Skip to main content

Cyware Fusion and Threat Response

Release Notes 3.1.0

The new and enhanced version of our fusion and threat response platform, CFTR v3.1.0, comes with advanced capabilities to help your security teams effectively manage threat response.

New Features

Advanced Filtering with Cyware Query Language

Cyware introduces Cyware Query Language (CQL) in CFTR to build structured queries and retrieve relevant data. Analysts can also save and reuse the CQL queries. For example, to retrieve the high-priority IP Spoofing incidents that are in the open state, you can use the following CQL query:

"Status" = “Open” AND "Severity" = “High” AND "Incident Type" = "IP Spoofing"
MacBook_Pro_-_896__4_.jpg
Bulk Allocate User Access Controls

Administrators can now allocate the user access controls, such as Business Units, Locations, and User Groups, to multiple users at one go. For example, when a new business unit is added, administrators can allocate the business unit to multiple users.

1_User_Management_landing__3_.png
Connect the Dots Suggestions for Untriaged Incidents

Connect the Dots feature now displays suggestions for untriaged incidents using the CFTR Machine Learning algorithm. This helps security analysts to find related data and provide contextual information even before the incident triage is complete.

Screenshot_2022-09-20_at_4_06_04_PM.png

Enhancements

Pin Notes in Incidents

Security analysts can pin important notes in incidents and allow the stakeholders to easily find relevant information in one place.

Screenshot_2022-09-21_at_11_17_31_AM.png
RBAC for Dashboards and Reports

Cyware introduces Role-Based Access Control (RBAC) for users to view the data displayed on dashboards and reports based on their user groups, allowed locations, and allowed business units.

Incident Configuration Enhancements

CFTR v3.1.0 provides the following enhancements:

  • Pause SLA: Administrators can choose to pause resolution SLA when incidents are paused.

  • Incident Reopen: The time limit to reopen incidents is now increased from 48 hours to 90 days.

Screenshot_2022-09-20_at_4_23_41_PM.png
Request for Incident Field Update Notes

Administrators can configure incident fields to request analysts to enter notes for updating the field values. For example, to change the severity of incidents, analysts must enter the reason for the change. This helps incident managers and other security analysts to find the reason behind the change from the incident activity logs and notes.

Screenshot_2022-09-20_at_4_25_43_PM.png
Screenshot_2022-09-20_at_4_28_48_PM.png
Incident Export Template Enhancement

The Overview and Preparation phases in incident export templates are now made non-mandatory. Administrators can choose any phase or field to create incident export templates.

Incident Summary to Display Total Time Spent

In addition to the time spent on each incident response phase, the incident summary now displays the total time spent on an incident.

Screenshot_2022-09-21_at_11_31_15_AM.png
Dashboard Enhancements

CFTR v3.1.0 provides the following functionalities for the analysts to manage dashboards:

  • Set dashboard refresh intervals.

  • Delete unused custom widgets.

  • Pause and play rotating dashboards.

  • Set time intervals for rotating dashboards.

MacBook_Pro_-_903.jpg
MacBook_Pro_-_909.jpg
Other Enhancements
  • Perform a global search for the content added in the notes across all modules.

  • Preserve the filters that are applied on the incident listing when returning from an incident details page.

  • Filter incidents based on the closed dates.