These Release Notes document security content updates from content package c2108.2 (i59) to c2109.2 (i60).
The security content updates listed below include changes to the following areas:
In the lists below, each item represents a specific parser, model, or rule that has been added, updated, or deprecated. To facilitate finding every data source where the changed content items are referenced, a content library query has been created for each changed parser, model, or rule. To view the results of each query, click on the link for the relevant content item.
- s-crowdstrike-auth-failed
-
APP-UOs-New – OS and Browser from user agent
-
VPN29-New – VPN Operating System
-
WEB-GUa-Browser-New – Top web browsers being used by peer group
-
WEB-GUa-OS-New – Top operating systems being used to connect to the web for peer group
-
WEB-OUa-Browser-New – Top web browsers being used in this organization
-
WEB-OUa-OS-New – Top operating systems being used to connect to the web for organization
-
WEB-OsUa-MobileBrowser-New – Top mobile apps/web browsers being used in the organization for this type of device
-
WEB-UUa-Browser-New – Top web browsers being used by user
-
WEB-UUa-MobileBrowser-New – Top mobile apps/web browsers being used by user
-
WEB-UUa-OS-New – Top operating systems being used to connect to the web for user
-
A-NET-HCountry-Inbound – Inbound country per asset
-
A-NET-HCountry-Outbound – Outbound country per asset
-
A-NET-OCountry-Inbound – Origination country per organization
-
A-NET-OCountry-Outbound – Outbound country per organization
-
A-NET-ZCountry-Inbound – Origination country per zone
-
A-NET-ZCountry-Outbound – Outbound country per zone
-
A-NETF-HCountry-Outbound – Failed outbound country per asset
-
A-NETF-OCountry-Outbound – Failed outbound country per organization
-
A-NETF-ZCountry-Outbound – Failed outbound country per zone
-
EM-EdC – Countries per Email Domain
-
EM-Gcountry – Email Countries from/to peer group
-
EM-Ucountry – Email Countries from/to user
-
EM-country – Email Countries
-
FA-UA-GC – Countries for peer groups file activities
-
FA-UA-OC – Countries for organization file activities
-
FA-UA-UC – Countries for user file activity
-
UA-GC – Countries for peer groups
-
UA-OC – Countries for organization
-
UA-UC – Countries for user activity
-
WCA-Ucountry – Web conference login countries for user
-
WEB-OC – Web destination countries for org
-
WEB-UC – Web destination countries for user
There are no deprecated models in this release.
- A-ALERT-DL – DL Correlation rule alert on asset
There are no updated rules in this release.
There are no deprecated rules in this release.