ADR Release Notes 10.1.2

Modified on Fri, 23 Aug at 8:52 AM

TABLE OF CONTENTS

Overview

Version 10.1.2 introduces several key enhancements:

  1. CCE Remote Upgrade / Remote Patch from UI: Simplified remote upgrade and patching processes directly from the user interface.

  2. MTMT-MSSP Level Alert Analysis and Deep Tracker: Enhanced functionality of new MTMT view to display more useful data, including assignee and tenant name.

  3. EDR: Support for bulk EDR agent installation with multi-use installation tokens. Added support for MSI download on EDR agent installation screen. 

  4. HA System: Added HA indicators to the MSSP APE and MTMT APE screens to show HA system health status along with basic statistics. Added Instrumentation for reporting NTP status in the otmdoc container utility.

  5. STIX/TAXII: Introduced a test connection capability.

  6. Bulk Support: Added UDA and TTI support for the MTMT and MSSP screens.

  7. Alert AnalysisAdded an alert timeline feature to display the alert lifecycle in chronological order. Timeline includes all events contributing to the Alert status and relevant user actions.

  8. MITRE Refinement: Enhanced, more accurate recognition and alignment with the MITRE framework.


List of New Features in 10.1.2

 

NoIssue keySummary
1SR-3890Added Ingested devices serial numbers to correlate with IP 
2SR-3813Added ability to perform UDA TTI Multiple tenant configuration from MSSP APE and MTMT MSSP  screens
3SR-5232Added anomalies detection in the network by monitoring Flow Stats and Log Stats count 
4SR-4521Added CCE Remote update support from UI
Note: Remote update works ONLY for CCEs running Release 10.1.2 or higher
5SR-454Added Remediation support for Google cloud platform , Aria AZT and Gajshield FW
6SR-2612Added ability to add an IP/hostname to the allowed list when an EDR endpoint is put into quarantine
7SR-3506Added OT/IoT Device discovery
8SR-3663Added MSSP Level Search screen and Configuration screen For Deep tracker
9SR-3246Added CCE- Nmap capability to scan known exploit port open on CCE subnet
10SR-4418Added support for Traffic Analyzer installation in https mode (CCE Control)
11SR-3725Added parser: Cyber MDX Device
12SR-1674Added parser: Instasafe VPN
13SR-1641Added parser: TrendMicro Email Security
14SR-4741Added parsers:  Epic Hyperspace, LastPass, F5 cloud , ProphazeWAF, SAAS Alerts, Cloudsek 
15SR-3812Added parser API - Bitdefender GravityZone Cloud
16SR-3959Added parser: AZURE SQL logs support
17SR-3323Added parsers: Trend Micro XDR, Forti EDR, Liongard CCDR, CTD, Manage Engine, Versa-Analytics
18SR-3307Added parser: Nozomi Networks: Industrial IoT & OT Cybersecurity



List of Improvements in 10.1.2

  

NoIssue keySummary
1SR-2487Add a timeline to alert life cycle.
2SR-3244Improvements to the Threat Model alert type recognition
3SR-4373Making changes on addOn device script so that it will support both SMB UI interface and addon device
4SR-4374Add drill-down to IP flows/Deep tracker screen from alert screen.
5SR-4479Security posture Report  Page 23 sorting out traffic correction
6SR-4848GTB DLP USB events to be added as a threat event.
7SR-4926Improvement in MTMT-MSSP deep tracker screen to adding state management after tenant drilldown.
8SR-4939Allow to add new tenant only when APE system load avg is below 80%
9SR-4949Re-design  Host Connections Screen to improve readability
10SR-4956Add new additional key for UDA 
11SR-5015There are few more improvements in MTMT-MSSP Deep-tracker screen.
12SR-5054MTMT, M-MSSP, A-MSSP Tenant Creation - Must check for APE resource status before UI allow tenant creation
13SR-5057Bulk Edit & Delete Support for UDA and TTIs from MTMT-MSSP 
14SR-5181Wrong Calculation of megabyte_count and mbps in Data Upload/Download events, may be in another events too 
15SR-5245aiXDR - Linux rules 
16SR-5247Add Data Download and Upload events from logs
17SR-5271Add a download link for EDR MSI
18SR-5294Need to show NTP sync status in otmdoc -x
19SR-5355Show HA Status information  on MTMT UI 
20SR-5356Remote CCE upgrade improvements.
21SR-5411Show "EDR server public host & port" in EDR host screen
22SR-5446aiSecurity Score360 - Data to be show in Report/Dashboard for the latest scan only


List of Main Bug fixes in 10.1.2

  

NoIssue keySummary
1SR-4165Issue while closing alerts in Bulk - alert are reported as closed multiple times
2SR-4174Azure Defender alerts-Coming under 1 alert and appear as Major alert
3SR-4222EDR md5sum hash redirected link is not opening 
4SR-4253Add parameters in TTI list
5SR-4642How to differentiate logs received from AWS - s3 Bucket
6SR-4657CCE 9.3.2 Hotfix-8 installation issue
7SR-4778CCE to LTS log transfer failure issues
8SR-4784Duplicate System Alerts
9SR-4790Alert Dashboard is not reflecting any data
10SR-4845Remediation test status not showing the status of test connection 
11SR-4887For Trend Micro Vision One generated alerts, no MITRE ID is listed, but in the message section of the event details a MITRE ID.
12SR-4917Cannot close System Alert on tenant UI 
13SR-4923Source Data Type is not Showing any results on all Tenants
14SR-4942Mitre not working for any alerts - User Access not working 
15SR-4943Alerts Excel Export missing data
16SR-4947Parser for watchguard in LEEF format 
17SR-4951CCE: Netskope Issue with policy alert - type=policy is missing in the "cat_types" array
18SR-4967OpenVAS Email Notification Issue - VAS email notification is generating only a single host report repeatedly
19SR-4970Security certificates do not survive after APE upgrade
20SR-4972pm2.log consuming lot of space which is causing disk overcommit on EDR Server
21SR-5018Not interpreting log_type="IDP" from Cyberoam (Sophos Firewall)
22SR-5043Prophaze logs are there on CCE but yet no threat events are coming on UI
23SR-5071Destination IP not showing result in IP Flow - Deep Tracker
24SR-5072Remediator is Blocking Private IP
25SR-5076LTS Anatomizer is not working after upgrade to the 10.0.2 version
26SR-5088Remediation Report is not Showing Complete Details
27SR-5094"Top Users with Attachment" is not showing any data
28SR-5102MSSP: All tenant alert notifications are not working
29SR-5170Add Option "Remove Custom Branding" at MSSP Level
30SR-5214APE 10.0.2: Azure Dashboard is showing almost blank while we are getting the data from all azure sources.
31SR-5340CCE drops security event (Malware) from LUMU
32SR-5357Brute Force Alert Flooding from Azure
33SR-5396Darktrace Log is not coming on the UI 
34SR-5498EDR agent installation failed In Mac
35SR-5519Traffic logs are getting flagged as Potential Exploit and creating lot of alerts 

 

List of Known Issues in 10.1.2


NoIssue keySummary
1SR-4954Azure SQL Integration Issue - no logs coming on the UI
2SR-4962CCE Token Defunct while data is continuously coming to the APE
3SR-5019IST/EDT Time format Difference - which does not match the expected difference.
4SR-5097Azure Dashboard not populating after 10.0.2 release
5SR-5322After manual remediation, some alerts remain open
6SR-5369OpenVAS scanning fails while scanning IP range


Breaking Changes in 10.1.2


No
  Issue key
Summary
1
SR-4182The user notification setup will not work by default on MTMT level. It is disabled for security reasons. If you have MTMT setup, Please contact support to follow additional steps at APE level to enable notifications at MTMT level. 
2SR-4900On Uploading data in Forensic Analysis Screen, it is sometimes giving Kong Error, sometimes {"statusCode":404, "error": "Not Found", "message": "Not Found"}, sometimes the dashboard is not uploading at all

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article