Release Notes 3.8
February 28, 2024
We are excited to introduce you to the latest version of Collaborate (CSAP) v3.8. This release includes new features and enhancements.
Member Portal
Threat Defender Library Enhanced
As a member, you can now utilize the enhanced user interface of TDL along with the improved threat defender content management. These are the key updates in the Member Portal:
You can now view related TDL content based on MITRE ATT&CK tactics, techniques, and sub-techniques directly from the content details page. Additionally, you can also access the ATT&CK Navigator directly from TDL, facilitating effective threat response strategies.
Experience an improved threat defender content creation process with the option to write custom code. This comes as an addition to the existing options of creating content using categories or uploading files directly from your local device.
If peer review is enabled for you, you can now submit your content to other members (peers) of your organization. Peers may subsequently submit your content to analysts for review. This additional step helps you in verifying and validating your content before it is published.
Access open-source intelligence (OSINT) content supported by Collaborate, now seamlessly integrated into TDL as part of the OSINT Repo.
For more information, see Threat Defender Library.
Security Workbench New
The Security Workbench feature now enables you to access open-source tools and resources such as Fang-Defang, STIX Converter, SPDX Converter, and more, to enrich your security operations.
For more information, see Security Workbench.
Intel Lake Enhanced
Intel Library is now renamed to Intel Lake in Collaborate.
Sorting is now available for Confidence Score, Created Date, and Modified Date columns in the Intel Lake listing.
You can now view the total number of threat intel objects related to an object in the Relations tab.
Analyst Portal
Threat Defender Library Enhanced
The Threat Defender Library (TDL) is now revamped with an enhanced user interface and improved threat defender content management. These are the key updates for the Analyst Portal:
You can now view related TDL content based on MITRE ATT&CK tactics, techniques, and sub-techniques directly from the content details page. Additionally, you can also access the ATT&CK Navigator directly from TDL, facilitating effective threat response strategies.
Experience an improved threat defender content creation process with the option to write custom code. This comes as an addition to the existing options of creating content using categories or uploading files directly from your local device.
As an analyst, you can enable the peer review process for members, which enables them to review each other's content before submitting it to analysts. For more information, see Configure TDL.
A few statuses have been introduced in TDL, such as Shared as Preview, Under Analyst Review, Declined by Analyst, and more. This provides improved organization and management of threat defender content.
TDL now features a revamped user interface that includes status widgets, making it easier to identify the number of content in various statuses.
For more information, see Threat Defender Library.
Other Enhancements
You can now automatically publish partner advisory feeds to Intel Exchange (CTIX). This helps you enrich IOC data in Intel Exchange (CTIX), for improved threat intelligence collaboration.
Intel Library is now renamed to Intel Lake in Collaborate.
Open API Enhancements
The Upload File endpoint now supports the individual_recipients
query parameter, which gives you the flexibility to pass individual recipients while uploading files to the Doc Library. For more information, see Collaborate (CSAP) API Reference.