Skip to main content

Cloud-delivered Incident ResponderIncident Responder Documentation

What's New

What's New in i63

Exabeam Cloud Search Service From Incident Responder

From Incident Responder, you can now search logs and run queries using the cloud-native Search application on the Exabeam Security Operations Platform. The Exabeam Cloud Search service is available in Incident Responder i62.5 and later and i63.6 and later.

What's New in i62

Turnkey Playbooks for Fusion Licenses

Note

We updated the release notes to include information about the availability of Incident Responder turnkey playbooks.

If you have a Fusion license, you can run turnkey playbooks even if you don't have Incident Responder.

To migrate a legacy license to a Fusion license, you must have Data Lake i40.4 and Advanced Analytics version i62.2. After you upgrade to these versions, Exabeam schedules your migration. To request that Exabeam prioritize your migration, contact your Exabeam representative or open a support case on the Exabeam Community.

To unlock additional features, like editing playbooks, creating and running custom playbooks, and integrating third-party services, you must have an Incident Responder add-on. To request the add-on, contact your Exabeam representative or open a support case on the Exabeam Community.

Exabeam Cloud Search Service From Incident Responder

From Incident Responder, you can now search logs and run queries using the cloud-native Search application on the Exabeam Security Operations Platform. The Exabeam Cloud Search service is available in Incident Responder i62.5 and later and i63.6 and later.

What's New in i61

This release does not include new features for Incident Responder.

What's New in i60

This release does not include new features for Incident Responder.

What's New in i59

This release does not include new features for Incident Responder.

What's New in i58

New Turnkey Playbooks for Behavior Analytics Incidents

Pre-configured playbooks for classifying and enriching Behavior Analytics incidents are ready for you to run.

When an Advanced Analytics user or asset session becomes notable, Case Manager automatically creates an incident with the Behavior Analytics incident type.

The Automated Incident Classification turnkey playbook analyzes the notable session to accurately classify the incident's type, helping you make sense of all the evidence in Advanced Analytics and quickly diagnose what threat you're investigating. It's important that incidents have the correct incident type so you standardize the evidence you collect and define tasks for investigating, containing, and remediating the incident.

The Automated Incident Enrichment turnkey playbook gathers critical information from the Advanced Analytics session and populates the Case Manager incident with additional contextual or evidence you need to investigate the incident.

Exabeam Documentation: Automated Incident Classification Turnkey Playbook

Exabeam Documentation: Automated Incident Enrichment Turnkey Playbook

What's New in i57

This release does not include new features for Incident Responder.