Table of contents
3 min
H2 title on one or more lines.
Speak to a Sekoia expert

Your security challenges deserve expert answers. Get a tailored demo and discover how Sekoia helps your team detect and respond to threats faster.

Get a demo

Share

Copied !

Detail of an alert, observable database, new exclusive source … the novelties of October 2021

In this article, you will discover all the news features while improving existing features of sekoia.io platform.

Sekoia.io aims to be as close as possible to the users of the platform, meeting their needs in a precise way, while taking into account their approach and user experience. In this dynamic, the platform continues to reinvent itself and evolve by regularly integrating new features while improving existing features. Discover in this article, all the news published in October 2021.

Operation Center: New alert details page

Understanding an alert has never been that easy!

Thanks to the new alert details page you will be able to :

  • Get an overview of the reasons why the alert was raised.
  • Create a Case from an alert or link it to an existing Case.
  • Consult the timeline of actions performed on an alert.
  • View and interact with the events linked to the alert.
  • Use Sekoia.io’s CTI during your investigations.
New alert details page on SEKOIA platform
New alert details page on SEKOIA platform

You can find all details in our documentation!

Intelligence Center

New feature: The observables page

In addition to the contextualized IoCs provided by Sekoia.io CTI Feed, we offer you now a qualified observable database to facilitate your monitoring! 

Observables are technical elements structured in STIX, aggregated in our knowledge base, which are not necessarily IoCs but that facilitate monitoring and investigation. An observable can form a threat and can contain interesting information associated with a context allowing a quick doubt lifting on an alert raised.

How to use the Observables?

You need context on a raised alert and you can’t find the associated context in the IoCs database? You can look at the observables page now, you will find information that will guide your investigation through tags and relationships.

You can find all details in our documentation !

New observables: Dynamic Domains

A list of more than 5,000 dynamic domains has been added to the Sekoia.io Observables database. Dynamic domains are regularly used maliciously by threat actors or malware. 

It is complemented by a new detection rule (Dynamic DNS contacted) with a “Master” level of effort: often led to contextualize the rule when activated in order to reduce the false positive rate.

New observables on SEKOIA platform
New observables on SEKOIA platform

New exclusive source : Sekoia.io Twitter Watcher 

We have created a new source “SEKOIA Twitter Watcher” that automatically retrieves IOC’s from a qualified list of relevant Twitter accounts that share technical CTI on current threats.

New exclusive source from SEKOIA platform
New exclusive source from SEKOIA platform

If you liked this article, we invite you to share it. You can also read our recent article :