Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

What's new in 8.15 #5508

Closed
17 of 22 tasks
natasha-moore-elastic opened this issue Jul 4, 2024 · 0 comments · Fixed by #5667
Closed
17 of 22 tasks

What's new in 8.15 #5508

natasha-moore-elastic opened this issue Jul 4, 2024 · 0 comments · Fixed by #5667
Assignees
Labels
Docset: ESS Issues that apply to docs in the Stack release Effort: Medium Issues that take moderate but not substantial time to complete highlights Priority: High Issues that are time-sensitive and/or are of high customer importance v8.15.0

Comments

@natasha-moore-elastic
Copy link
Contributor

natasha-moore-elastic commented Jul 4, 2024

Please add your features and enhancements for 8.15. Don't forget to include the related PR link!

Detections & Response

  • Add features here

Rules Management

Detection Engine

Threat Hunting

Explore

  • Add features here

Investigations

Entity Analytics

Generative AI

EDR Workflows/Asset Management

  • Scan files and folders for malware (Scan response action [ESS] #5563)
    Elastic Defend’s new scan response action lets you perform on-demand malware scans of a specific file or directory on a host. Scans are based on the malware protection settings configured in your Elastic Defend integration policy.

  • Filter out process descendants (Process descendant filtering in event filters [ESS] #5626)
    Create an event filter that excludes the descendant events of a specific process, but still includes the primary process itself. This can help you limit the amount of events ingested into Elastic Security.

  • Isolate and release CrowdStrike-enrolled hosts (CrowdStrike bidirectional response actions (isolate & release) #5529)
    Using Elastic’s CrowdStrike integration and connector, you can now perform response actions on hosts enrolled in CrowdStrike’s endpoint protection system. These actions are available in this release:

    • Isolate a host from the network
    • Release an isolated host
  • Retrieve files from SentinelOne-enrolled hosts (SentinelOne get-file response action [classic] #5499)
    Using Elastic’s SentinelOne integration and connector, you can now retrieve files from SentinelOne-enrolled hosts and download them through Elastic Security.

Cloud Security

  • Add features here

Endpoint

  • Add features here

Protections Experience

  • Add features here

ResponseOps

(@natasha-moore-elastic I pulled these from the Kibana What's new so they're good to insert as is.)

  • Introducing case templates - Kibana cases offer a new powerful capability to enhance the efficiency of your analyst teams with templates. You can manage multiple templates, each of which can be used to auto-populate values in a case with pre-defined knowledge. This streamlines the investigative process and significantly reduces time to resolution. (Add case templates #5565)
  • Case custom fields are GA - In 8.11, custom fields were added to cases and they are now moving from technical preview to general availability. You can set custom field values in your templates to enhance consistency across cases. (Case custom fields GA #5591)
@natasha-moore-elastic natasha-moore-elastic added highlights Priority: High Issues that are time-sensitive and/or are of high customer importance Effort: Medium Issues that take moderate but not substantial time to complete v8.15.0 labels Jul 4, 2024
@natasha-moore-elastic natasha-moore-elastic self-assigned this Jul 4, 2024
@natasha-moore-elastic natasha-moore-elastic added the Docset: ESS Issues that apply to docs in the Stack release label Aug 7, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Docset: ESS Issues that apply to docs in the Stack release Effort: Medium Issues that take moderate but not substantial time to complete highlights Priority: High Issues that are time-sensitive and/or are of high customer importance v8.15.0
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant