Home
Blog
New Sekoia features in July 2021

New Sekoia features in July 2021

Discover how the SEKOIA.IO platform continues to reinvent itself and evolve by integrating new features (Tracking of Chinese APT groups)
lighthouse with purple background

Key takeaways

July 2021 Sekoia update: 30 new CVE-focused rules, Hatching Triage CTI integration, ShadowPad tracking, and User Center multi-role improvements.

  • Thirty new detection rules were added in July 2021 covering five high-priority CVEs recommended for immediate activation: CVE-2018-13379 (Fortinet), CVE-2019-2725 (Oracle WebLogic), CVE-2019-11510 (Pulse Secure), CVE-2020-0688 (Exchange), and CVE-2018-11776 (Apache Struts 2).
  • Hatching Triage sandbox was integrated as a new CTI source, enriching the database with C2 IPs, domains, and hashes for ~20 malware families including Cobalt Strike, Agent Tesla, LokiBot, and IcedID.
  • C2 infrastructure monitoring for ShadowPad was strengthened, extending coverage of Chinese APT groups including APT41 and Winnti Group.
  • User Center improvements added multi-role assignment at invitation time and the ability to add users already known to Sekoia across communities without requiring a new email authentication flow.
  • A new 'Your community' page gives administrators a single-click view of first login dates and 2FA activation status for all community members.

Sekoia aims to be as close as possible to the users of the platform, meeting their needs in a precise way, while taking into account their approach and user experience. In this dynamic, the platform continues to reinvent itself and evolve by regularly integrating new features while improving existing features.

30 new detection rules added to the catalog

Since the previous month, 30 new rules verified by our analysts have been added to the Sekoia XDR rules catalog. To protect you against the TOP 10 most exploded vulnerabilities of the last two years, we strongly recommend you to activate the following rules:

  • CVE-2018-13379 (Fortinet FortiOS)
  • CVE-2019-2725 (Oracle WebLogic Server)
  • CVE-2019-11510 (Pulse Secure Pulse Connect Secure (PCS))
  • CVE-2020-0688 (Microsoft Exchange Server)
  • CVE 2018-11776 (Apache Struts 2)

These vulnerabilities are exploited ahead of ransomware attacks but also cyber spying attacks to gain initial access into their victims’ information systems.

Cyber Threat Intelligence updates

New intelligence source: Hatching Triage

Our CTI database includes a new source of technical intelligence with the integration of the European sandbox Hatching Triage. This new source will reinforce our coverage of the most active malware of the moment such as Cobalt Strike, Agent tesla, LokiBot or IcedID. It provides our CTI database with IPs / domain names of Command & Control (C2) and hashes of about twenty malware.

Tracking of Chinese APT groups

In June, we strengthened our monitoring of C2 malware infrastructures like ShadowPad used by several threat actors attributed to China like APT41 or Winnti Group.

What’s new in the User Center?

The invitations

The change of the invitation process makes it easier to :

  • Assigning multiple roles to users: Different roles can be assigned at the same time when sending the invitation.
  • Adding a user known to Sekoia: You can add existing users in other communities directly to a new one without going through the email invitation and authentication process.

Your community on Sekoia

The new “Your community” page now allows you to see with a single click:

  • The date of the first log-in for all community members.
  • The activation of the double authentication factor for all community members.

Cyber Threat Intelligence

Actionable cyber threat intelligence for security teams that need to understand threats faster, focus on what matters, and operationalize intelligence across hunting, detection, and investigation.

Abstract circular icon with a central human figure surrounded by six connecting nodes.