Releases: splunk-soar-connectors/recordedfuture
Releases · splunk-soar-connectors/recordedfuture
4.4.3
4.4.2
- Changes to polling of alerts; now requires a comma seperated list to pull in alerts
- Fixing logic issue blocking the polling of alerts
- Fixing issues with hardcoded path for Cloud
4.3.2
- Improved visibility of support documents
- Renaming of app headers
- Fixing issues with hardcoded path for Cloud
- Improved format for Intelligence Command Widgets
- Added status config options for fetching standard and playbook alerts
4.3.1
- Increase timeout setting for RecordedFuture HTTP client
4.3.0
- Added new actions:
- links search - find links data in Recorded Future dataset.
- detection rule search - download detection rules (yara, sigma, snort) into the system for provided entity.
- threat actor intelligence - get intelligence data for threat actor.
- threat map - get a threat map from Recorded Future.
- Change the way Playbook alerts are polled from Recorded future into the Splunk SOAR. On the first poll the creation date is used to poll the alerts and all the next poll the alert that were updated during the time period from last poll to current poll.
- Now the intelligence commands will not fail with error NotFound but will successfully finish with the message that Recorded future does not have data for that entity.
- Added a code_repo_leakage type of playbook alerts.
- Recorded Future AI Insights added to Intelligence and Alert Lookup results.
4.2.0
- Added new actions:
- create list
- list search
- list details
- list add entity
- list remove entity
- list entities
- list status
- playbook alerts search
- playbook alert details
- playbook alert update
- Added new configs to ingest settings
4.1.0
- Fixed the bug when scheduled pulling for events was not working.
- Change the name of the app from "Recorded Future" to "Recorded Future For Splunk SOAR"
4.0.0
- Added two new actions: alert_lookup and alert_update
- On_poll functionality to download alerts
- alert_rule_lookup renamed to alert_rule_search to better describe the action
- alert_data_lookup renamed to alert_search to better describe the action
- Improved tagging of entities in alert widgets to find the related actions
3.1.0
- Added MITRE ATT@Ck codes to the entity information
- Added links information to intelligence lookups
- Improved presentation of Fixed table output views
- API call response tailored to the app