Skip to content

What's new in 8.15 #5508

Closed
Closed
@natasha-moore-elastic

Description

@natasha-moore-elastic

Please add your features and enhancements for 8.15. Don't forget to include the related PR link!

Detections & Response

  • Add features here

Rules Management

Detection Engine

Threat Hunting

Explore

  • Add features here

Investigations

Entity Analytics

Generative AI

EDR Workflows/Asset Management

  • Scan files and folders for malware (Scan response action [ESS] #5563)
    Elastic Defend’s new scan response action lets you perform on-demand malware scans of a specific file or directory on a host. Scans are based on the malware protection settings configured in your Elastic Defend integration policy.

  • Filter out process descendants (Process descendant filtering in event filters [ESS] #5626)
    Create an event filter that excludes the descendant events of a specific process, but still includes the primary process itself. This can help you limit the amount of events ingested into Elastic Security.

  • Isolate and release CrowdStrike-enrolled hosts (CrowdStrike bidirectional response actions (isolate & release) #5529)
    Using Elastic’s CrowdStrike integration and connector, you can now perform response actions on hosts enrolled in CrowdStrike’s endpoint protection system. These actions are available in this release:

    • Isolate a host from the network
    • Release an isolated host
  • Retrieve files from SentinelOne-enrolled hosts (SentinelOne get-file response action [classic] #5499)
    Using Elastic’s SentinelOne integration and connector, you can now retrieve files from SentinelOne-enrolled hosts and download them through Elastic Security.

Cloud Security

  • Add features here

Endpoint

  • Add features here

Protections Experience

  • Add features here

ResponseOps

(@natasha-moore-elastic I pulled these from the Kibana What's new so they're good to insert as is.)

  • Introducing case templates - Kibana cases offer a new powerful capability to enhance the efficiency of your analyst teams with templates. You can manage multiple templates, each of which can be used to auto-populate values in a case with pre-defined knowledge. This streamlines the investigative process and significantly reduces time to resolution. (Add case templates #5565)
  • Case custom fields are GA - In 8.11, custom fields were added to cases and they are now moving from technical preview to general availability. You can set custom field values in your templates to enhance consistency across cases. (Case custom fields GA #5591)

Metadata

Metadata

Labels

Docset: ESSIssues that apply to docs in the Stack releaseEffort: MediumIssues that take moderate but not substantial time to completePriority: HighIssues that are time-sensitive and/or are of high customer importancehighlightsv8.15.0

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions