Home
Blog
Detail of an alert, observable database, new exclusive source… What's new in October 2021

Detail of an alert, observable database, new exclusive source… What's new in October 2021

In this article, you will discover all the new features, plus improved existing features, within the Sekoia platform.
Developer workstation setup with dual monitors showing code and workplace apps.

Key takeaways

October 2021 Sekoia update: redesigned alert details page, Observables database launch, 5,000 dynamic domains, and Twitter Watcher CTI source.

  • The new alert details page in the Operation Center provides a single-view layout covering the reason the alert was raised, linked events, CTI context, and the action timeline, with direct Case creation or linking from the same screen.
  • The Observables page was launched as a distinct layer from the IoC feed: STIX-structured technical objects with tags and relationship context that aid doubt-lifting during investigations even when no IoC match exists.
  • A database of 5,000+ dynamic domains was added to Observables, paired with a new 'Dynamic DNS contacted' detection rule requiring analyst review to reduce false positives.
  • The new 'Sekoia Twitter Watcher' source automatically pulls IoCs from a curated list of CTI-sharing Twitter accounts, feeding fresh technical indicators on current threats into the Intelligence Center.
  • Platform goal is tighter integration between the operation center and the intelligence center: observables now surface threat relationships and CTI context directly during alert investigation workflow.

Sekoia aims to be as close as possible to the users of the platform, meeting their needs in a precise way, while taking into account their approach and user experience. In this dynamic, the platform continues to reinvent itself and evolve by regularly integrating new features while improving existing features. Discover in this article, all the news published in October 2021.

Operation Center: New alert details page

Understanding an alert has never been that easy

Thanks to the new alert details page you will be able to :

  • Get an overview of the reasons why the alert was raised.
  • Create a Case from an alert or link it to an existing Case.
  • Consult the timeline of actions performed on an alert.
  • View and interact with the events linked to the alert.
  • Use Sekoia’s CTI during your investigations.

You can find all details in our documentation.

Intelligence Center

New feature: The observables page

In addition to the contextualized IoCs provided by Sekoia's CTI feed, we offer you now a qualified observable database to facilitate your monitoring.

Observables are technical elements structured in STIX, aggregated in our knowledge base, which are not necessarily IoCs but that facilitate monitoring and investigation. An observable can form a threat and can contain interesting information associated with a context allowing a quick doubt lifting on an alert raised.

How to use the Observables?

You need context on a raised alert and you can’t find the associated context in the IoCs database? You can look at the observables page now, you will find information that will guide your investigation through tags and relationships.

You can find all details in our documentation.

New observables: Dynamic Domains

A list of more than 5,000 dynamic domains has been added to the Sekoia.io Observables database. Dynamic domains are regularly used maliciously by threat actors or malware. 

It is complemented by a new detection rule (Dynamic DNS contacted) with a “Master” level of effort: often led to contextualize the rule when activated in order to reduce the false positive rate.

New exclusive source : Sekoia Twitter Watcher 

We have created a new source “SEKOIA Twitter Watcher” that automatically retrieves IOC’s from a qualified list of relevant Twitter accounts that share technical CTI on current threats.

Cyber Threat Intelligence

Actionable cyber threat intelligence for security teams that need to understand threats faster, focus on what matters, and operationalize intelligence across hunting, detection, and investigation.

Abstract circular icon with a central human figure surrounded by six connecting nodes.