New Features
- UEBA: redesigned entity overview with activity and risk trend cards, entity score rings, an urgency distribution view, and a Total Involvement Matrix heatmap that drills down into originated incidents, involved alerts, and behaviour events.
- UEBA: new entity relationship graph on user and host detail pages, visualizing peer activity, alerts, and top actions.
- UEBA: identities are now correlated across directory syncs (mail, UPN, sAMAccountName) and shown together on the user profile with cross-links.
- UEBA: "Devices" is renamed to "Hosts" across UEBA and enrichment settings, and info tooltips on entity cards explain where each metric comes from.
- Directory enrichment: the sync interval can now be configured per source for LDAP, Microsoft Entra ID, and Google Workspace.
- Response actions now record how they were triggered (action rule, API, or user) in the new Response.TriggerSource column.
- Host audit trail: journal monitoring can now collect an OS-level audit trail of commands executed on monitored hosts.
- Scheduled reports now support Excel/CSV export for multiple reports, with unique file names per export job.
- The white list permission can now be granted from the Roles page.
- API-backed lists now support the IP match type in rule evaluation.
Plugin & Integration Updates
- Added Ribbon GSX log parsing for GSX SYS and GSX CDR formats.
- Added Trend Micro TippingPoint response integration.
- Added a vendor-agnostic S3-compatible storage poller (Custom S3).
- Added VMware VeloCloud SD-WAN poller.
- Added Seclore EDRM plugin.
- Added Cribl Windows Event Logs plugin with source geo-location fields (City, Country).
- Added ManageEngine DLP Plus API poller.
- Added Varonis Alerts SaaS API poller.
- Added Zoho CRM audit log poller.
- Added Zoho Mail poller with mail audit and login history streams.
- Added FileZilla Server 1.x log format support.
- Improved Barracuda firewall log parsing and event categorization.
- Restored previously removed Office 365 Management fields per the normalization documentation.
- Improved Kaspersky Security Center parsing: connection details, positional fields, and non-English console labels are now normalized into standard columns.
- FortiMail: comma-delimited (CSV) syslog format is now supported.
- JumpServer PAM: log lines containing NUL bytes are now parsed correctly.
- GreyCortex Mendel: multi-word protocol and service names are now parsed.
- ESET Endpoint: ESET PROTECT event-log notification messages are now parsed.
- F5 BIG-IP LTM: event parsing now includes a custom category field.
- Microsoft Exchange JSON logs: key naming is normalized for consistency.
- Palo Alto Networks: full PAN-OS messages are now surfaced and block-IP actions have improved timeout handling.
- Arbor Edge Defense: blacklist host actions now support automatic recovery and expiry time.
- Cisco ISE: the connection test now checks both MnT and ERS APIs and reports per-API error details.
- Poller reliability: corrected initial lookback windows, Netskope alert collection, the first MSSQL checkpoint, and Cloudflare R2 position tracking.
Other Improvements
- The alarm processing pipeline has been re-engineered for higher throughput, with an auto-scaling worker pool.
- Internal service hardening: messaging, coordination, and file synchronization services now communicate over cluster-internal interfaces only.
- Connection Test flows for integrations and log sources have been hardened to further protect stored credentials.
- Strengthened input validation across management and configuration APIs.
- Sensitive parameters are no longer included in configuration import status messages.
Bug Fixes
- MSS: hub incidents are now always stored with a valid status.
- Configuration restore is more resilient: recovery and status gaps are closed, cross-version imports are handled, and failures are clearly reported.
- Custom configuration export keeps reference fields, and import prunes entries whose references are missing.
- Built-in library content is no longer missing after forming a cluster.
- Installation safeguard: factory defaults are never re-applied over an existing installation.
- Alert matching: empty field values are evaluated correctly in notEqual conditions, and empty match conditions are rejected.
- Response actions: failed recoveries are retried before being dropped, and response card creation is no longer blocked by incident bookkeeping errors.
- Health-check diagnostics no longer remain stuck in the running state after a restart.
- Source status checks now treat out-of-window cache entries as a miss, giving accurate status results.
- Log capture sender filters are now validated as * or an IP list.
- Threat intelligence list snapshots now load reliably under heavy load.
- Various UEBA accuracy and display fixes: trend cards, matrix labels, entity card queries, and machine-account exclusion.