Skip to content

Releases: panther-labs/panther-analysis

v1.33.1

15 Aug 20:19
70294f9
Compare
Choose a tag to compare
  • Slack and Cloudflare detections are now available in packs
  • Added alert context to AWS detections that did not previously have them
  • Modified the Cloudflare L7 DDoS to not alert on blocked events
  • Removed managed schemas

v1.33.0

04 Aug 01:44
d071b43
Compare
Choose a tag to compare
  • New Slack detections and data models
  • Added workaround for Identity Providers AWS Console Login without MFA
  • Added exclusion for Panther IAM roles in the AWS S3 Activity - Greynoise detection
  • New detection for AWS IAM Role - External Permission
  • Fixed GSuite summary attributes
  • Improved alert titles for GSuite Rule Triggers
  • Added template for CIDR lookup

v1.32.0

01 Jul 22:46
5b6ab8b
Compare
Choose a tag to compare
  • Added new CloudFlare detections
  • Added Confluence 0-Day IOCs
  • Removed workaround for global helper importing order
  • Updated Greynoise reference links
  • Update to MITRE ATT&CK mappings to align with the MITRE heatmap feature

v1.31.0

11 May 15:25
2c744ea
Compare
Choose a tag to compare
  • Add Panther Audit Log Detections
  • Update AWS Pack with missing Helper
  • Add GCP Helpers
  • GreyNoise Enhancements

v1.30.0

02 May 17:08
eb4af5c
Compare
Choose a tag to compare
  • Map all prebuilt detections to MITRE ATT&CK
  • Update to use Python 3.9
  • Various bug fixes

v1.29.1

08 Apr 20:00
36891f9
Compare
Choose a tag to compare
  • Add missing helper to Greynoise pack def

v1.29.0

04 Apr 19:38
32f8152
Compare
Choose a tag to compare
  • Add Support for Packs
  • Add GreyNoise Integration for Panther 1.32

v1.28.1

28 Mar 21:02
bda3f05
Compare
Choose a tag to compare
  • Various bugfixes for new Okta detections
  • Okta queries now disabled by default to prevent issues with instances containing no Okta logs

v1.28.0

23 Mar 19:58
9474ba9
Compare
Choose a tag to compare
  • Rule Tuning and Bug Fixes
  • Helper function for upcoming threat intel features
  • Large update to Okta detections
  • Addition of Okta investigative queries

v1.27.1

03 Mar 03:21
ebfb938
Compare
Choose a tag to compare
  • BUGFIX: Add missing data models to standard detections pack