary panel in Search now surfaces all OCSF fields for the relevant event categories when querying OCSF-normalized data, giving full visibility into parsed log data and making it easier to build and refine searches. (MATCH-24732)

Fixed Issues

  • Fixed an issue where certain OCSF Turbosearch queries with timechart aggregations could fail with a "maximum recursion depth exceeded" error. (MATCH-24851)
  • Resolved an issue where full text Search queries were slower than expected, particularly when searching over multi-day time ranges. (MATCH-24040)
  • Fixed an issue where the Natural Language (NLP) to Anomali Query Language (AQL) conversion feature failed to translate queries. NLP now correctly recognizes current source type names and supports both default and user-created views. (MATCH-21917)

Feeds

New Features and Enhancements

  • Added the engine for the new premium feed, Google Threat Intelligence - Live Yara Rule Hunting. (FD-23690, FD-23689, FD-23971)
  • In the Check Point Exposure Management IoC Intelligence feed, the Tenant ID field now accepts either the tenant slug or the full Argos Tenant URL, aligning with the existing Check Point Exposure Management IoC Feed. (OP-41726)

Fixed Issues

  • Fixed an issue where victim incidents from the Ransomware.live feed did not set a structured target location and industry, using a plain text tag instead. Incidents can now be filtered by target country and shown on the map. (FD-23911)
  • Fixed RSS feed sources that were being blocked by web application firewalls due to outdated browser identification. Affected feeds now successfully ingest content. (FD-23541)
  • Updated dependencies to resolve installation conflicts. (FD-23923)

ThreatStream Next Gen

New Features and Enhancements

  • Added a History tab to PIR generated outputs, providing a per-run diagnostic log with timestamped tool calls and output results. (STAR-125, STAR-138)
  • Improved permission handling for the PIR module's tool integration flow. (STAR-220)
  • The PIR landing page and other tables now display timestamps in the user's local time zone instead of UTC. (STAR-226)

Fixed Issues

  • Fixed an issue where creating a new PIR could fail with an API error. (STAR-237)
  • Fixed a table alignment issue in PIR email notifications. (STAR-251)
  • Fixed an issue where ThreatStream Next Gen chat could lose context or become unresponsive mid-conversation. (STAR-239)
  • Fixed an issue where PIR-generated reports could include activity timelines outside the requested date range. (STAR-253)

Anomali Release Notes – 2026.07.R1.1

Note: Major new features are released through a phased rollout and may take up to two weeks to become generally available. Bug fixes, parser updates, and minor UI improvements are typically available immediately upon deployment.

ThreatStream Next Gen

New Features and Enhancements

  • Added tag filtering support for security reports. (STAR-227)
  • PIR output tags can be applied to generated security reports and used to filter reports in Intelligence Search and AQL queries. (STAR-184)
  • Added the ability to associate observables collected during PIR execution with the generated threat model, investigation, or case, with an option to enable or disable this per output type. (STAR-194)
  • Added Output Tags to the PIR creation wizard, allowing you to configure tags that are automatically applied to outputs generated by a PIR run. (STAR-193)
  • Added Collection Tags to the PIR creation wizard, allowing you to configure tags that are automatically applied to observables, threat models, and investigations matched during PIR execution. (STAR-192)

Fixed Issues

  • Fixed an issue where AI-powered suggestions for tags, keywords, and analytical processes during PIR setup would fail to generate when a longer description was entered. (STAR-238)
  • Fixed an issue on the Command Center Dashboard where organizations unrelated to a given industry vertical were incorrectly listed under Targeted Organizations for that vertical. (AI-1243)

Anomali Release Notes – 2026.07.R1

Note: Major new features are released through a phased rollout and may take up to two weeks to become generally available. Bug fixes, parser updates, and minor UI improvements are typically available immediately upon deployment.

ThreatStream

New Features and Enhancements

  • Added support for the Zscaler cloud configuration parameter so that customers on non-production Zscaler environments (for example, zscalerbeta) would be able to authenticate and push observables correctly. (OP-41526)
  • Renamed the settings option previously labeled "Search," which redirected users to UI theme preferences, so its name more accurately reflects its function and reduces confusion for analysts. (OP-41599)

Fixed Issues

  • Fixed an issue where sandbox error messages were not displayed in the UI when a Polyswarm detonation failed but the scan completed successfully. Additionally, fixed a case where sandbox submissions that failed during polling with an unrecognized status would show an error state with no accompanying message. (OP-41535)
  • Discontinued the Rapid7 InsightVM vulnerability enrichment integration. The integration tile will be removed from the App Store. Customers with an active InsightVM configuration do not need to take action; data syncing will stop automatically. (OP-41500)
  • Added App Store tiles for the Kaspersky Crimeware Hash and Kaspersky Crimeware URL feeds. (OP-41621)
  • Fixed an issue where clicking the "+" button to manually add an observable to an investigation could cause the screen to go blank, requiring the user to navigate back or refresh the page to recover. (OP-41602)
  • Resolved a logging issue during email ingestion where the logging context (organization ID and import session) from a previously processed email could persist and appear against a subsequent email, resulting in inaccurate log context for troubleshooting. (OP-41467)
  • Fixed an issue where the Import Source column on the Observables page displayed no value for observables manually imported through the ThreatStream UI, even though the import source was correctly stored and visible via advanced search filtering and CSV export. (OP-41600)
  • Fixed an issue where the Cognyte Luminar integration tile incorrectly displayed an Assets tab (Domains, Executives, Mobile Apps) that does not apply to this integration. (OP-41618)

Security Analytics, Search, Dashboards, and Alerts

New Features and Enhancements

  • The streamstats operator now supports the dc (distinct count) aggregation function, enabling you to count unique values over a sliding window of events. This is particularly useful for building more accurate detection rules. A new parameter, window with value (between 1 and 50) is required when using dc with streamstats to ensure consistent query performance. Unbounded windows (window=0) are not supported.(MATCH-23589)
  • Introduced support for ingesting Mimecast cloud logs into Security Analytics via the Mimecast API 2.0 integration, enabling customers to monitor and analyze Mimecast email security events alongside other data sources. (MATCH-17044)

Fixed Issues

  • Resolved an issue where using isnotnull() / isnull() on OCSF struct/object fields (for example, process.file) would cause the timeline histogram to fail while search results returned normally. (MATCH-24754)
  • Previously, when using the OCSF schema, the Raw view displayed a message field that was null for most events. The Raw view now displays the raw_data field for OCSF schema events, providing meaningful and usable content in your search results. (MATCH-24733)
  • Resolved an issue where performing a drill-down action on an extracted field that contained brackets ([]) in its name would result in a UI error instead of executing the search. (MATCH-23887)
  • Fixed the append feature issues in lookup tables. (MATCH-24651, MATCH-24213, MATCH-23133)
  • Fixed an issue where expanding an event returned by the ocsf operator did not display additional event details. (MATCH-24734)

Feeds

New Features and Enhancements

  • Added support for ingesting all Google Threat Intelligence report types, including historical data. (FD-23593)
  • Improved the Feeds SDK to support richtext formatting for body descriptions across all supported threat model types. (FD-23537)
  • Improved the RansomwareLive feed to clearly display recent victim organizations, making it easier to identify potentially affected entities. (FD-23413)
  • Added Kaspersky Crimeware intelligence feeds and threat collections, providing coverage of crimeware activity and associated threat indicators. (FD-23162)

Fixed Issues

  • Fixed a SpyCloud feed ingestion timeout that occurred when processing large date ranges. Feeds now poll data incrementally, allowing successful ingestion of historical data. (FD-23609)
  • Anomali Curated RSS OSINT Threat Bulletins now render the full article content instead of only a headline link and source name. (FD-23415)

ThreatStream Next Gen

Fixed Issues

  • Fixed an issue where AI-powered suggestions (tags, keywords, and analytical process) in PIR creation Steps 2 and 3 would fail to generate when a larger description was submitted. (STAR-238)

Anomali AI

New Features and Enhancements

  • Introduced ThreatStream MCP endpoint with OAuth authentication support that lets customers connect external AI clients to the Anomali platform (In preparation for the future release). (AI-1017)

Fixed Issues

  • Fixed an issue where non-relevant companies (for example, transportation and automotive organizations) were incorrectly listed under unrelated industry verticals in the Targeted Organizations widget on the NextGen Command Center Dashboard. (AI-1243)

Anomali Release Notes – 2026.06.R2

Note: Major new features are released through a phased rollout and may take up to two weeks to become generally available. Bug fixes, parser updates, and minor UI improvements are typically available immediately upon deployment.

ThreatStream

New Features and Enhancements

  • Added JA4 TLS fingerprint as a new supported observable indicator type (ja4_tls_fingerprint), extending ThreatStream's fingerprinting coverage beyond the existing JA3 MD5 type. (OP-41517)
  • Workgroups assigned to Actor threat models can now be removed or reassigned after the threat model is created. Previously, once a workgroup was added to a threat Actor, it could not be changed or removed, even before the threat model was published. (OP-38061)
  • Added a new Anomali PDRP Takedown Service integration to the App Store, enabling to submit takedown requests for malicious domains, URLs, and IPs detected by the new Anomali PDRP service. (OP-41495)
  • The new Anomali PDRP service is now generally available to all customers and supports self-service onboarding. (OP-41512)
  • Updated the logo and name of the new Anomali PDRP service. The new name is Anomali PDRP Enhanced. (OP-41529)
  • Implemented rate limiting on MCP API Endpoints to improve platform stability. Without rate limiting, unbounded concurrent requests could exhaust available workers; per-user and per-organization request quotas are now enforced. (OP-41439)
  • Updated the Flashpoint VulnDB v2 (Ignite API) enrichment integration in the App Store to keep vulnerability intelligence ingestion compatible with Flashpoint's API platform migration. (OP-41519)
  • Updated the Domain Tools Iris enrichment version. (OP-41218)
  • Added a new tile to the App Store for the RPiList Malware open-source feed that tracks domains associated with malware distribution. (OP-41550)
  • Added a new tile to the App Store for the URLhaus Hostfile open-source feed. The URLhaus feed provides a high-fidelity list of domains used for malware distribution in hostfile format, suited for DNS filtering, threat hunting, and incident response. (OP-41549)

Fixed Issues

  • Fixed an issue where password-protected PDF files containing the @ character in their password failed during detonation in Joe Sandbox. Passwords with the @ character are now handled correctly. (OP-41509)
  • Fixed an issue where SSO-only users could not access Priority Intelligence Requirements (PIRs), including non-admin users, due to missing SSO identity mapping in the PIR role-based access control configuration. (OP-41598)

Security Analytics, Search, Dashboards, and Alerts

New Features and Enhancements

  • Introduced the OCSF Category Field Panel in Event Search — a new contextual sidebar that surfaces OCSF v1.2.0 schema fields organized by category (System Activity, Findings, IAM, Network Activity, Discovery, and Application Activity). (MATCH-24334)
  • Added a cumulative response size guard to the superapi_call and tsapi_call user-defined functions to prevent runaway queries from exhausting available memory when API endpoints return large per-row responses. The response size budget key is also reset before each ensuring stale counters from prior invocations do not incorrectly block valid re-invocations triggered by HTTP timeouts. (MATCH-24650, MATCH-24737)

Fixed Issues

  • Fixed an issue where OCSF full-text search using the ocsf '...' syntax silently dropped approximately 100,000 events near UTC day boundaries. Affected events are now included correctly in search results. (MATCH-24710)
  • Fixed an issue where MSSP columns were absent from the Common Table Expression (CTE) projection in the OCSF query path, causing a COLUMN_NOT_FOUND error for organizations with MSSP enabled. The managed_customer_id and related MSSP columns are now correctly included. (MATCH-24635)
  • Fixed an issue where the "Modified by" column was not populated when users with MSSP enabled updated lookup tables. The column now correctly reflects the identity of the user who made the change. (MATCH-24477)
  • Resolved memory-related crashes in coordinator pods caused by large API response payloads. A streaming-based approach now replaces the prior buffered model for external API calls, significantly reducing peak memory consumption. (MATCH-24456)

Feeds

New Features and Enhancements

  • Improved the Doppel premium feed ingestion with native engine conversion. (FD-23303)
  • Updated the Ransomfeed - Real-Time Ransomware Intelligence open-source feed to support Copilot source extraction feature. (FD-23233)
  • Added a new open-source feed, URLhaus Hostfile. The feed delivers a hostfile-format list of domains associated with malware distribution, suitable for DNS filtering, threat hunting, and rapid incident response. (FD-23542)
  • Updated the Cognyte premium feed, completing the migration of this integration to the current feed engine for improved reliability and maintainability. (FD-20832)
  • Migrated the Flashpoint VulnDB feed integration from the standalone VulnDB API to the Flashpoint Ignite vulnerability intelligence endpoints, in advance of Flashpoint's deprecation of the original VulnDB API. The underlying vulnerability data is unchanged; only the delivery mechanism has been updated. (FD-23005)
  • Updated the Recorded Future Analyst Notes feed integration to version 2.2.0, incorporating the latest changes from Recorded Future's API. (FD-23477)

Fixed Issues

  • Resolved intermittent 500 Internal Server Error responses from the Google Threat Intelligence (GTI) API affecting multiple feeds. Error handling and retry logic have been improved to reduce ingestion failures caused by transient GTI API errors. (FD-23092)
  • Resolved a no-results condition affecting the Zscaler Deception commercial feed (feed ID 9779) on the US Cloud environment. The feed now ingests data correctly. (FD-23345)

ThreatStream Next Gen

New Features and Enhancements

  • PIRs now have permission-based controls and per-PIR sharing. Organization Administrators can configure which users can create, edit, run, and delete PIRs. PIR owners can set individual PIRs to Private or grant Read or Write access to specific roles via the Manage Access feature. (STAR-124)
  • PIR default schedules now use the user's local time at the moment of creation instead of a hardcoded top-of-hour value. This distributes PIR execution times naturally across the clock, preventing simultaneous runs that could overwhelm backend infrastructure when many PIRs share the same default schedule. (OP-41543)

Anomali Release Notes – 2026.06.R1

Note: Major new features are released through a phased rollout and may take up to two weeks to become generally available. Bug fixes, parser updates, and minor UI improvements are typically available immediately upon deployment.

ThreatStream

New Features and Enhancements

  • Added a self-service Assets management page to the new PDRP feed. Organization administrators can now configure and manage monitored assets such as domains, social media profiles, and mobile apps without requiring Anomali Customer Support intervention. (OP-41337, OP-41137)
  • Added a "Search By" filter option in the Import assistant Associations modal. Users can now choose between "All Fields" (the default, which searches names, aliases, tags, and body content) or "Name Only" for more precise threat model search results. (OP-41398)
  • Zscaler integration now supports ATP Malicious URLs as a target list, in addition to the existing custom URL category. Existing integrations are unaffected and continue to write to a custom URL category. (OP-41097)

Fixed Issues

  • Fixed an issue where the source field on Threat Bulletins created via the API was not displayed correctly in the threat models table, and the publication status was not honored. (OP-39901)
  • Fixed an HTTP 403 Forbidden error that occurred during TAXII poll operations. (OP-41257)

Security Analytics, Search, Dashboards, and Alerts

New Features and Enhancements

  • Added OCSF schema enhancements with view definitions and role-based access control, enabling role-based visibility into OCSF data. (MATCH-24479)
  • Added support for selecting between Standard and OCSF schemas when configuring Views, including dynamic category and field filtering based on the selected schema. (MATCH-24145)

Fixed Issues

  • Fixed an issue in MSSP Alert Triage where selecting multiple organizations caused filter fields to be duplicated for each organization instead of being aggregated into a single unified filter view. (MATCH-24380)
  • Fixed an out-of-memory error when running yieldtable over large OCSF result sets (more than 200,000 objects). Large yields now complete successfully without exhausting memory. (MATCH-24378)
  • Fixed an issue where using calc to assign a value to a field that already existed as a nested or complex field in the OCSF schema (for example, calc user = user.name) caused downstream operators to produce empty or incorrect results. The parser now correctly uses actual output types after calc transformations rather than the original schema types. (MATCH-24368)
  • Fixed an issue where OCSF iocmatch_ocsf queries that use a subsearch (such as appendtable) became stuck in a queued state and never returned results. (MATCH-24336)
  • Fixed an issue where OCSF turbosearch timechart queries were queued instead of executing on the turbosearch fast path. (MATCH-24260)
  • Fixed an issue in MSSP mode where the order of organizations selected in the organization drop-down affected query results when multiple organizations were selected. (MATCH-24065)

Feeds

New Features and Enhancements

  • CrowdStrike threat reports now include MITRE ATT&CK technique associations, providing enhanced context for threat actor tactics and techniques. (FD-18122)
  • Added a new open-source feed, Real-Time Ransomware Intelligence. The feed provides real-time monitoring of ransomware group activities and victim disclosures from leak sites, tracking more than 92 active groups across more than 110 countries with threat actor attribution and stolen data volume metrics. (OP-41450)
  • Added a new premium feed, Check Point Exposure Management IoC Intelligence. The feed provides real-world threat data from global firewalls, Threat Emulation, and email security, with every indicator representing a confirmed attack blocked by ThreatCloud AI. (OP-41378)
  • Added the following Intel 471 premium feeds to support Verity API: Watcher Alerts, Credential Intelligence, Malware Intelligence, Vulnerability Reports, Spot Reports, Information Reports, Geopolitical Reports, FINTEL Reports, and Breach Alerts. These feeds provide access to Intel 471 intelligence covering threat actors, malware families, compromised credentials, vulnerabilities, breaches, and geopolitical developments. (OP-41431, OP-41430, OP-41428, OP-41427, OP-41426, OP-41425, OP-41424, OP-41423, OP-41422, FD-22868)
  • Added new Anomali premium feeds: Anomali Early Warning Alerts, which provides real-time alerts when initial access brokers offer access to your organization on underground forums and marketplaces; Anomali Credential Monitoring, which delivers compromised credential intelligence sources from underground markets and threat actor activity; and Anomali C2 Detection, which identifies active command-and-control servers and infrastructure associated with your IP space to support proactive blocking of C2 communications. (OP-41362, OP-41086, OP-41363, FD-23030, FD-23027)
  • Added a new premium feed, Doppel. The feed provides intelligence from Doppel covering brand impersonation, phishing infrastructure, and related external risk signals to support detection, investigation, and response workflows. (OP-41096)

Fixed Issues

  • Fixed an API Data structure validation issue that was causing feed ingestion errors. (FD-23457)

  • Fixed the Mandiant feed parsing issue on EU Cloud to correctly extract nested content elements and restore normal ingestion of Mandiant research indicators. (FD-23441)

  • Fixed rendering issues with Google Threat Intelligence reports. (FD-23274)
  • Fixed ThreatGrid Sandbox domain confidence scoring to correctly use vendor risk scores. (FD-23253)
  • Fixed Pydantic validation errors in Recorded Future Alerts feeds caused by an API change that returns risk context objects without a score field. The feeds now handle the missing field gracefully by using default values. (FD-23203)
  • Fixed an AttributeError in MISP feed processing when event objects contain unexpected string values in the object UUID field. (FD-23201)
  • Fixed a TypeError in Digital Shadows threat model ingestion when location data is returned as objects rather than strings. (FD-23196)

ThreatStream Next Gen

New Features and Enhancements

  • Added support for the PIR expiry_date field in the MCP tools. (STAR-126)
  • Added the Lookback Window setting to the PIR creation wizard's Inputs step (Step 2) that enables PIRs to consider only intelligence records from the selected time range. (STAR-143)

  • Added support for Safari and Edge browsers in ThreatStream Next Gen, achieving browser compatibility parity with classic ThreatStream. (STAR-160)

Anomali Release Notes – 2026.05.R2

Note: Major new features are released through a phased rollout and may take up to two weeks to become generally available. Bug fixes, parser updates, and minor UI improvements are typically available immediately upon deployment.

ThreatStream

New Features and Enhancements

  • Added support for the Zscaler OneAPI in the ThreatStream Zscaler integration. The updated integration supports the new OneAPI endpoint as well as the legacy Zscaler API. (OP-40741)
  • Joe Sandbox integration now supports password-protected PDF file submissions. (OP-41394)

Security Analytics, Search, Dashboards, and Alerts

New Features and Enhancements

  • Added resource tagging support for Saved Searches, Alerts, Macros, Lookup Tables, Views, and Reports. Users can apply tags and filter by tags on each resource type, and bulk edit tags and permissions across multiple selected resources at once. (MATCH-23496, MATCH-23498, MATCH-23499, MATCH-23502, MATCH-23505, MATCH-23508, MATCH-23847, and MATCH-23852)
  • Extended RBAC to support the OCSF schema. Organization administrators can now define role-based access controls using OCSF schema fields in addition to the standard (eventlog) schema. (MATCH-23710)
  • Updated the role UI to include a schema selector (Standard / OCSF). When OCSF is selected, the interface constructs the appropriate match_filter using OCSF field definitions. (MATCH-24146)
  • Extended OCSF schema support in Lookup Tables to include OBJECT (nested struct) fields. Users can now create and read lookup tables that include complex OCSF fields and their nested field structure as source columns. (MATCH-23702)
  • Added a tag filter control to the Saved Search list page. The filter dropdown displays only tags visible to the current user (owned or shared to org), supports multi-select, and applies AND logic across selected tags. (MATCH-23498)
  • Added a customizable file suffix option for scheduled reports. Users can now select a field from the report's associated lookup table to append to the output filename, making it easier to distinguish files generated with different parameter sets. (MATCH-23440)
  • Improved the determinism of the timechart operator's bucket calculations. The timechart operator no longer rationalizes bucket intervals, ensuring consistent and predictable bucket counts required for building machine learning models. (MATCH-22989)

Fixed Issues

  • Resolved an issue where applying or updating resource tags via the API returned HTTP 400 or HTTP 500 errors for Saved Searches, Lookup Tables, Macros, Alert Rules, Views, and Reports. (MATCH-24466)
  • Fixed a race condition in OCSF Correlation that caused data corruption in the iocmatch_ocsf and tmmatch_ocsf Iceberg tables due to concurrent INSERT and VACUUM operations. (MATCH-24436)
  • Resolved an issue where OCSF turbosearch returned different results than a standard where filter for equivalent queries. (MATCH-24435)
  • Fixed an issue in OCSF Correlation where match counts showed zero results due to an incorrect bucket location reference in the correlation message. (MATCH-24420)
  • Fixed an issue where iocmatch_ocsf queries containing a subsearch (for example, using appendtable) were queued indefinitely and never returned results. (MATCH-24336)
  • Resolved an issue where Security Analytics dashboards appeared empty for EU SaaS deployments. (MATCH-24265)
  • Fixed a critical issue where a single malformed crontab schedule entry containing double spaces caused the entire scheduler service to stop, preventing all periodic tasks from executing. (MATCH-24104)
  • Resolved a search error that occurred when a natural language query included semantic date range expressions such as "events between two dates." (MATCH-24094)
  • Fixed an issue where lookup tables and dashboards did not return data when an MSSP parent organization (not in Restricted Fields mode) queried data for a child organization that was in Restricted Fields mode. (MATCH-24059)
  • Resolved a conflict in AQL where the rex operator's regex named capture groups collided with OCSF struct field names (for example, a capture group named job conflicting with the OCSF job struct field), causing the command to fail. (MATCH-23919)

Feeds

New Features and Enhancements

  • Added a new open-source feed, RansomLook.io - Ransomware OSINT Feed. This feed tracks ransomware group leak sites, updating every two hours, and provides structured threat intelligence including victim listings, ransomware group profiles, and cryptocurrency wallet data under a CC BY 4.0 license. (FD-23042)
  • Added a new open-source feed, TweetFeed. This feed aggregates IOCs (URLs, domains, IPs, SHA256, and MD5 hashes) shared by security researchers on Twitter/X, providing real-time community-curated threat intelligence. (FD-22890)
  • Added a new open-source feed, Anomali Dark Web Intelligence. This feed delivers observables from dark web sources including infrastructure, malware, and adversary tooling. (FD-23012, OP-41314)
  • Added a new open-source feed, Anomali Threat Briefings. This feed delivers rapid-response analyst briefings on emerging threats, zero-days, and active campaigns. (FD-23261, OP-41364)
  • The Cyberint feed has been renamed to Check Point Exposure Management IoC Feed and updated with the new Check Point branding. The feed delivers IOCs sourced from OSINT and deep/dark web sources, with risk scores via a daily feed and query API. (OP-41441)
  • Added a new Domain Tools Iris enrichment source. The updated enrichment submission has been security reviewed, functionally tested, and certified for use in ThreatStream. (OP-41218)
  • Updated PDRP Threat Bulletin titles to follow a descriptive format of [Service Type]: [Alert Title] - [UUID] for improved customer clarity. Internal "ss" tag prefixes have been removed from customer-visible tags. (FD-23087)
  • Added CIDR type mappings to the new Feeds page. When a feed is configured to ingest CIDR-type observables, the appropriate itype mappings (such as mal_ipcidr, mal_ipv6cidr) are now correctly applied, ensuring observables are classified and enriched accurately. (OP-41344)

  • Extended MISP feed ingestion to populate three additional fields: Locations, Source Locations, and Target Industry enriching indicator context for MISP-sourced intelligence. (FD-19050)

Fixed Issues

  • Fixed a bug in the Google Threat Intelligence (GTI) feed where inconsistent ordering in the list formatting logic caused unnecessary Threat Model body updates during ingestion. (FD-23213)
  • Resolved HTTP 400 errors in the Mandiant DTM feed (feed 10854) that occurred when creating incidents in ThreatStream due to a payload structure incompatibility with the ThreatStream incident API. (FD-23211)
  • Improved the ThreatFox OSINT feed update logic to correctly handle single-indicator updates within a 24-hour window, preventing indicators from being skipped or duplicated during incremental refreshes. (FD-19426)
  • Fixed an issue in the Google Threat Intelligence (GTI) feed where tags generated during ingestion exceeded the maximum allowed tag length, causing ingestion errors. (FD-23195)

ThreatStream Next Gen

New Features and Enhancements

  • Expanded the Command Center Threat Landscape from 16 industry verticals to 26, incorporating verticals from STIX 2.1, CISA, and the Legal sector. Industry vocabulary has been aligned platform-wide to eliminate mapping losses between data model values and what is displayed in Command Center. (STAR-127, STAR-140)
  • Added expiry date support for Priority Intelligence Requirements (PIRs). Users can now set an expiry date on a PIR at creation time or by editing an existing PIR. When the expiry date is reached, the PIR automatically transitions to the Paused status and stops running on its schedule. Expiry dates are configurable via the UI and API. (STAR-131, STAR-130).

Anomali Release Notes – 2026.05.R1

Note: Major new features are released through a phased rollout and may take up to two weeks to become generally available. Bug fixes, parser updates, and minor UI improvements are typically available immediately upon deployment.

ThreatStream

New & Enhanced Features

  • Analysts can now export entities from an Investigation to an existing Threat Model, in addition to creating a new one. Only entities not already associated with the selected Threat Model are added, preventing duplicates. (OP-40747)
  • Added support for the Anomali PDRP Service (New) entitlement. When enabled, the integration tile appears in the App Store with its associated configuration and dashboard; when not entitled, the tile and related surfaces are hidden. (OP-41122)

Fixed Issues

  • Resolved an issue where screenshots for suspicious domains were not rendering within Threat Bulletin details in the PDRP dashboard, and clicking the associated links redirected users back to the dashboard instead of displaying the expected screenshot. (FD-23114)

Security Analytics, Search, Dashboards, and Alerts

New & Enhanced Features

  • Lookup tables now support OCSF OBJECT (nested) fields, allowing users to create lookup tables that include complex OCSF fields and their nested field structure as source columns. (MATCH-23702)
  • Users can now configure a custom field from a lookup table to be appended to scheduled report filenames, making it easier to identify which parameter set each output file corresponds to. When not configured, files continue to use the existing naming convention of dashboard name and timestamp. (MATCH-23440)

Fixed Issues

  • Resolved an issue where MSSP parent organizations could not retrieve search results or dashboard data from child organizations under certain configurations. (MATCH-24059)
  • Resolved an issue where the AQL rex command failed when a named capture group conflicted with an existing OCSF struct field of the same name, causing errors or incorrect results. (MATCH-23919)

Feeds

New & Enhanced Features

  • Added an APP Store tile for the new open-source feed, RansomLook.io - Ransomware OSINT Feed, providing ransomware threat intelligence tracking active leak site posts, ransomware group activity, and victim data across multiple ransomware campaigns. (OP-41284)
  • Added proxy support to the Feed SDK, allowing feed integrations operating behind a corporate proxy to connect successfully to external feed sources. (FD-22841)

Fixed Issues

  • Resolved an issue where the ThreatGrid Sandbox feed reported an incorrect source confidence value for certain observables, causing the displayed confidence to not reflect the score from the originating analysis. (FD-23049)
  • Resolved an issue where feed failures would occur when running multiple feeds sequentially on ThreatStream OnPrem. (FD-22812)
  • Resolved an issue where feed configurations could not parse CIDR address ranges, preventing IPv4 and IPv6 CIDR-formatted observables from being ingested through advanced feed configurations. (FD-22313)
  • Resolved an issue where the Google Threat Intelligence integration was not fetching all available report content, and certain fields such as analyst commentary were missing or incorrectly rendered in ThreatStream. (FD-23112)

ThreatStream Next Gen

New & Enhanced Features

  • Delivered interface improvements across multiple ThreatStream Next Gen modules, including Intelligence Search, Priority Intelligence Requirements, Case Management, Reporting, Integrations Marketplace, and Dashboard, providing a more consistent experience across these areas. (STAR-25, STAR-27, STAR-29, STAR-30, STAR-31, STAR-32, STAR-33, STAR-34, STAR-35, STAR-43, STAR-44, STAR-120, STAR-122)

Anomali Release Notes – 2026.04.R2

Note: Major new features are released through a phased rollout and may take up to two weeks to become generally available. Bug fixes, parser updates, and minor UI improvements are typically available immediately upon deployment.

ThreatStream

New & Enhanced Features

  • Added support for the search_filter parameter on the threat model search API endpoint, enabling API users to apply saved search filters when querying threat model objects, including Actors, Campaigns, Malware, TTPs, Vulnerabilities, Threat Bulletins, Signatures, Incidents, Attack Patterns, Intrusion Sets, Tools, Infrastructure, Identities, and Courses of Action, consistent with how saved searches work on the intelligence endpoint. (OP-41162)

Fixed Issues

  • Fixed a display formatting issue with WHOIS enrichment data on observable details pages, where the enrichment output was rendering as raw HTML markup instead of the intended structured, human-readable format. (OP-41172)

Security Analytics, Search, Dashboards, and Alerts

New & Enhanced Features

  • Enhanced the AQL whois operator to automatically parse key WHOIS fields, including creation date, domain name, domain status, name server, and registrant name, into individual output columns alongside the existing raw whois_data column, enabling analysts to filter, aggregate, and build detections on structured domain registration attributes without manual parsing. (MATCH-23329)
  • Added support for an optional custom file name suffix for scheduled reports. Users can select a field from a lookup table to append to the report file name in the format <dashboardname>_<CustomSuffixFieldValue>_<timestamp>, helping users identify which export corresponds to a specific parameter set. (MATCH-23440)
  • Completed a set of pending improvements and stability fixes for OCSF support, covering multiple AQL operators and query behaviors from Phase 1. (MATCH-23764)

Fixed Issues

  • Fixed the AQL inlist operator, which failed with an internal error when using table reference syntax to check field values against a column in a lookup table. (MATCH-23730)
  • Fixed the AQL sparkline aggregation function, which was returning a generic error for all queries. The operator now correctly generates inline time-series data grouped by the specified field. (MATCH-23729)
  • Fixed the AQL aggr count(distinct ...) function, which was returning no results when used with dotted OCSF field names even when matching data existed. (MATCH-23713)
  • Fixed an issue where the search result export returned incomplete data for large result sets. Queries returning more than approximately 10,000 records were being truncated during export even when the full result set was available in the UI. (MATCH-23691)

Feeds

New & Enhanced Features

  • Added an APP Store tile for the new open-source feed, TweetFeed, providing observables shared by the information security community on X/Twitter, including URLs, domains, IPs, and file hashes. This real-time, multi-type feed is curated by active security researchers. (OP-41202)
  • Added a new open-source feed, PhishDestroy, providing a community-powered blocklist of phishing and scam domains updated in real time, suited for DNS filtering and threat hunting. (OP-41201, FD-22889)
  • Added a new open-source feed, PhishHunt.io - Active Phishing Blocklist, providing a real-time feed of active phishing URLs targeting brand impersonation with full URL paths and brand context, suited for phishing detection, SOC alerting, and threat hunting. (OP-41199, FD-22666)
  • Added a new open-source feed, ShadowWhisperer Malware Blocklist, providing a community-maintained blocklist of malware domains, browser hijackers, and phishing sites with low overlap with existing OSINT sources, suited for DNS blocking, network defence, and threat hunting. (FD-22661)
  • Restored Bitdefender co-branded feeds in the App Store following completion of the partner agreement renewal. (OP-41248)
  • Added support for parsing CIDR addresses, including both IPv4 and IPv6 ranges, from advanced feed configurations, enabling feeds that provide network ranges in CIDR notation to be ingested correctly. (FD-22313)
  • Updated the SpyCloud v3 feed engine conversion to ensure continued compatibility and accurate data ingestion. (FD-22740)

Fixed Issues

  • Resolved an issue affecting a commercial feed on the US Cloud that was preventing successful ingestion runs. (FD-22913)

Anomali Copilot

Fixed Issues

  • Fixed an issue where Anomali Copilot did not highlight all detected URLs when scanning a PDF document. Affected URLs were identified in the sidebar but not highlighted inline in the document view. Additionally resolved a related issue where detected URLs were being truncated in the results list. (AI-1014)

Anomali Release Notes – 2026.04.R1

Note: Major new features are released through a phased rollout and may take up to two weeks to become generally available. Bug fixes, parser updates, and minor UI improvements are typically available immediately upon deployment.

ThreatStream

New & Enhanced Features

  • Added service provider initiated single sign-on (SSO) support directly from the secondary ThreatStream login page. Users can now enter their email address to trigger the SSO flow without relying solely on IdP-initiated sign-in through their identity provider portal. (OP-40243)
  • Added EPSS Score and EPSS Percentile to Vulnerability Details pages, along with new EPSS-based Vulnerability filtering in basic search. (OP-40777, OP-40864)
  • Increased the frequency of investigation lookup table generation to three times per day. (OP-40984)
  • Added a new PDRP self-service feed to the App Store, enabling users to activate the tile using an API key obtained by contacting Anomali Support. (OP-41136)
  • Added the following new indicator types: malware-associated ports (mal_port), compromised ports (compromised_port), and compromised passwords (compromised_password). (OP-41041, OP-41042, OP-41043)
  • Added a new App Store tile in preparation for the ShadowWhisperer Malware Blocklist open-source feed. (OP-41053)
  • Added a new App Store tile in preparation for the Anomali Curated RSS OSINT feed. (OP-41039)
  • Added a new App Store tile in preparation for the Cognyte: Luminar IOCs, Leaked Credentials and AI Cyber Feeds premium feed. (OP-41007)
  • Enhanced the Takedown service experience with workflow and usability improvements, including more robust validation and clearer request handling. (OP-41114)

Fixed Issues

  • Fixed an issue where some audit-log rows could display incorrectly. (OP-41101)
  • Fixed an issue where underscores in email investigation details could appear with unintended escaping. (OP-41069)
  • Resolved multiple dark mode display issues across modals and dashboards to improve readability and layout. (OP-40939)
  • Fixed an issue where certain observables containing special characters could fail to open in the details view. (OP-40838)

Security Analytics, Search, Dashboards, and Alerts

New & Enhanced Features

  • Introduced resource tag management, including the ability to create, rename, merge, and delete tags. (MATCH-23485)
  • Added dashboard tagging capabilities, including the ability to add, create, and remove tags directly on dashboards to improve dashboard organization and filtering. (MATCH-23492, MATCH-23493)
  • Enhanced Geo Map visualizations to support splitting results by a categorical field. (MATCH-20445)
  • Enhanced the search result export functionality in preparation to enable selecting the preferred time format. (MATCH-23391)
  • Enhanced the saved searches functionality in preparation to allow sharing saved searches through Trusted Circles. (MATCH-22903)
  • Added an entropy function for detections and analytics workflows. (MATCH-23275)
  • Improved timechart visualization handling to correctly display totals across supported widget types. (MATCH-23365)
  • Improved customer visibility into production updates with consolidated “What’s New” and detailed Release Notes for customer-impacting changes. (MATCH-16920, MATCH-18373)
  • Added a default max_depth for Decision Tree models to prevent failures when the parameter is not provided. (MATCH-23645)
  • Improved error handling for KMeans calculations when a feature column contains only null values. (MATCH-23568)

Fixed Issues

  • Fixed an issue where large page sizes could cause pagination to stop returning results after a certain page. (MATCH-23465)
  • Fixed an issue where results could fail to display in the table under certain storage/offload configurations. (MATCH-23077)
  • Fixed an issue where field summaries could fail to load when using pivot-style queries. (MATCH-23225)
  • Fixed the AQL like() behavior to return expected matches. (MATCH-23707)
  • Fixed the AQL sort operator to support dotted field names for OCSF data. (MATCH-23703)
  • Fixed the AQL openports operator to support dotted field names without binding errors. (MATCH-23621)
  • Fixed the AQL transpose operator to support dotted field names when pivoting results. (MATCH-23619)
  • Fixed the AQL makejson operator output to generate valid JSON when using dotted field names. (MATCH-23617)
  • Fixed an AQL parsing issue that could cause filldown to fail for certain metadata fields. (MATCH-23620)
  • Fixed the AQL mcatalog operator to prevent internal execution errors in supported scenarios. (MATCH-23599)
  • Fixed the AQL contingency operator to handle null/empty values more reliably. (MATCH-23597)
  • Fixed the AQL cluster operator to correctly resolve dotted field names. (MATCH-23594)
  • Fixed the AQL appendtable and appendcols operators to better handle schema/type differences when combining results. (MATCH-23592)

Feeds & Enrichments

New & Enhanced Features

  • Updated the feed ingestion SDK to version 2.8.0 to improve compatibility and stability. (FD-22816)
  • Updated the SpyCloud Enterprise Protection integration to align with the latest vendor changes. (FD-22740)
  • Enhanced Flashpoint Alerts feed processing to prevent ingestion failures caused by overly long tags. (FD-22746)

Fixed Issues

  • Fixed an issue where Google Threat Intelligence feeds could fail with HTTP 400 errors by improving pagination and last-modified handling. (FD-22537)
  • Resolved an issue that could cause a commercial feed to error during collection when request URLs exceeded vendor limits. (FD-22798)

Anomali Release Notes – 2026.03.R2

Note: Major new features are released through a phased rollout and may take up to two weeks to become generally available. Bug fixes, parser updates, and minor UI improvements are typically available immediately upon deployment.

ThreatStream

New & Enhanced Features

  • Added native ingestion and scheduled updates of First.org EPSS (Exploit Prediction Scoring System) data for CVE-based vulnerabilities, enabling richer Vulnerability Management dashboards and workflows that incorporate exploit probability. (OP-40473)
  • Added an HTML API Reference button on the Downloads page that opens the ThreatStream API documentation in online help for easier access to the latest REST API details. (OP-40811)
  • To support the upcoming EPSS Scoring integration, threat_models table now includes additional EPSS fields: epss_score and epss_percentile. (OP-40778)

Fixed Issues

  • Fixed an issue where some observables in the EU Cloud would not load correctly when values contained special characters, improving reliability for viewing and searching these observables. (OP-40838)
  • Standardized the format of rawText returned by WhoIs enrichment so all lookups use RDAP JSON format, improving reliability for downstream processing. (OP-40889)
  • Resolved an error that could occur when logging into Anomali if a chat username contained unsupported characters, so affected users can now sign in without chat account failures. (OP-40947)
  • Fixed an issue where the “Passive DNS” reputation label was truncated in the observable detail “Show Details” panel so the label now displays fully. (OP-40980)
  • Fixed several dark mode display issues affecting the Preferred Tags page and the Private Feeds and Rules dashboard widgets so buttons, dialogs, and text have proper contrast and layout. (OP-40939)
  • Security vulnerability fixes.

Security Analytics, Search, Dashboards, and Alerts

New & Enhanced Features

  • Improved the alert triage experience with persistent comment history, richer side-panel context, and streamlined multi-alert assignment and investigation workflows. (MATCH-22163)
  • Added the asset lookup table that uses the standardized asset schema to display asset data populated from vulnerability scanners. (MATCH-23481)
  • Added Phase 1 support for the Open Cybersecurity Schema Framework (OCSF), enabling source-agnostic searches, alerts, and dashboards on OCSF fields while continuing to support existing event data. (MATCH-22735)
  • Implemented automatic tracking of queued searches in an audit log to improve visibility into search processing. (MATCH-17435)
  • Enhanced the timechart operator to support adding total summary rows and columns for multi-series visualizations. (MATCH-20293)
  • Improved error reporting for the apply operator so model-related failures return clear, actionable messages across supported apply actions. (MATCH-22212)
  • Delivered storage-layer metadata improvements. (MATCH-22713)
  • Improved the event data lifecycle in the archive restoration process. (MATCH-23014)
  • Added the investigation_elements lookup table, available on request, to provide a centralized reference for investigation-related elements and support consistent querying, reporting, and analysis. (MATCH-23283)
  • Added a frequency-based view to the MITRE heatmap dashboard widget so users can color techniques by how often they occur, with configurable fields, value-based color gradients, and tooltips showing MITRE details and frequency counts. (MATCH-23388)

Feeds

New & Enhanced Features

  • Updated the indicator type detection logic to better handle all IPv4 and IPv6 indicator types, including benign IPs, Tor exit nodes, and IoT/PoS indicators, reducing the chance of misclassification. (FD-19111)
  • Improved the deployment script to terminate active background worker processes earlier in the deployment sequence, preventing stale processes from interfering with service restarts and ensuring a cleaner deployment state. (FD-22126)
  • Updated the Anomali Feed SDK to version 2.7.5, incorporating the latest SDK improvements and fixes. (FD-22530)
  • Updated the DomainTools Iris Detect feed activation process to use header-based API key authentication only, removing the need for a username and simplifying configuration. (OP-40945)

Fixed Issues

  • Fixed an issue where Google Threat Intelligence feeds could fail with 400 errors by improving cursor-based pagination and last-modified date handling, including resetting invalid cursors when necessary. (FD-22537)