New Features
Threat Intelligence (STIX/TAXII)
- Implemented STIX/TAXII bucket support with indicator management and API enhancements.
- Added STIX fields to the bucket form and STIX type filtering to bucket filters.
- Introduced URL type support and pattern matching in STIX bucket configurations.
Integration & Data Collection
Plugin Updates
- Cloudflare Plugin Updated
- SentinelOne Plugin Updated
- Office 365 Management Plugin Updated
- IBM QRadar Plugin Updated
Other Improvements
Security & Permissions
- Encrypted bucket passwords for enhanced data protection.
- Added stats permission support in PermissionList and RolesForm.
Incident & Alert Handling
- Enhanced incident alert info with guide link support.
- Fixed detail display issues in alert cards.
System Maintenance
- Handled exceptions during current index list retrieval in maintenance scripts.
- Increased file descriptor limit for the logsign-poller-api service.
Licensing & Validation
- Corrected license check result handling for improved validation reliability
MSS Operations
- Developed MSS Incident Auto-Closure Script for managed security services (MSSP) workflows.
System Enhancements
- Updated URI mappings across multiple log file types for improved parsing consistency.