Initially released on 5th August 2021
This release brings advanced search capability (this is big!), drastically improved UI responsiveness (clusters and alert histograms now load quicker than the Aussies overtaking the Poms on the medal tally), Hour/Day/Week/Month cluster view, new (MS Advanced Threat Analytics) and improved tool integrations, a bunch of bug fixes and a continually maturing wiki to help with support and training.
Click on the following gif for a 2min overview of the major upgrades which are now available to all users. Enjoy!
To find out more about using Advanced Search, check out the Advanced Search Tutorial.
Following the recent introduction of "chip" based basic searching, we wanted to provide even more powerful search capabilities, with the introduction of SOC.OS query language.
Any SOC.OS search bar supports advanced search using the SOC.OS query language. Simply press the Advanced button to the right of the query to convert your basic query mode into an advanced query. You can then edit the raw text of the SOC.OS query.
Introduced in the previous release but missing from our release notes, you can now choose to view the visualisation grouped into time periods of Hour, Day, Week or Month, allowing you to better interpret clusters over varying time periods.