The Complete SOC.OS Update: August 2021

AUGUST 24, 2021

DAVE MAREELS

SOC.OS has successfully been upgraded.

With the latest release, you can say hello to advanced search capability, drastically improved UI responsiveness, Hour/Day/Week/Month cluster view, new (MS Advanced Threat Analytics) and improved tool integrations. Not to forget a bunch of bug fixes and a continually maturing wiki to help with support and training.

Click on the following video for a 2min overview of the major upgrades which are now available to all users. Enjoy!

 

WHAT’S NEW FOR THE SOC.OS USER INTERFACE (UI)
 

Advanced search capabilities
Following the recent introduction of “chip” based basic searching, we wanted to provide even more powerful search capabilities. We’ve delivered this with the introduction of the new SOC.OS query language. Any SOC.OS search bar supports advanced search using the SOC.OS query language. Simply press the Advanced button to the right of the query to convert your basic query mode into an advanced query. You can then edit the raw text of the SOC.OS query to fit your specific investigation. For more information on this new capability, check out the dedicated “Advanced Search” page on the SOC.OS wiki, here.
 

Time period-based cluster visualisation filtering
You can now choose to view the visualisation grouped into time periods of Hour, Day, Week or Month, allowing you to filter your view and better interpret clusters over varying time periods.

 

WHAT ELSE IS NEW?

  • Auth0 log in page  updated to latest version (v11.27)
  • Preparation for SOC.OS Alert search (more details to come in next releases)
  • Further visualisation improvements driven from Elasticsearch (histogram), improving performance and responsiveness
  • Security and performance updates

 

Bug Fixes

  • More UI bugs and inconsistencies fixed
    • Threat types in visualisations
    • Scroll bars
    • Alert percentages
  • Default search query no longer re-populates after deleting and moving between clusters
  • Cluster attribute searches now work across all attributes and not just the first in list
     

Source Systems

  • New integrations of source systems:
    • Microsoft Advanced Threat Analytics
  • Improved existing integrations:
    • FortiOS support updated to v7.0
    • Cylance mapping now includes “Artefacts of Interest”
    • Palo Alto mappings updated for additional actions
       

SOC.OS Wiki

  • Search help page updated with Advanced Search
  • Tutorial videos for some features now available here (more coming soon)

 

WHAT’S NEXT FOR THE SOC.OS SOFTWARE?
As ever, we’re excited to continue to develop SOC.OS to meet your needs, and always welcome your input. Please continue to call us or email support@socos.io about defects and improvement suggestions, no matter how small or seemingly left field!

About the author

BACK TO BLOG

For more information about SOC.OS, contact info@socos.io