WHATS NEW IN TDR TDR UPDATES This presentation

  • Slides: 44
Download presentation
WHAT’S NEW IN TDR

WHAT’S NEW IN TDR

TDR UPDATES • This presentation describes updates to: • • • Threat Detection and

TDR UPDATES • This presentation describes updates to: • • • Threat Detection and Response (TDR) This presentation does not describe: • Updates before July 2020 • Some small bug fixes For a complete list of enhancements and resolved issues by date, see the Threat Detection and Response Release Notes

JULY 2021

JULY 2021

Legacy TDR UI End-of-Life • The legacy TDR UI reached the End-of-Life (EOL) on

Legacy TDR UI End-of-Life • The legacy TDR UI reached the End-of-Life (EOL) on 22 July 2021 and is no longer available. All existing direct links to the legacy TDR UI are no longer in the Watch. Guard Portal, and existing bookmarks directly referencing your regional TDR account are now redirected to Watch. Guard Cloud. Release date: 22 July 2021 Watch. Guard Training Copyright © 2021 Watch. Guard Technologies, Inc. All Rights Reserved

MARCH 2021

MARCH 2021

Host Sensor License Details Tile • The Watch. Guard Cloud dashboard (Subscriber view) now

Host Sensor License Details Tile • The Watch. Guard Cloud dashboard (Subscriber view) now includes a TDR Host Sensor License Details tile. • The main Watch. Guard Cloud dashboard now shows four TDR tiles: o Host Status o Indicators o Remediations o Host Sensor License Details Release date: 25 March 2021 Watch. Guard Training Copyright © 2021 Watch. Guard Technologies, Inc. All Rights Reserved

TDR Dashboard is Now the Summary Page • The TDR Dashboard in Watch. Guard

TDR Dashboard is Now the Summary Page • The TDR Dashboard in Watch. Guard Cloud is now the Summary page. The TDR Summary page appears by default in the Monitor > Threat Detection menu. Release date: 25 March 2021 Watch. Guard Training Copyright © 2021 Watch. Guard Technologies, Inc. All Rights Reserved

FEBRUARY 2021

FEBRUARY 2021

Enhancements • Threat. Sync will now receive Firebox logs from Watch. Guard Cloud Visibility.

Enhancements • Threat. Sync will now receive Firebox logs from Watch. Guard Cloud Visibility. If your Firebox is connected to Watch. Guard Cloud, the Firebox logs will appear in Threat. Sync, even if the TDR feature is not enabled. • An updated version of Spanish online help is now available from Watch. Guard Help Center. To switch between languages in Help Center, in the top-right of the page, click the icon and select a language from the drop-down list. Release date: 18 February 2021 Watch. Guard Training Copyright © 2021 Watch. Guard Technologies, Inc. All Rights Reserved

JANUARY 2021

JANUARY 2021

Remediations Tile • The Remediations tile is now available on the main Watch. Guard

Remediations Tile • The Remediations tile is now available on the main Watch. Guard Cloud dashboard. Release date: 21 January 2021 Watch. Guard Training Copyright © 2021 Watch. Guard Technologies, Inc. All Rights Reserved

General Settings Page • The General Settings page is now available in Watch. Guard

General Settings Page • The General Settings page is now available in Watch. Guard Cloud in the TDR Configure menu. Navigate to Configure > Threat Detection and, in the Threat. Sync section, select General. Release date: 14 January 2021 Watch. Guard Training Copyright © 2021 Watch. Guard Technologies, Inc. All Rights Reserved

TDR Integration with Watch. Guard Cloud • TDR is now integrated with Watch. Guard

TDR Integration with Watch. Guard Cloud • TDR is now integrated with Watch. Guard Cloud. o Account Management — TDR now uses the accounts you create and manage from Watch. Guard Cloud. You no longer have to maintain two different account structures between Watch. Guard Cloud and TDR. o Inventory Management — You can now assign TDR licenses from your Service Provider account into a child Subscriber account in the same UI you use to assign Auth. Point licenses and perform all other inventory management in Watch. Guard Cloud. o Tier-2+ Operators — With the Watch. Guard Cloud integration, you now have the ability to create operators for tier-2 accounts with access to TDR. o Account Delegation — With the Watch. Guard Cloud integration, you can now delegate accounts that have TDR licenses to another Service Provider to manage. Release date: 5 January 2021 Watch. Guard Training Copyright © 2021 Watch. Guard Technologies, Inc. All Rights Reserved

TDR Integration with Watch. Guard Cloud o Tier-3 TDR accounts — Because tier-2 Service

TDR Integration with Watch. Guard Cloud o Tier-3 TDR accounts — Because tier-2 Service Providers are allowed to allocate inventory to their tier-3 accounts, they can now allocate Host Sensors to tier-3 accounts. TDR will be fully accessible in that tier-3 account. o Legacy TDR UI — You can still use the legacy TDR UI for all tier-1 accounts and all tier-2 accounts that were originally created in TDR. o TDR Subscriber tiles — Two TDR tiles show you aggregated information to give you a quick overview of your Subscriber account. These are the first of more tiles to come: ‣ Host Status ‣ Indicators Release date: 5 January 2021 Watch. Guard Training Copyright © 2021 Watch. Guard Technologies, Inc. All Rights Reserved

TDR Features in Watch. Guard Cloud • You can access the same pages as

TDR Features in Watch. Guard Cloud • You can access the same pages as the TDR web UI to manage TDR within Watch. Guard Cloud. • You can view TDR features in Watch. Guard Cloud from the Monitor and Configure menus. Release date: 5 January 2021 Watch. Guard Training Copyright © 2021 Watch. Guard Technologies, Inc. All Rights Reserved

TDR Left Navigation Monitor Menu in Watch. Guard Cloud • In the left navigation

TDR Left Navigation Monitor Menu in Watch. Guard Cloud • In the left navigation Monitor menu, you can select pages to monitor TDR. Release date: 5 January 2021 Watch. Guard Training Copyright © 2021 Watch. Guard Technologies, Inc. All Rights Reserved

TDR Left Navigation Configure Menu in Watch. Guard Cloud • In the left navigation

TDR Left Navigation Configure Menu in Watch. Guard Cloud • In the left navigation Configure menu, you can select pages to configure TDR. Release date: 5 January 2021 Watch. Guard Training Copyright © 2021 Watch. Guard Technologies, Inc. All Rights Reserved

DECEMBER 2020

DECEMBER 2020

TDR Integration with Watch. Guard Cloud • Updates to TDR to prepare for the

TDR Integration with Watch. Guard Cloud • Updates to TDR to prepare for the integration with Watch. Guard Cloud in January 2021. Release date: 10 December 2020 Watch. Guard Training Copyright © 2021 Watch. Guard Technologies, Inc. All Rights Reserved

Export Feature Now Supports Large Data Sets • The Export feature in the TDR

Export Feature Now Supports Large Data Sets • The Export feature in the TDR UI has been improved to support the download of large data sets. • The Export feature is available on these pages: o Threat. Sync > Indicators o Threat. Sync > Remediations o Devices / Users > Hosts o System > Audit Log Release date: 10 December 2020 Watch. Guard Training Copyright © 2021 Watch. Guard Technologies, Inc. All Rights Reserved

NOVEMBER 2020

NOVEMBER 2020

User-Based Threat. Sync Services • User-Based Threat. Sync Services are now publicly available. Release

User-Based Threat. Sync Services • User-Based Threat. Sync Services are now publicly available. Release date: 19 November 2020 Watch. Guard Training Copyright © 2021 Watch. Guard Technologies, Inc. All Rights Reserved

Threat. Sync > Remediation Page User Column • The Threat. Sync > Remediation page

Threat. Sync > Remediation Page User Column • The Threat. Sync > Remediation page now has a filterable User column. Release date: 12 November 2020 Watch. Guard Training Copyright © 2021 Watch. Guard Technologies, Inc. All Rights Reserved

Reset Page User Option • The Settings > Reset page now has a reset

Reset Page User Option • The Settings > Reset page now has a reset User option. • A user reset removes all users and indicator references, but does not remove the indicator. Release date: 12 November 2020 Watch. Guard Training Copyright © 2021 Watch. Guard Technologies, Inc. All Rights Reserved

OCTOBER 2020

OCTOBER 2020

User-Based Threat. Sync Services (Early Access) • Threat. Sync > Users — This new

User-Based Threat. Sync Services (Early Access) • Threat. Sync > Users — This new page shows a combined score for a user, based on the indicators attributed to that user. Only users with a threat score are shown on this page. Release date: 20 October 2020 Watch. Guard Training Copyright © 2021 Watch. Guard Technologies, Inc. All Rights Reserved

User-Based Threat. Sync Services (Early Access) • Color-coded logged indicator icons show the current

User-Based Threat. Sync Services (Early Access) • Color-coded logged indicator icons show the current status of users logged in to a computer with a Host Sensor installed. Release date: 20 October 2020 Watch. Guard Training Copyright © 2021 Watch. Guard Technologies, Inc. All Rights Reserved

User-Based Threat. Sync Services (Early Access) • The Indicators table shows all indicators attributed

User-Based Threat. Sync Services (Early Access) • The Indicators table shows all indicators attributed to that user. • The Hosts table shows a list of all endpoint devices that a user is logged in to. Release date: 20 October 2020 Watch. Guard Training Copyright © 2021 Watch. Guard Technologies, Inc. All Rights Reserved

User-Based Threat. Sync Services (Early Access) • Devices / Users > Users —This new

User-Based Threat. Sync Services (Early Access) • Devices / Users > Users —This new page shows all users detected by Threat. Sync and their login status. • Color-coded logged in indicator icons show the current status of users logged in to a computer with a Host Sensor installed. Release date: 20 October 2020 Watch. Guard Training Copyright © 2021 Watch. Guard Technologies, Inc. All Rights Reserved

User-Based Threat. Sync Services (Early Access) • Devices / Users > Users — This

User-Based Threat. Sync Services (Early Access) • Devices / Users > Users — This new page shows all users detected by Threat. Sync and their login status. Release date: 20 October 2020 Watch. Guard Training Copyright © 2021 Watch. Guard Technologies, Inc. All Rights Reserved

User-Based Threat. Sync Services (Early Access) • On the Devices / Users > Users

User-Based Threat. Sync Services (Early Access) • On the Devices / Users > Users page, on the Hosts tab, you can view a list of endpoint devices that a user is logged in to. Release date: 20 October 2020 Watch. Guard Training Copyright © 2021 Watch. Guard Technologies, Inc. All Rights Reserved

User-Based Threat. Sync Services (Early Access) • The Threat. Sync > Indicators page now

User-Based Threat. Sync Services (Early Access) • The Threat. Sync > Indicators page now includes a new User column to enable you to easily sort and filter indicators. Release date: 20 October 2020 Watch. Guard Training Copyright © 2021 Watch. Guard Technologies, Inc. All Rights Reserved

SEPTEMBER 2020

SEPTEMBER 2020

Whitelist is now Allowlist • In the TDR UI, the term Whitelist has been

Whitelist is now Allowlist • In the TDR UI, the term Whitelist has been replaced with Allowlist. • On the Indicators page, the Action Requested drop-down list has been updated. Release date: 3 September 2020 Watch. Guard Training Copyright © 2021 Watch. Guard Technologies, Inc. All Rights Reserved

Whitelist is now Allowlist • On the Signature Overrides page, the text in the

Whitelist is now Allowlist • On the Signature Overrides page, the text in the Manual Actions drop-down list has been updated to Allowlist. Release date: 3 September 2020 Watch. Guard Training Copyright © 2021 Watch. Guard Technologies, Inc. All Rights Reserved

Whitelist is now Allowlist • On the Threat. Sync > Hosts page, the text

Whitelist is now Allowlist • On the Threat. Sync > Hosts page, the text in the Manual Actions drop-down list has been updated to Allowlist. Release date: 3 September 2020 Watch. Guard Training Copyright © 2021 Watch. Guard Technologies, Inc. All Rights Reserved

Host Sensor Manual Update • You can now manually run a Host Sensor update

Host Sensor Manual Update • You can now manually run a Host Sensor update if previous auto-update cycles have failed—even with auto-update turned on. Release date: 3 September 2020 Watch. Guard Training Copyright © 2021 Watch. Guard Technologies, Inc. All Rights Reserved

JULY 2020

JULY 2020

TDR Online Help Localization • TDR Help is now available in French, Japanese, and

TDR Online Help Localization • TDR Help is now available in French, Japanese, and Spanish. • To switch between languages in Help Center, in the top-right of the page, click the icon and select a language from the drop-down list. • If localized Help is not available for a product, the icon does not appear. Release date: 30 July 2020 Watch. Guard Training Copyright © 2021 Watch. Guard Technologies, Inc. All Rights Reserved

Enhancements • Email notification subject lines now include more information and are easier for

Enhancements • Email notification subject lines now include more information and are easier for other applications to read. • Sensor Status notifications now include the description of the problem in the body of the email. • All reports now include the account name in the title page of the report. • The Host Sensor system tray icon now prevents application crashes due to process injection. • Files located in a Windows update directory are no longer eligible for APT Blocker Submission. • Files detected as corrupt by TDR are no longer eligible for APT Blocker Submission. Release date: 23 July 2020 Watch. Guard Training Copyright © 2021 Watch. Guard Technologies, Inc. All Rights Reserved

Machine Learning Enhanced Process Indicators • Machine Learning is now used to detect process

Machine Learning Enhanced Process Indicators • Machine Learning is now used to detect process indicators. This results in a higher detection rate of malicious processes. In the TDR UI, the text (ML) appears next to process indicators identified by machine learning. Release date: 7 July 2020 Watch. Guard Training Copyright © 2021 Watch. Guard Technologies, Inc. All Rights Reserved

Threat. Sync > Incidents Page Renamed to Threat. Sync > Hosts • The Threat.

Threat. Sync > Incidents Page Renamed to Threat. Sync > Hosts • The Threat. Sync > Incidents page is now Threat. Sync > Hosts. Release date: 7 July 2020 Watch. Guard Training Copyright © 2021 Watch. Guard Technologies, Inc. All Rights Reserved

Enhancements • The TDR UI now displays dates in DD/MM/YYYY format when UK English

Enhancements • The TDR UI now displays dates in DD/MM/YYYY format when UK English is selected in your browser. • You can now see who is logged in to a computer. • Indicator notifications now link directly to an indicator in the UI and are displayed even when remediated. • Corrupt executable files are not marked as ineligible for Sandbox Analysis by APT Blocker. • AD Helper now supports Java 11. • Indicators with a score of 0 and a sandbox result of Successful will now have a Previous Score. Release date: 7 July 2020 Watch. Guard Training Copyright © 2021 Watch. Guard Technologies, Inc. All Rights Reserved

THANK YOU

THANK YOU