TABLE OF CONTENTS
- Overview
- Important Notes
- List of New Features in 10.2.2
- List of Improvements in 10.2.2
- List of New Parsers in 10.2.2
- List of Main Bug fixes in 10.2.2
- List of Known Issues in 10.2.2
- Breaking Changes in 10.2.2
Overview
Version 10.2.2 introduces several key enhancements:
- Dashboarding and Reporting: Customer feedback is incorporated in these features to help our customers in their operations.
- Alert Dashboard.
- New Inventory Report PDF.
- BI 360 and Score 360: This release acknowledges the use of BI360 and Score 360 by ADR partners and executes on their feedback for these.
- Enhanced BI360 capabilities for sophisticated analytics and more suitable customization.
- Score360 increases the depth of your security posture reporting.
- Device Support: As always support for number of existing devices is enhanced to reflect vendor updates while a good number of new device support is added.
Important Notes
- If any of UI fixes/ improvements don't work, please clear browser cache and recheck.
- URGENT - Starting 10.1.2, SSH Tunnel support between CCE and APE is discontinued and is replaced by HTTPS.
- If APE server has 5 disks mounted for mnt, please contact ADR support for the upgrade.
List of New Features in 10.2.2
No | Issue key | Summary |
1 | SR-3262 | Inventory Report can be downloaded as PDF |
List of Improvements in 10.2.2
No | Issue key | Summary |
1 | SR-6015 | Event Processor USER_DB lookup improvement |
2 | SR-6006 | New Perf Improved UDA Does not support UDA where 'having' clause have time range restrict |
3 | SR-6003 | Add Application Port and Protocol along with Application Name on the Host Graph Screen |
4 | SR-5998 | CCE - summarize Login event to reduce the load |
5 | SR-5994 | BI Tool - Improvements to enhance usability |
6 | SR-5958 | Support User Activities for all user and all screens |
7 | SR-5787 | EDR Endpoint registration token, perpetual token which never expire |
8 | SR-5770 | New SOC Report and Old SOC Report co-existence or overwrite |
9 | SR-5735 | Deep Tracker / IP Flows - Query builder is not patching the field properly selected form dropdown list |
10 | SR-5719 | MTMT-MSSP Deep Tracker - Improvements to enhance usability. |
11 | SR-5712 | CCE: Expanding list of events for ESET Parser. |
12 | SR-5708 | LTS - Improvements to CCE logs processor to read the logs from files |
13 | SR-5695 | MSSP/MTMT Dashboard - Tiles based dashboard need ability to pin |
14 | SR-5694 | Alert Analysis - MITRE Kill chain drill down must show threat indicator associated the alert only |
15 | SR-5687 | Hosted site backup improvements |
16 | SR-5669 | Improved integration with the Nessus |
17 | SR-5646 | CloudX: Expanded Azure Data Set integration |
18 | SR-5641 | Enhanced BI Tools Drill down - Introduce another layer before Deep Tracker / IP Flow / Alert Screen |
19 | SR-5638 | Bulk System Alert Closure at Tenant Level |
20 | SR-5543 | New System Benchmark - Backup/Restore 4 disk setup |
21 | SR-5532 | CloudX - Data Pull: Improved scalability for bigger env - Outlook Data Only |
22 | SR-5503 | aiPMax Endpoint - Controlled Upgrade, Not auto-upgrade by default |
23 | SR-5439 | Box integration and other integrations recognition authentication token creation as a security event |
24 | SR-5437 | The Score360 now includes Private/Internal Network data in the final scoring, enhancing the security assessment by factoring in the internal network's vulnerability and configuration. This change aims to provide a more holistic view of the organization's security posture |
25 | SR-5419 | Expanded list of events in Nxlog |
26 | SR-5406 | For On client side Alert screen---- After export showing client ID it should show client name. |
27 | SR-5392 | Improvement in Tenant Report Screen |
28 | SR-4519 | TTI: The Additional Type entity dropdown should contain every additional field that we find in the raw logs. |
29 | SR-4412 | Configure Expected Device Type in System Alerts Configuration screen. |
30 | SR-3748 | MITRE Tech_ID Refinement |
List of New Parsers in 10.2.2
No | Issue key | Summary |
1 | SR-5955 | Added parser: DDN storage |
2 | SR-5952 | Darktrace parser improvement |
3 | SR-5927 | Expanded list of events added for Epic. |
4 | SR-5875 | Added parser: Levelle SD-WAN |
5 | SR-5848 | Added parser: BeroeEKYs In-house built application |
6 | SR-5819 | Added parser: SDC DLP Device |
7 | SR-5792 | Added parser: beroe-live-stage (In-house built application) |
8 | SR-5790 | Enhanced Nginx parser - access logs |
9 | SR-5742 | Added parser: Netcore Email server |
10 | SR-5725 | Added parser: Vicarius Topia API Based |
11 | SR-5723 | Enhanced Prophaze WAF |
12 | SR-5666 | Added parser: Cyberoam firewall |
13 | SR-5663 | Added parser: F5 BIG IP LTM |
14 | SR-5650 | Added parser: Wazuh |
15 | SR-5577 | HUBSPOT Ticketing Tool integration with cGuard |
16 | SR-5547 | Resolved Palo Alto Username parsing issue |
17 | SR-5513 | Added parser: IPS Checkpoint logs |
18 | SR-5510 | Added parser: database logs hosted on oracle linux server |
19 | SR-5492 | Added parser: Abi-bot |
20 | SR-5438 | Added parser: Asimily Integration |
21 | SR-4844 | Added parser: Huawei SAN switch |
22 | SR-4713 | Added parser: Wallix PAM |
23 | SR-3984 | Added parser: F5 |
List of Main Bug fixes in 10.2.2
No | Issue key | Summary |
1 | SR-6072 | TTI with "Client Country Name" field doesn't work |
2 | SR-6057 | Discrepancy in TTI for Data upload events |
3 | SR-6032 | As we have observed, the event triggered as ransomware due to alert potential malware infection is a false positive for the process TiWorker.exe. |
4 | SR-5949 | Duplicate Events being generate for Microsoft Entra ID |
5 | SR-5947 | aiSecurity Score360 Report is giving duplicate results |
6 | SR-5931 | Release 10.1.2 uninstaller is not signed |
7 | SR-5903 | Tenants not receiving data from SharePoint and OneDrive. |
8 | SR-5849 | The message is not correct for Suspicious Account Creation alert |
10 | SR-5750 | Potential Malware Infected Host Event Type Details: Script Execution does not show a threat indicators |
11 | SR-5677 | An windows event_id 4741 is not being parse by CCE |
12 | SR-5675 | Reset Two-Factor Authentication Code is not working on otmcloud. |
13 | SR-5664 | Custom SOC Report enhancements |
14 | SR-5651 | Assignee names are not coming for the some tenants |
15 | SR-5636 | Unable to create SFTP connection between CCE and LTS Server: Authentication failed |
16 | SR-5607 | A few of the integrated device details are not showing in the log and flow status if we filter for more than 15 minutes, but we are getting the information in the Deep Tracker. |
17 | SR-5583 | Cannot create new Tenant inside MSSP |
18 | SR-5582 | Google Cloud Platform showing 404 |
19 | SR-5580 | LTS: Getting Error in Visualizing data on Forensic Analysis screen |
20 | SR-5576 | Device Configuration missing after upgrade |
21 | SR-5561 | 10.1.2 ARIA AZT Integration misses new logs that are added |
22 | SR-5548 | MSSP page not being loaded correctly on otmcloud |
23 | SR-5545 | APE Installation issue, Error: Failed to Create Docker Images |
24 | SR-5539 | UDA Test Search Condition is not working |
25 | SR-5537 | Getting error while generating SOC report for one of the tenant of partner AHAT |
26 | SR-5535 | Open vas issue with the scan - incorrect time and date publishing |
27 | SR-5524 | SentinelOne Issue after Upgrade - not getting logs after the upgrade 10.0.2 |
28 | SR-5486 | Huge volume of Login & Logout events disrupting data pipeline at APE System and dropping the data |
29 | SR-4060 | Azure Defender alerts-Coming under the same threat indicator instead of properly defined threat indicator types |
List of Known Issues in 10.2.2
No | Issue key | Summary |
1 | SR-6209 | Unsigned files in quarantine directory |
2 | SR-6081 | Potential issue with EPP uninstall - files being still quarantined |
3 | SR-6064 | TTI is not working temporarily during TTI edits |
4 | SR-5808 | Issue with "Batch Action" on Alerts - closes all Alerts vs selected ones |
5 | SR-5779 | False positive Ransomware alerts |
6 | SR-5508 | EDR related alert - no details for Threat indicator |
7 | SR-5892 | EPP - EPP events message need to change so we can differentiate between detection and protection mode. |
Breaking Changes in 10.2.2
No | Issue key | Summary |
1 | SR-4182 | The user notification setup will not work by default on MTMT level. It is disabled for security reasons. If you have MTMT setup, Please contact support to follow additional steps at APE level to enable notifications at MTMT level. |
2 | SR-4900 | LTS : Data with device name is not allowed from UI to load in Forensic analysis screen |
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article