/search endpoint:

    • Added offset parameter for improve pagenation support.
    • Added rule_id field.
    • Changed title behavior to keep it in sync with what shown in UI.
  • Details endpoints:
    • Added alert_rule.id, alert_rule.label and alert_rule.name fields.
    • Deprecated case_rule_id and case_rule_label fields, use alert_rule instead.

Risk API

by Tobias Bende

New version of the Risk API, including Active Risks endpoint.

The Playbook Alert API has been updated to v1.1.0, including support for the Payment Card Fraud Playbook Alert.

New version of Malware Intelligence API released.

  • Add support for retrying failed Yara and Sigma rule generation jobs

New version of Malware Intelligence API released.

  • Add support for editing generated Sigma rules

New version of Malware Intelligence API released.

  • Add more fields to static report section
  • Removed the field dynamic.dumped.name