Contents and detection
A list of the improvements for the Contents and Detection that have been introduced in this release.
- The column for the field KEV is now also displayed and filterable in the vulnerability list view
- Improved the detection behind the alert type
SIGN:MULTIPLE-UNSUCCESSFUL-LOGINS
- Reduced the frequency of
SIGN:MALFORMED-TRAFFIC
alerts applying a cap of 10 alerts every 6 hours. The cap is applied pertrigger-id
per transmitting node - Improved the memory consumption to display the text of Threat Intelligence contents when available
- SEL discovered Common Platform Enumeration (CPE)s and vulnerability are now confirmed as high likelihood
- Improved detection for multiple unsuccessful logins based on secure shell (SSH) banners