SNYPR 6.3.1 Build 181059 0119 Release Notes
Total Page:16
File Type:pdf, Size:1020Kb
SNYPR 6.3.1 Build 181059_0119 Release Notes Date Published: 1/20/2021 Securonix Proprietary Statement This material constitutes proprietary and trade secret information of Securonix, and shall not be disclosed to any third party, nor used by the recipient except under the terms and conditions prescribed by Securonix. The trademarks, service marks, and logos of Securonix and others used herein are the property of Securonix or their respective owners. Securonix Copyright Statement This material is also protected by Federal Copyright Law and is not to be copied or reproduced in any form, using any medium, without the prior written authorization of Securonix. However, Securonix allows the printing of the Adobe Acrobat PDF files for the purposes of client training and reference. Information in this document is subject to change without notice. The software described in this document is furnished under a license agreement or nondisclosure agreement. The software may be used or copied only in accordance with the terms of those agreements. Nothing herein should be construed as constituting an additional warranty. Securonix shall not be liable for technical or editorial errors or omissions contained herein. No part of this publication may be reproduced, stored in a retrieval system, or transmitted in any form or any means electronic or mechanical, including photocopying and recording for any purpose other than the purchaser's internal use without the written permission of Securonix. Copyright © 2020 Securonix. All rights reserved. Contact Information Securonix 5080 Spectrum Drive, Suite 950W Addison, TX 75001 (855) 732-6649 SNYPR Release Notes 2 Table of Contents Introduction 4 Improvements 5 Bug Fixes 7 Known Issues 11 What's New in Content 12 New Connectors 12 Contextual Connectors 15 Beta Connectors 16 Improved Connectors 16 New Content 21 Improved Content 22 Deprecated Parsers 28 Deprecated Policies 40 SNYPR Release Notes 3 Introduction Introduction SNYPR 6.3.1 Build 181059_0119 includes improvements, bug fixes, connectors, and content. SNYPR Release Notes 4 Introduction Improvements This following table describes the improvements included in this release: Key Component Summary The Audit Trail records the following information for improved monitoring and tracking: l Tenant setup details such as adding a new tenant, modifying an existing tenant, and deleting an existing tenant. This is only applicable for multi-tenant module. l Detailed user information such as user name, email address, last login time, INC-233922 role membership, group membership, Auditing and access level. INC-231748 Note: In the multi-tenant mode, tenant access is recorded in place of the access level. l User login type to determine if the user is logging using the local authentication or Single Sign On (SSO). Case/Incident Removed the Switch Workflow option - Management from the Incident Management screen. Improved the O365 connector to filter INC-236467 Connector duplicate events. SNYPR Release Notes 5 Introduction Key Component Summary Added scroll functionality to the Take Action drop-down on the Violations view, Security Command - allowing users to view all available actions Center regardless of where the violation displays on the screen. The following improvements were made for SCC widgets that displayed Sandbox violations: l The Sandbox widget populates results Security Command - l The Violation Timeline widget Center displays all Sandbox policies l Sandbox categories display appropriate names when selecting a policy category l Older violations are visible for the policies Added the Classless Inter-Domain Routing Spotter - (CIDR) search to improve the allocation of Queries/Operators IP addresses. SNYPR Release Notes 6 Bug Fixes Bug Fixes The following table describes the bug fixes included in this release: Key Component Summary The application saves the Login URL when - Authentication you enable Single Sign-On (SSO) from Settings > Single Sign On. Fixed an issue where the Show User Input Case/Incident - Form? setting was not holding its disabled Management status after a workflow is saved. Fixed an issue in the Activity Stream of Case/Incident Incident Management that caused the - Management activity stream to only be visible by users assigned to the case. Fixed an issue that caused incidents to not appear on the SCC for threat models, Case/Incident - regardless of if the incident was created Management and visible on the Incident Management screen. Fixed an issue on the Incident Management screen that caused the Case/Incident - violation summary to display an Management UNKNOWN value for policies on open Incidents. Fixed an issue in Incident Management Case/Incident - that caused a blank screen to display when Management an incident was selected. Fixed an issue so that the Category field - Policy Engine displays the original policy's category when you create a duplicate policy. SNYPR Release Notes 7 Bug Fixes Key Component Summary Fixed the Policy Creation screen to CLOUD-23660 Policy Engine display correct Japanese characters. The violation summary and related information are displayed for Aggregated - Policy Engine Event Evaluator (AEE) policies where the violation entity is Network Address. The Identity based policy displays the CLOUD-23721 Policy Engine correct preview of rule conditions. Included CURRENT_DATE functions for CLOUD-23722 Policy Engine Identity based policies. Improved the performance of the Does_ - Policy Engine Not_Contain_In_List operator. Fixed an issue so that the Security Command Center screen displays violation - Policy Engine events and tree view for hourly behavior policies. - Policy Engine Fixed the risk booster for the lookup table. Fixed Job 13: Action Prediction to resolve Response Bot the incorrect queue error. Security Command Fixed a discrepancy in views for users - Center between Top Threats and Top Violators. Fixed an issue on the Violations screen Security Command - where incidents failed to generate Center automatically. Security Command Fixed an issue where bulk action does not - Center mark all the selected policies. Fixed an issue that caused the same case Security Command - details and Violation Summary to display Center for different incidents. SNYPR Release Notes 8 Bug Fixes Key Component Summary Fixed an issue so that User Import activity CLOUD-18047 Shared Service runs on schedule. Fixed an issue that caused the Indexer - Spotter Cache Counts Consumer to fail an automatic restart when updating the cache. Fixed an issue in the Search Results view of Spotter that triggered the Max query - Spotter Console limit reached # 1000 error message and caused search results to not display when the maximum query limit was reached. Fixed an issue in the Search Results view of Spotter that caused the event card to Spotter - display the most recent eventtime results Queries/Operators instead of displaying the eventtime results that were selected in the query bar chart. Fixed an issue in the Search Results view Spotter of Spotter that caused an incorrect - Queries/Operators pagination count to display when the table query was run. Fixed an issue that caused the query Spotter formation to become corrupt when - Queries/Operators whitespace characters were used in the Spotter search query. Fixed the attribute autosuggestion list to Spotter populate in alphabetical order, ensuring - Queries/Operators you apply the correct attribute as you type your Spotter search query. Fixed an issue in Spotter that caused - Spotter Reporting additional attributes to display when exporting TABLE query results. SNYPR Release Notes 9 Bug Fixes Key Component Summary Fixed an issue in Spotter that caused long text strings to truncate in text format and - Spotter Reporting in the footer pagination when reports were exported. Fixed an issue in Spotter that caused the csv format to use the value in the pdf - Spotter Reporting format when the report-type order was changed in drop-down. Fixed an issue in Spotter and in the Security Command Center that caused an - Spotter Reporting inconsistent report output when users tried to view a violation event for a policy. Fixed an issue in Spotter that caused an - Spotter Reporting inconsistency in exported reports. Fixed an issue so that the Box connector Third-Party token remains valid when the datasource is INC-232172 Integration rescheduled or data is previewed after schedule. Fixed the sort by tenant function in the INC-231057 Views - Resources Resource screen. Fixed an issue that caused searching for a - Watchlist masked member of a watchlist to not be possible with masked ID. Fixed an issue so that users can whitelist - Whitelist accounts with the account name ending with the $ sign. SNYPR Release Notes 10 Known Issues Known Issues The following table describes the known issues that exist in this release: Component Summary When you delete a threat model, it deletes the violations associated Analytics to the threat model but the entry is displayed in the Threat Modeler screen. The entity meta data attributes are not listed in the Action filter drop Entity Metadata down. 1. CIDR search is only available for the following comparison operators: l Equals (=) l Not Equals (!=) Spotter l In Queries/Operators l Not In 2. CIDR search is dependent on the data stored at time of ingestion. Data ingested prior to CIDR search being enabled is not retrieved. When the ipaddress_long field is used in the Spotter search query, Spotter no queries are found. However, the ipaddress_long field displays Queries/Operators