Skip to content

Latest commit

 

History

History
702 lines (356 loc) · 32.9 KB

ReleaseNotes_c2206.2.md

File metadata and controls

702 lines (356 loc) · 32.9 KB

Security Content c2206.2 Release Notes

These Release Notes document security content updates from content package c2204.3 to c2206.2.

The security content updates listed below include changes to the following areas:

In the lists below, each item represents a specific parser, model, or rule that has been added, updated, or deprecated. To facilitate finding every data source where the changed content items are referenced, a content library query has been created for each changed parser, model, or rule. To view the results of each query, click on the link for the relevant content item.

Parsers

New Parsers

Updated Parsers

Deprecated Parsers

  • checkpoint-firewall-accept-1

  • checkpoint-firewall-allow-1

  • checkpoint-firewall-block

  • checkpoint-firewall-drop-1

  • checkpoint-firewall-reject

  • checkpoint-network-connection-1

  • checkpoint-network-connection-2

  • checkpoint-network-connection-3

  • checkpoint-network-connection-4

  • checkpoint-vpn-login-3

Models

New Models

There are no new models in this release.

Updated Models

  • A-FLSh-Count – Count of failed logons from host

  • EM-Gcountry – Email Countries sent to by peer group

  • UA-OC – Countries for organization

  • WEB-RCCount – Count of allowed web activity events with 3xx/4xx requests in a sequence

Deprecated Models

There are no deprecated models in this release.

Rules

New Rules

There are no new rules in this release.

Updated Rules

There are no updated rules in this release.

Deprecated Rules

  • A-NET-Coin-IP – com.exabeam.releasenotesgeneratortool.UseCase@6ddf90b0

  • WEB-Shadow-Mining-IP – com.exabeam.releasenotesgeneratortool.UseCase@57536d79