> ## Documentation Index
> Fetch the complete documentation index at: https://docs.wirespeed.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Changelog

> Latest updates and improvements to Wirespeed

Stay up to date with the latest features, improvements, and fixes to the Wirespeed platform.

<Update label="Aug 3, 2026">
  **Features**

  * Ask Wirespeed on advanced events builds SIEM queries for you
  * Security overview PDF auto-downloads when generation finishes
  * Imported external custom detection rules support Always Notify
  * Service providers with no clients can be deleted from team settings
  * Syslog integrations can be enabled and disabled from the UI

  **Detection & Integrations**

  * CrowdStrike ProcRansomware recategorized to endpoint execution
  * Palo Alto Spam Bot Traffic recategorized to outbound connection
  * Okta login failures recategorized to brute force
  * Process URL domains extracted in detections
  * Apple Private Relay and Google One VPN logins triaged as trusted relays

  **Improvements**

  * Advanced Events action renamed to "Create Custom Detection"
  * Custom detection event timestamps preserved correctly
  * Explore filters no longer include internal fields
  * Custom detection confirm button says "Create" for non-service-provider accounts
</Update>

<Update label="Jul 31, 2026">
  **Features**

  * New OAuth Grant identity verdict category for suspicious app authorizations
  * Remediation page shows Actions Taken and Potential Actions tabs
  * Home page remediation card links to the remediation list

  **Detection & Integrations**

  * Microsoft inbox rule update detections parse actionable rule changes
  * Nation-state IP detections recategorized to login
  * Identity SKU scopes Microsoft integration to identity and email coverage

  **Improvements**

  * Time range preset reads "Last 24 hours" instead of "Last 1 day"
  * Syslog integration settings save correctly again
  * Chat-ops test cases show a disclaimer in messages and summaries
</Update>

<Update label="Jul 30, 2026">
  **Detection & Integrations**

  * Microsoft UAL device-registration detection fixed
  * [Google Chronicle](/integrations/google-chronicle) reliability fixes
  * Picus attack simulation matching improved
  * Gmail send destinations extracted from Google Directory events
  * Identity login hunts restored for policy-blocked sign-ins
  * Wirespeed integration health now reflects custom detection sync errors
  * Microsoft credential-theft and malware alerts re-categorized
  * SentinelOne brute-force logins now categorized

  **Improvements**

  * Chat-ops verdict rules skipped when delivery policy blocks messaging
  * Credential reset flow fixed
  * Logout fixed
  * Device-code multi-device rule deduped by device ID
  * Asset deduplication fully rolled out
  * SIEM Explore histogram fixed
  * Remediation log entries now link to the affected asset
  * SIEM Explore hides empty event tables and the Legacy tab
</Update>

<Update label="Jul 29, 2026">
  **Features**

  * SIEM Explore is the default events view — Legacy Basic kept with a migration banner
  * Detections, cases, and asset pages embed SIEM 2.0 event views
  * Service Provider Live Support — chat goes straight to a human agent
  * Team switch triggers a full page refresh
  * Custom detections can Always Notify
  * MSP nav shows client count again
  * Asset detail source tables default to showing all records
  * Centralized login support for logout and SSO callbacks

  **Detection & Integrations**

  * [Admin By Request](/integrations/admin-by-request) integration added
  * [Google Chronicle](/integrations/google-chronicle) syncs live rules
  * Google Apps Script Gmail OAuth managed detection rule
  * Palo Alto Cortex categorization updates
  * Palo Alto remediation support
  * Attack simulation matching uses destination hostnames

  **Improvements**

  * "Switching teams" toast is now silent
  * Webhook rate limit raised to 3,000/min per team
  * ChatOps slider hidden for endpoint-only groups
</Update>

<Update label="Jul 28, 2026">
  **Features**

  * ChatOps detection activity shows on case timelines
  * Attack sim verdicts fall back to related endpoints after an API miss
  * API actions show the API key name instead of a pseudo-email
  * Sortable MSP client metric columns
  * Async PDF generation UI
  * Multiple support chat sessions supported

  **Detection & Integrations**

  * Microsoft nation-state and credential detector categorization
  * Okta external user identification
  * Okta intermediate auth events no longer treated as failed logins
  * [Vectra](/integrations/vectra) endpoint hostname mapping fixed
  * Azure device owner and user ops allowed in managed detection rule

  **Improvements**

  * Support chat autoscroll fixed
  * User-agent pill back in What Happened
  * Halo inbound ticket closure detection improved
</Update>

<Update label="Jul 23, 2026">
  **Detection & Integrations**

  * [Halo ITSM](/integrations/halo-itsm) tickets close via the Actions endpoint

  **Improvements**

  * Webhook retries use exponential backoff
  * Always Notify groups skip chat-ops verdict rules
  * Removed the 15-minute remediation cooldown, so repeat detections re-remediate
</Update>

<Update label="Jul 22, 2026">
  **Detection & Integrations**

  * Residential proxy verdict matches narrowed
</Update>

<Update label="Jul 21, 2026">
  **Features**

  * TOR login rule can trigger password reset
  * LOTL non-technical rule retired

  **Improvements**

  * Detection dashboard and case search performance improved
  * Residential proxy removed from anonymized login rule
</Update>

<Update label="Jul 20, 2026">
  **Improvements**

  * Logout reliability fix
</Update>

<Update label="Jul 17, 2026">
  **Features**

  * [Tracebit](/integrations/tracebit) integration added
  * Device-code multi-device registration detection
  * Anonymized-login managed detection rule
  * Managed detection rules can be disabled per rule
  * Password reset routes through OAuth when centralized login is enabled
  * Custom Detections nav renamed to Detection Rules

  **Detection & Integrations**

  * [Sandfly](/integrations/sandfly) marked beta with informational categorization

  **Improvements**

  * Auth0 existing users and pending invites handled on login
  * LOTL timeline messages no longer say "for AI analysis"
</Update>

<Update label="Jul 16, 2026">
  **Features**

  * [Tenable Nessus](/integrations/tenable-nessus) attack simulation integration
  * Managed detection rules centralized
  * Ask Wirespeed chat tools scoped by user role
  * Team switcher shows your current team
  * Phone number and onboarding flow updates
  * Trial users must accept terms of service
  * SSO registration redirects handled in auth callbacks

  **Detection & Integrations**

  * CyberArk renamed to Idira (formerly CyberArk)
  * Microsoft Graph sign-in logs skipped when UAL is enabled

  **Improvements**

  * Azure RBAC false-positive escalations fixed
</Update>

<Update label="Jul 15, 2026">
  **Features**

  * Verdict rules can Remediate and Correlate & Resolve without escalating
  * File detail page shows enrichment inline, no more JSON popups

  **Detection & Integrations**

  * [Freshservice](/integrations/freshservice) integration added
  * [Cortex](/integrations/palo-alto-networks-cortex) imports custom detection rules
  * [PingOne](/integrations/ping-one) now syncs directory users
  * VIP and HVA group checks apply across grouped endpoints and users

  **Improvements**

  * Manual remediations skip the 15-minute remediation cooldown
  * Chat-ops verdict rules are skipped when no chat integration is connected
</Update>

<Update label="Jul 14, 2026">
  **Features**

  * Ask Wirespeed can present choice pickers in chat
  * Case details show Time To Detect, Verdict, Remediate, and Close
  * Support chat keeps connecting until an agent answers, and you can reconnect after a session ends

  **Detection & Integrations**

  * [Okta](/integrations/okta) now supports session revoke and password reset remediation
  * [SentinelOne](/integrations/sentinel-one) fixed an issue with manual file quarantine and release
  * [Vectra](/integrations/vectra) severity thresholds raised
  * Entra Windows Server devices correctly join the SERVER group
  * Cortex Cyberint alerts categorized (phishing, DMARC, credential exposure, and more)
  * Better enrichment for CrowdStrike, Sophos, Cortex, and Microsoft detections
  * Microsoft Purview policies no longer import as custom detections

  **Improvements**

  * Lateral movement verdicts retuned
  * Long asset lists in What Happened truncate after three items
  * Exclusion next steps only suggested for privileged file paths
  * Grouped Endpoints/Users filter renamed to "Show grouped only"
  * Clearer remediation timeline messages when actions aren't supported
  * Homepage and PDF detection counts clarify escalated vs total
</Update>

<Update label="Jul 10, 2026">
  **Detection & Integrations**

  * [NinjaOne](/integrations/ninjaone) organization picker for scoping which orgs to ingest
  * [JumpCloud](/integrations/jumpcloud) token exchange and asset field sync fixed
  * [Cisco Umbrella](/integrations/cisco-umbrella) sync tracks each log type separately
</Update>

<Update label="Jul 9, 2026">
  **Features**

  * Grouped Endpoints — the same device across integrations now shows as one row, with per-integration sources on the detail page
  * Grouped Users — same for directory users synced from multiple integrations

  **Detection & Integrations**

  * [Fleet](/integrations/fleet-dm) integration added for endpoints and logs
  * [PingOne](/integrations/ping-one) improved rate limit handling
  * [Halo ITSM](/integrations/halo-itsm) validates claims on enable
  * Known-unsafe IP login rule re-enabled by default

  **Improvements**

  * Billable user and endpoint counts now come from nightly snapshots (\~01:30 UTC)
  * Team Analytics and the Clients page show whether counts are from license or snapshot data
  * ScreenConnect relay matching uses connection params, not just the binary name
  * Windows event log titles use the message field
  * Detections now show time-to-detect and time-to-verdict
  * Support chat auto-scrolls and flashes the tab title on unread replies
  * Asset tags no longer stretch full width
</Update>

<Update label="Jul 8, 2026">
  **Features**

  * Groups can now Always Notify — detections on managed assets escalate instead of auto-resolving
  * Clearer timeline messages when a case closes after monitoring
  * Category column added to the case detections table
  * Authentication baselines cover privacy services (VPN, relay, proxy, TOR) — not just VPN

  **Detection & Integrations**

  * [NinjaOne](/integrations/ninjaone) supports organization separation for MSSPs
  * [PingOne](/integrations/ping-one) no longer retries expired risk evaluations
  * Improved detection of mass email bursts
  * Remediation summaries now list the remediation actions taken

  **Improvements**

  * Cases severity filters and widgets now use case severity consistently
  * Related cases and detections stack full-width on asset pages
  * White-label platform names restored in case timelines
  * Support chat attachments load correctly
  * Fewer false positives on trusted relay logins (Apple Private Relay, Google One VPN)
  * Advanced IP Scanner added to the tool catalog
  * ScreenConnect relay hosts extracted from process command lines
  * Better authentication log matching for login detections
  * [Halo ITSM](/integrations/halo-itsm) 4xx responses no longer fail ticket updates
</Update>

<Update label="Jul 6, 2026">
  **Features**

  * New suddenly-active lateral movement hunt — dormant users who suddenly move laterally get escalated
  * Residential proxy login rule is now on by default

  **Detection & Integrations**

  * [Picus](/integrations/picus) correlation now matches on agent hostname
  * [Google Security Center](/integrations/google-security-center) auth and permission checks fixed

  **Improvements**

  * Historic auto-close is paused during systemic platform outages
</Update>

<Update label="Jul 2, 2026">
  **Features**

  * [Okta](/integrations/okta) can now unsuspend users on release
  * [SentinelOne](/integrations/sentinel-one) Vigilance-managed detections are recognized like Falcon Complete
  * Improved loading time of cases page
  * Full events search: clearer loading, better facet sync, and a 1-day default lookback

  **Improvements**

  * Cases can still auto-close when a third party is managing the detection
  * Identity SKU teams only see Microsoft entitlements that apply to them
  * Support chat handles disconnects and idle timeouts more gracefully
  * [CrowdStrike](/integrations/crowdstrike-falcon) and [Halcyon](/integrations/halcyon) detection cursors stabilized
</Update>

<Update label="Jul 1, 2026">
  **Features**

  * Case closure now collects feedback and an optional comment instead of a verdict
  * Revamped timeline UX
  * Escalated cases badge now opens the filtered cases list
  * Group rule preview highlights matching text
  * Exclusion rules can now target custom asset groups by name

  **Detection & Integrations**

  * [Cisco Duo](/integrations/cisco-duo) remediation and release actions fixed
  * Slack webhooks can now be enabled or disabled from the integration link
  * Identity integrations now support OAuth credentials
  * Identity SKU teams now process only identity and email detections
  * Better MFA classification for Microsoft and Entra sign-in logs
  * New endpoint lateral movement burst detection rule

  **Improvements**

  * Case escalation webhooks now include a richer payload and remediation timestamps
  * Team inbox changes are now recorded in system logs
  * Clearer directory email search behavior
  * Duplicate case file warnings consolidated into a single banner
</Update>

<Update label="Jun 29, 2026">
  **Features**

  * [NinjaOne](/integrations/ninjaone) integration added
  * [Sandfly](/integrations/sandfly) integration added
  * [Fleet](/integrations/fleet-dm) is coming soon
  * Custom rule provenance badge on the detection page
  * Platform invites now resend every 7 days

  **Improvements**

  * PDF donut charts render small segments more accurately
  * Billable asset counts now align with canonical dedupe
</Update>

<Update label="Jun 25, 2026">
  **Features**

  * Mean Time to Respond (MTTR) now shown in the case details view
  * Remediation actions are now included in escalation webhooks

  **Improvements**

  * Verdict and severity badges always show on detection details
  * Cleaner collapsed left navbar
  * CSV event exports are now named `events.csv`
  * Failed remediation actions now return a clear error instead of a generic failure
  * Better endpoint clustering when integrations report a short hostname vs. an FQDN
</Update>

<Update label="Jun 24, 2026">
  **Features**

  * Time to Close badge on the detection details page

  **Improvements**

  * Restored 30-day auth IP patterns
</Update>

<Update label="Jun 23, 2026">
  **Features**

  * [OneLogin](/integrations/onelogin) integration added
  * Escalated open case count now shows as a badge in the nav and dashboard funnel
  * Onboarding setup guide can now be dismissed
  * Custom detections table now shows when it was last edited
  * Rule ID search added to categorization integration and group pages
  * Integrations can now offer multiple authentication methods

  **Detection & Integrations**

  * [Google Security Center](/integrations/google-security-center) now supports Workload Identity Federation auth
  * [Sophos](/integrations/sophos) can now acknowledge detections in the source (now GA)
  * Better [Axonius](/integrations/axonius) endpoint vs. server classification
  * Remediation dialog hides actions your integrations don't support

  **Improvements**

  * Maximized Ask Wirespeed chat now stays within the viewport
  * Faster Cases funnel loading
  * Cases by Client moved below the noise reduction funnel on the service provider dashboard
  * Request an integration form now lets you pick multiple use cases
  * Fixed the integration deletion UI
  * Clearer copy for non-redirect OAuth integrations
</Update>

<Update label="Jun 18, 2026">
  **Features**

  * Full-screen Ask Wirespeed page with deep-linkable conversations
  * Asset platform now shown in user and endpoint hover cards

  **Improvements**

  * Directory listing now respects the "all" filter
  * Mobile styling fixes
  * Fixed breadcrumbs showing integration UUIDs
</Update>

<Update label="Jun 16, 2026">
  **Features**

  * Revamped command palette `Cmd+K` now runs commands, not just search. It's context-aware, so opening it from a case, user, or endpoint surfaces that page's actions, plus global commands like opening AI chat, jumping to Events, or setting your timezone
  * Integration health surfaced in the left navigation

  **Detection & Integrations**

  * [Cortex XDR](/integrations/palo-alto-networks-cortex) file quarantine and restore actions
  * [Halcyon](/integrations/halcyon) file quarantine
  * [JumpCloud](/integrations/jumpcloud) lock pins surfaced on the endpoint detail page

  **Improvements**

  * JSON event filters append to your existing search instead of replacing it
  * Sidebar asset counts match table totals
</Update>

<Update label="Jun 15, 2026">
  **Features**

  * Filter connected integrations by category, with a new category column
  * New Integrations widget on the home dashboard

  **Detection & Integrations**

  * Better [Okta](/integrations/okta) detection user extraction
  * Cleaner [Thinkst Canary](/integrations/thinkst-canary) extraction and titles
  * Fixed [Microsoft](/integrations/microsoft) entitlement state
</Update>

<Update label="Jun 11, 2026">
  **Features**

  * Integrations can now be reconnected with a new OAuth reconnect button
  * Verdicts now run attack simulation checks on deception cases

  **Detection & Integrations**

  * [Cisco Duo](/integrations/cisco-duo) now ingests activity logs
  * [Jamf Protect](/integrations/jamf-protect) shows primary file evidence when no related files are present
</Update>

<Update label="Jun 10, 2026">
  **Features**

  * New mass email send monitor
  * Critical defect rate tile added to Team Analytics
  * Faster Team Analytics CSV export
  * Regex group exclusion rules now display clearly

  **Improvements**

  * Fixed a crash in the JSON query viewer with very large queries
</Update>

<Update label="Jun 9, 2026">
  **Features**

  * Noise reduction funnel added to Team Analytics

  **Detection & Integrations**

  * Improved [Palo Alto Cortex](/integrations/palo-alto-networks-cortex) detection mapping
  * Warns when custom detection preview rows lack extractable asset fields

  **Improvements**

  * Refined dashboard statistics
  * Restored "see all" source info on the users page
  * Fixed a team inbox submission loop and partial-email submits
</Update>

<Update label="Jun 8, 2026">
  **Features**

  * Users and endpoints can now be exported to CSV
  * Users table now shows only enabled endpoints by default
  * Team Analytics now shows MTTV, MTTD, MTTC, and MTTR snapshot cards
  * PDF reports now include a Mean Time to Remediate widget
  * Home dashboard loads faster with per-card loading skeletons

  **Detection & Integrations**

  * Better [Horizon3](/integrations/horizon3) attack simulation matching
  * [CrowdStrike](/integrations/crowdstrike-falcon) Falcon bulk download support
  * Login verdicts now prioritize a managed device over a residential proxy
  * Improved Google OAuth event parsing

  **Improvements**

  * Time to remediate badge now shows human-readable durations
  * Detections list resets to the first page when filters change
  * Cleaner case timeline log when a case closes
  * VPN totals now match the displayed counts
  * Rewrote the verdict timeline override message in third person
</Update>

<Update label="Jun 5, 2026">
  **Features**

  * Dashboards now show Mean Time to Remediate
  * Team Analytics now shows SIEM event count and ingest size
  * Successful login locations moved to Team Analytics
  * Users table can filter by ChatOps SMS enrollment status
  * Ask Wirespeed can explain escalations using your verdict rules

  **Detection & Integrations**

  * [JumpCloud](/integrations/jumpcloud) can now lock macOS devices
  * [Microsoft](/integrations/microsoft) setup now shows tenant name and default domain
  * Microsoft OAuth setup now stops early when license validation fails
  * Attack simulation integration logs now show successful checks too

  **Improvements**

  * Integration deletion now runs in the background with a "Deleting..." state
  * Endpoint assets now default to live endpoints
  * Remediation skips actions an integration does not support
</Update>

<Update label="Jun 3, 2026">
  **Features**

  * New Ask Wirespeed card on your dashboard — kick off an AI chat right from the home page
  * Cases over time moved to Team Analytics

  **Improvements**

  * Clearer escalated-cases card subtitle copy
  * Clearer chat-ops timeline message for unmanaged users
</Update>

<Update label="Jun 2, 2026">
  **Features**

  * Home dashboard refresh: stats now span 90 days, with new Noise Reduction and Remediation Actions Taken cards
  * Service provider dashboard now has a noise reduction funnel (mobile included)
  * Case timeline timestamps now sit below each entry
  * SP Clients table shows a File Auto Remediation column and a Data add-on label (ADR + Data)

  **Detection & Integrations**

  * [Sophos Central](/integrations/sophos) EDR integration added (beta) for endpoint threat detections and telemetry
  * [Microsoft Defender](/integrations/microsoft) can now quarantine files on endpoints
  * [Odoo Helpdesk](/integrations/odoo-helpdesk) is out of beta
  * Better [SafeBreach](/integrations/safebreach) attack simulation matching
  * Coming soon integrations now appear in the browse catalog with a "Notify me" button
  * New residential proxy login rule — flagged malicious with sessions revoked
  * Timeline now reads "\$source mitigated" when a detection was prevented at the source
  * CrowdStrike automated leads now come in as Low and auto-close
  * Optimized enrichment across CrowdStrike, Jamf, Defender, and SentinelOne
</Update>

<Update label="May 27, 2026">
  **Improvements**

  * Scaled up our parsing cluster for steadier, higher-throughput syslog ingestion
  * AI timeline summaries expand when truncated
</Update>

<Update label="May 26, 2026">
  **Improvements**

  * Action buttons no longer overlap long source names
  * Fixed team analytics chart axes on the all-time timeframe
  * Fixed misalignment in the remediation breakdown chart
</Update>

<Update label="May 22, 2026">
  **Detection & Integrations**

  * Better [Picus](/integrations/picus) simulation matching

  **Improvements**

  * AI origin-hunt reports now render markdown formatting
  * Clearer login-screen messaging for Control credentials
  * Failed-jobs pill now filters to failed jobs
  * Fixed double counting in noise reduction stats
  * Fixed incorrect noise reduction in the PDF security overview
  * Fixed queue details link navigation
</Update>

<Update label="May 21, 2026">
  **Features**

  * MTTR and MTTC got renamed — MTTC is Mean Time to Close, MTTR is Mean Time to Remediate
  * Microsoft Cloud Apps policies sync as external detections
  * Timeline links to Detection Events preserve the time range
  * Case threat indicators list is now paginated

  **Detection & Integrations**

  * [Idira (formerly CyberArk)](/integrations/cyberark) beta integration for Privilege Cloud audit events and directory users
  * Endpoint discovery and nuisance default to suspicious
  * SentinelOne "Unusual addition of credentials to an OAuth app" categorizes as identity persistence
  * Improved Okta log ingestion parsing
  * Microsoft Defender XDR Sharepoint URL click detections categorize as email malware

  **Bug Fixes**

  * Fixed issue with add-on toggles on subscription tiles
  * Cleaned up AI chat titles to summarize your inquiry
  * TOR login detections no longer show as auto-closed after failed remediation
  * Monitor completion timeline entries show up on close
  * Check Point Harmony handles malformed scopes and skips unavailable update source actions
  * External and NHI users are skipped for Chat Ops SMS onboarding invites
</Update>

<Update label="May 19, 2026">
  **Features**

  * Security Overview PDF funnel chart got a visual refresh
  * Security Overview PDF new-assets section only counts managed endpoints and users
  * Date range filters work with just a start date — end date defaults to now
  * Escalated cases always notify the customer, no minimum severity gate
  * Copy button on the Source Details JSON viewer

  **Bug Fixes**

  * Notification toggles and frequency dropdowns update instantly
  * Integration logs reset to page 1 when you change filters
  * System Log filter clear (X) resets the date range to all time

  **Detection & Integrations**

  * CrowdStrike Falcon Automated Lead "SuspiciousRMMUsage" categorizes as remote management
</Update>

<Update label="May 14, 2026">
  **Features**

  * User API keys are now team API keys — manage them all under [Team Settings](/settings/team)
  * Attach AI chat transcripts to a case or detection, then revisit them from the new Chats tab
  * Copy AI chat responses with a one-click Copy button
  * Verdict rule outcomes now spell out the actual actions, like "Contain User (Revoke Sessions)"
  * Asset remediate modal and hover cards only show remediation actions the linked integration actually supports
  * Remediation History now lists attempts blocked by team config with a "blocked" badge
  * New Cloud Public Bucket detection category with a real-time anonymous S3 listability check

  **Detection & Integrations**

  * Microsoft Defender for Endpoint indicators are now pulled in as external detection rules
  * Microsoft Graph alerts fall back to `AlertFoldedOnUser` when no other user evidence is present
  * Microsoft OAuth setup now links to docs when it fails with `AADSTS50097` (Conditional Access device required)
  * Improved categorizations of Stairwell detections
  * Microsoft DfE "Sensitive information theft activity via SAM" categorizes as endpoint discovery
  * "Notification of quarantined emails" categorizes as email phishing
  * SentinelOne STAR rules sourced from Microsoft Entra ID categorize as identity login
  * More categorization updates across CrowdStrike Falcon, Microsoft Defender, SentinelOne, Vectra, and Palo Alto Cortex
  * Picus simulation matching now covers extra Picus folders

  **Bug Fixes**

  * Timeline comments show the author's name instead of their email, with their team appended for cross-team comments
  * Partial IP search like `10.` now actually returns results
  * Integration log filter dropdown resets when you clear it
  * Donut charts with a single category render cleanly without a gap
  * Stairwell detections no longer create a ghost "object" file
  * Auto remediation messages no longer repeat the same group name
</Update>

<Update label="May 11, 2026">
  **Features**

  * Security Overview PDFs are now available underneath Team Analytics!
  * Beta integrations now require acknowledgement before setup
  * [Exium](/integrations/exium) integration added for syslog events

  **Detection & Integrations**

  * Login and rejected MFA timelines now link to the matching authentication event
  * Detection Events searches now include usernames and email local parts
  * Verdict rules can now resolve detections when ChatOps times out
  * Stairwell threat report matches now process as detections

  **Bug Fixes**

  * Team Analytics date ranges now cap at one year with a helpful toast
  * All-time case trends now choose smarter chart granularity
  * Service provider teams can no longer create integrations directly
  * Integration deletion is much faster
  * Security Overview PDFs now show case trend axes reliably
  * Asset cards no longer clip descenders in names
</Update>

<Update label="May 5, 2026">
  **Features**

  * Team Analytics now supports custom date ranges
  * System Log now captures more platform activity, from remediation to team changes

  **Detection & Integrations**

  * Cisco Meraki, FortiAnalyzer, HYAS Protect, and ManageEngine syslog events now have more resilient parsing
  * Palo Alto Cortex source updates now use the right resolved status
  * Palo Alto Cortex endpoint sync handles comma-separated IPs
  * Integration logs now show successful source updates
</Update>

<Update label="May 1, 2026">
  **Features**

  * Settings reorganized into a tabbed layout: Account, Team Members, Your Profile, Notifications
  * Detections and Cases page widgets now respect the page filters, not just the time selector
  * System Log now has type, status, and date filters plus a per-entry detail view
  * Users page swaps the static User Types pie for a data-driven Top Groups chart that syncs with the group filter
  * Request an integration form added to the catalog: if you don't find what you're looking for, make a request
  * First-time chat-ops setup now requires a confirmation step before sending messages
  * ChatOps emails now come from no-reply so recipients can't reply back into the thread
  * Nav switcher search now finds teams under matching service provider rows
  * Sibling-detection remediation is attributed back to the originating detection in timelines instead of looking like a duplicate
  * Group filter dropdown scrolls cleanly on tall lists

  **Detection & Threat Intelligence**

  * Okta "end user reported suspicious activity" is now ingested as a detection and mapped to rejected MFA
  * Jamf Protect detections use match metadata for the finding info and emit related users and processes as evidence
  * LOTL AI timeline collapses to a single line with classification and confidence
  * `ncat.exe` added to the tool catalog
  * Categorization updates across CrowdStrike, Defender for Office, Defender for Cloud, and SentinelOne

  **Bug Fixes**

  * Team Analytics is responsive on smaller screens
  * Platform logo upload errors now name the size or format issue
  * Detection user matching now checks alias emails on directory users
</Update>

<Update label="Apr 29, 2026">
  **Features**

  * Heads up: if you use the legacy Microsoft Teams ChatOps integration, migrate to the new [Microsoft Teams integration](/integrations/microsoft-teams) by May 31, 2026 or you'll lose Teams ChatOps
  * Group tags moved to the asset page header with inline add and remove
  * Microsoft license tracking expanded to cover Microsoft 365 Business Standard and Apps for Business SKUs

  **Detection & Threat Intelligence**

  * Picus simulation matching now correlates detections using relative paths, command filenames in staging directories, and cases with no agent IP
  * Jamf Protect persistence tags now map to endpoint persistence
  * SentinelOne STAR Office 365 DLP policy deletion now maps to data share
  * CrowdStrike IDP unusual workstation network logon now maps to lateral movement
  * CrowdStrike IDP protocol anomaly on valid accounts now maps to identity persistence
  * Cortex "New FTP Server" is categorized as informational
  * Jamf Protect categorization rules use a more reliable match field

  **Bug Fixes**

  * IP asset search no longer errors when searching URL-like or slash-containing values
  * Custom attribute searches strip backslashes from keys
</Update>

<Update label="Apr 27, 2026">
  **Features**

  * Search and group users or endpoints by any raw source attribute, with a visual query builder
  * Microsoft license sync includes Office 365 licenses
  * SentinelOne notes sync back to source alerts

  **Detection & Threat Intelligence**

  * Check Point Harmony detections have cleaner, structured descriptions
  * Google Security Command Center detections include better titles and deep links
  * Jamf Protect detections highlight the blocked file, not the reporting process
  * Benign shared files no longer create threat indicators
  * SentinelOne D-Bus service alerts map to endpoint persistence

  **Performance & Reliability**

  * Service provider integration pagination stays clickable during refreshes
  * Integration log timestamps render in the right timezone
</Update>

<Update label="Apr 24, 2026">
  **New Integrations**

  * [WatchGuard Firebox](/integrations/watchguard-firebox) integration added for syslog events

  **Features**

  * Detections and cases can now be filtered by group
  * Service provider clients can now be sorted by subscription
  * CrowdStrike file deletion remediation is now available
  * Endpoint live status now uses vendor last-seen timestamps
  * Suspicious verdict badges now show on open detection details

  **Detection & Threat Intelligence**

  * WDC categorization rules updated across Okta, CrowdStrike, SentinelOne, and Microsoft
  * External custom detection categorization now uses only accepted categories
  * Live-off-the-land file risk now takes priority over remote management tooling
  * TruffleHog is treated as discovery tooling instead of live-off-the-land
  * Automatic file remediation and release require ReversingLabs verification
  * SentinelOne verdict updates now only change verdicts when detections close
  * Halo ITSM 401 errors now surface as critical authentication failures

  **Performance & Reliability**

  * Webhook throttling and paused-queue checks now use in-memory caches for hot traffic
  * Detection ingest does fewer duplicate team and integration lookups
  * Group and group-rule deletion is faster
  * Advanced event results no longer flash or rerun after streaming finishes
  * Group filters now sync reliably and hide bulk actions until rows are selected
  * Auto-remediation is attributed to Wirespeed in case summaries and timelines
  * Service provider users now lock when disabled in an operating team directory
</Update>

<Update label="Apr 23, 2026">
  **Features**

  * Events search now supports 180-day and 365-day windows
  * System logs now support richer audit-trail fields and metadata

  **Detection & Threat Intelligence**

  * Check Point Harmony detection deep links now use the right tenant domain
  * SentinelOne actions handle compact and dashed source IDs correctly
</Update>

<Update label="Apr 22, 2026">
  **Features**

  * User-endpoint associations now support filtering
  * Split data and count calculations across queries to improve application performance

  **Detection & Threat Intelligence**

  * Okta AppInstance targets now map to the OCSF service field
  * Picus detection simulation matching improved

  **Bug Fixes**

  * Verdict rules save reliably again
  * Jamf Protect file names now derive from file paths when missing
  * Improved integration-specific error handling
  * Optimized ChatOps policy evaluation
</Update>

<Update label="Apr 20, 2026">
  **Features**

  * OCSF query results now stream into the UI as they come back instead of waiting for the full result
  * Manual detection status changes are respected even when the source alert closes
  * Faster detection fetches — safe/known IP and location lookups moved to verdict time
  * Team analytics copy updated to use "Resolved" wording
</Update>

<Update label="Apr 17, 2026">
  **New Integrations**

  * [Stairwell](/integrations/stairwell) integration added for webhook-based detection events

  **Features**

  * Identity login ChatOps messages now include the VPN service when detected
  * Microsoft OAuth error page has a clearer CTA and shows more detail
  * Custom detections now support `ingested_at` for accurate timeline ordering
  * Group rules can target by Integration Source ID

  **Detection & Threat Intelligence**

  * Consolidated endpoint file enrichment matches in the timeline
  * Added timeline logging for the login no-user verdict rule

  **Bug Fixes**

  * Platform users are only locked when all linked directory accounts are disabled
  * Jamf Pro sync reliability improved
</Update>

<Update label="Apr 16, 2026">
  **Features**

  * Kandji endpoint remediation now behaves consistently with JumpCloud

  **Detection & Threat Intelligence**

  * Detection enrichment retries up to 3 times before giving up
  * Peeker noise reduction excludes custom-only escalations

  **Bug Fixes**

  * Email casing fixes across identity matching
  * Reingested escalations no longer lose state
  * Remediation no longer logs results on already-resolved detections and cases
  * `maxAutoRemediationsPerDay` of 0 now correctly means "disabled"
  * Ticket updates skip detections with no case ID
</Update>

<Update label="Apr 15, 2026">
  **Features**

  * Detection page limits default displayed assets and related detections — pages load faster
  * Chat Ops verdict rules enable all sub-options by default
  * AI bot prompt, tooling, and documentation improvements
  * Dark mode rendering fixes for IP addresses

  **Bug Fixes**

  * Subscription expiry calculation fixed
  * Detection close is deferred when remediation is still pending
  * Detection refresh skipped when the integration is disabled
  * Demo switch validation clears correctly when toggled
</Update>

<Update label="Apr 14, 2026">
  **Features**

  * AI → human chat handoff improvements

  **Detection & Threat Intelligence**

  * Google Security Center initial mappings (also closes cloud data transfer category)
  * Darktrace CrowdStrike `device_name` extracted as hostname
  * NetSupport Manager (`pcicl32.dll`) and ZA\_Connect.exe added to the tool catalog
  * Falcon mapping tweak

  **Bug Fixes**

  * Halo ITSM token scopes are now validated
  * `/cases` returns 404 for invalid IDs instead of hitting the database
  * Exclusion Slack value formatting normalized
</Update>

<Update label="Apr 13, 2026">
  **New Integrations**

  * [Google Security Center](/integrations/google-security-center) integration for Cloud Security Command Center findings

  **Features**

  * "Close" verdict language renamed to "Resolve" across the app
  * VIP styling and group badges now shown on user hover cards
  * AI chat mobile improvements: keyboard viewport, links, and chips
  * Server-side custom-field validation

  **Detection & Threat Intelligence**

  * Verdict tuning for MFA rejected and lateral movement alerts
  * SentinelOne alert mapper updated
  * Cortex gains a category group for third-party CPH detections
  * AWS user email extraction fix

  **Bug Fixes**

  * Split-email matching restored for group rule email automation
  * Okta cursor is preserved when requests fail
  * JumpCloud docs now show up in the integrations list
  * Email malware handling fixes
  * Silenced a noisy Picus error
</Update>

<Update label="Apr 11, 2026">
  * Wordfence integration now exposes its webhook secret for setup
  * Integration refreshes no longer error on expected integration exceptions
</Update>

<Update label="Apr 10, 2026">
  **New Integrations**

  * [JumpCloud](/integrations/jumpcloud) integration for directory events, user/endpoint sync, and remediation

  **Features**

  * Severity filter added to cases and detections
  * Remediation failure reasons now surface in timeline logs with the integration's logo

  **Detection & Threat Intelligence**

  * AWS GuardDuty detections now extract user email from PrincipalId
</Update>

<Update label="Apr 9, 2026">
  **New Integrations**

  * [Picus Security](/integrations/picus) integration for attack simulation validation

  **Features**

  * Detection refresh syncs verdict and status from SentinelOne & Microsoft
  * Microsoft integration supports custom user directory fields
  * Various improvements to improve accuracy of AI bot
  * Palo Alto Networks Cortex is out of beta
  * SSO-only users now get a database profile created automatically

  **Detection & Threat Intelligence**

  * Email evasion categorization for Microsoft XDR
  * Live-off-the-land mapping now covers processes, not just files
  * Malicious verdict set for escalated malware and identity contain/escalate rules
  * Low-severity cloud verdict rules for informational and low findings
  * Noise reduction metrics exclude low/info severity escalations
  * Escalated AQL batch restricted to medium+ severities
  * Microsoft Tor alerts mapped to network categories
  * "Posture - Health" category renamed to "Health"
  * Identity/Login no-user fallback rule added
  * Warning escalation and AQL recategorization tuned
  * 20+ new categorization rules across integrations

  **Bug Fixes**

  * Fewer false "unhealthy" integration alerts from transient polling failures
  * Events count no longer shows NaN in Team Analytics
  * AI chat handles responses with multiple code blocks correctly
  * AI chat queries now time out instead of hanging on large data sets
</Update>

<Update label="Apr 7, 2026">
  **Features**

  * Team Analytics page with time-series charts and breakdowns by category, integration, and group
  * The AI chat bot can filter by time for cases and detections
  * New "Was Monitored" filter on the cases list
  * Compressed timeline UI fits more entries on screen
  * Searchable, grouped-by-class category dropdown on the Detections page
  * Timestamps are now DST-aware with richer hover details
  * ChatOps responses now show responder IP and user agent in the timeline
  * Integration name shown in permission-error timeline logs
  * "Detection added" timeline events use actual discovery time, not system time
  * Remediation history detection SIDs are now clickable links
  * Session revocation and file quarantine skip the 15-minute remediation cooldown
  * External rules import button becomes "Update" for already-imported rules

  **Detection & Threat Intelligence**

  * SonicWall device auth events mapped to OCSF Authentication
  * SentinelOne unified alerts get Microsoft prevented parity for quarantine/removed-after-delivery
  * SentinelOne file path extraction from command-line arguments
  * SentinelOne lateral movement matching fixed for dynamic alert name prefixes
  * Mailbox-rule monitors now revoke sessions by default
  * Live-off-the-land file risk no longer overrides discovery/persistence categories
  * Identity login low-confidence rule adjusted to informational
  * Endpoint lateral movement low-confidence rule now includes medium severity
  * 30+ new categorization rules across integrations
</Update>

<Update label="Apr 1, 2026">
  **New Integrations**

  * [PingOne](/integrations/ping-one) identity integration added for audit activities and risk evaluations (beta)
  * [Axonius](/integrations/axonius) endpoint integration added for asset inventory

  **Features**

  * Remediation is now *fine grained*, allowing you to select the exact actions you want to perform
  * New remediation options: File quarantining and unquarantining
  * Brand new onboarding checklist walks new teams through setup steps
  * AI chat is now full-page on mobile with scroll lock and safe-area support
  * "Chat" button now opens Ask Wirespeed first, with a link to human support
  * Timeline timestamps now show seconds
  * Endpoints table supports searching by EDR/MDM ID
  * Endpoints and users support custom attribute filtering from Axonius
  * AiTM detection timelines now link directly to the suspicious events
  * Integration page filters can now be reset
  * Imported external rules now match incoming detections automatically

  **Detection & Threat Intelligence**

  * Login detections get a dedicated low-confidence verdict rule
  * Defender for Identity credential-access alerts mapped to identity login
  * SentinelOne enumeration alerts mapped to endpoint discovery
  * Cortex XDR domain extraction expanded to firewall miscellaneous fields
  * Sign-in logs now preferred over UAL for authentication lookups
  * Simulation detections can now recategorize on trusted mappings

  **Technology Update**

  * Our API has been rewritten in Rust...April Fools!
</Update>

<Update label="Mar 29, 2026">
  **Features**

  * CSV export for Events — available in both Basic and Advanced search
  * AI chatbot can now refresh endpoint and user details live from the source integration
  * Case activity timeline shows exact timestamps by default (relative time on hover)
  * Reopened detections create a case and esclate
  * Inherited exclusions show properly in hover cards and entity chips
  * Reopened detections create a case and escalate

  **Detection & Threat Intelligence**

  * Zscaler ZPA authentication events now mapped to OCSF
  * Cortex alerts extract and dedupe domains from raw alert fields
  * SocGholish and command-and-control late-stage mappings added
  * Remediation blocked by policy now escalates instead of closing
  * CrowdStrike credential-access tactic mapped to identity category

  **Bug Fixes**

  * IP detail breadcrumbs show the actual IP instead of a UUID
  * Fixed detection summary contradicting chat ops timeline
  * Onboarding logo stays visible across slide transitions
  * Source Details hidden on user detail page when empty
</Update>

<Update label="Mar 21, 2026">
  **Features**

  * Child teams now see inherited provider exclusions with a read-only "Inherited" badge
  * Entra custom security attribute syncing
  * Events queries now show result count and execution stats
  * Service provider members can no longer be removed or demoted by child team members
  * System log now records admin credential resets

  **Detection & Threat Intelligence**

  * [Cisco Umbrella](/integrations/cisco-umbrella) now ingests audit logs alongside DNS logs
  * Cortex action process fields mapped to process evidence
  * Microsoft "connection to remote" alerts mapped to outbound connections
  * SentinelOne Impact custom rules mapped to endpoint impact
  * Palo Alto Cortex credential access mapped to private credential exposure
  * CrowdStrike ignored detections now correctly set to suppressed status

  **Bug Fixes**

  * Fixed SentinelOne unified-alert indicator file extraction
  * Fixed EntityChip text overflow
  * Fixed Cortex causality actor SHA256 file evidence mapping
</Update>

<Update label="Mar 20, 2026">
  **Features**

  * **Groups — source system updates**: Under **Advanced Options** when editing a group (above **Group Rules**), **Update Source System** is on by default. Turn it off to stop pushing verdict, status, notes, and comments back to the integration for detections involving assets in that group. [Learn more](/groups)
  * Microsoft Defender for Cloud Apps alerts now ingested and categorized
  * Closure comments to source systems now include a resolution reason (exclusion name, automation rule, etc.)
  * AI case summaries now highlight automated remediation actions
  * Exclusions can now suppress source system status changes

  **UI/UX Improvements**

  * Entity chip hover cards redesigned
  * Comment box now shows "Ask Wirespeed" support link
  * OAuth error "View Documentation" button moved into the error details box for visibility
  * "Back To Service Provider" link hidden for users without parent team access

  **Detection & Threat Intelligence**

  * Microsoft mailbox forwarding rule creation now categorized
  * SentinelOne admin remediation alerts mapped to informational
  * Cortex domain-qualified usernames normalized for user extraction
  * Cortex persistence remapped
  * CrowdStrike `policy_disabled` now respected when determining blocked detections
  * "Authentication Methods Changed for Privileged Account" remapped to Identity > Persistence

  **Bug Fixes**

  * Fixed verdict not forwarding to source integration on detection close
  * Fixed events page URLs generated by AI chatbot
  * AI case summaries no longer include hallucinated asset links
  * Okta error messages now surface instead of "Unknown error"
  * Fixed hover card crashes on invalid entity references
  * Fixed endpoint table OS filter mapping
  * Fixed MSP Clients table sorting
</Update>

<Update label="Mar 17, 2026">
  **Features**

  * **Comments & Timelines**: Cases and detections now use a unified timeline where you can add, edit, and delete comments, attach images (drag-and-drop or paste), and review system activity alongside discussion
  * **Custom Groups**: Create your own user or endpoint groups with per-group Chat Ops and Remediation controls. [Learn more](/groups)

  **UI/UX Improvements**

  * Case details card updated with new layout and consistent MTTV/MTTD/MTTC thresholds across case and home dashboards
  * AI chatbot now renders markdown tables with horizontal scrolling in chat responses
  * System log now records group modification events
  * Team settings members table now shows phone numbers
</Update>

<Update label="Mar 13, 2026">
  **Features**

  * Integrations now receive richer closure comments when cases or detections are closed — verdict, summary, actor, MTTV, and details link
  * Webhook-only integrations (Wiz, Darktrace, Wordfence): webhook modal auto-opens on first connect with "View setup instructions" link
  * IP details page now shows Related Users based on private IP address associations

  **Detection & Threat Intelligence**

  * Cortex XDR: enriched detection context with process fields, hardware ID, and causality actor — reduces over-escalation
  * Palo Alto Cortex: Rare RDP session remapped to Lateral Movement, Uncommon SSH session to Outbound Connection
  * Suspicious Kerberos authentication remapped to Lateral Movement
  * SentinelOne: late stage lateral movement categorization additions
  * CrowdStrike: user threatgraph metadata fetched in detection enrichment
  * Okta: actor extraction from authentication logs
  * CIR custom detections: detections starting with \[CIR] categorized as custom
  * Microsoft: improved license selection
  * Tightened categorization group filters to prevent wrong rule matches
  * AI summary now uses "related detection" instead of "threat indicator"

  **Bug Fixes**

  * Password reset errors now surface to users instead of failing silently
  * Fixed team switching
  * Fixed OFAC evaluation
</Update>

<Update label="Mar 12, 2026">
  **New & Updated Integrations**

  * New [ServiceNow Change Requests](/integrations/service-now) collaboration integration (beta). Checks recent change requests during endpoint triage and automatically recategorizes detections tied to planned changes, reducing noise from authorized admin activity
  * New [Zscaler ZPA (Syslog)](/integrations/zscaler-zpa) network integration. Forward ZPA logs to Wirespeed via syslog with dedicated branding and attribution in the integrations catalog

  **Features**

  * AI chatbot is now generally available
  * IP detail page reorders sections for private IPs — Related Endpoints and Related Users are promoted above Cases and Detections
  * "Add Integration" buttons are now hidden for non-admin users

  **Detection & Threat Intelligence**

  * Microsoft UAL `UserLoggedIn` and `UserLoginFailed` events now mapped as OCSF Authentication with full enrichment matching sign-in logs
  * Defender XDR: map "Suspicious PowerShell-driven file creation and deletion" alerts to Endpoint Evasion
  * CrowdStrike `SuspiciousPrivEsc` remapped from Live Off The Land to Endpoint Persistence
  * CrowdStrike asset extraction now checks both target endpoint and domain controller hostnames
  * Palo Alto Cortex XDR detections now show associated users in the asset list
  * Orca Security detections now prefer `Details` over `Description` for source description, fixing empty narratives
  * AI summary no longer incorrectly classifies non-managed users (root, cron, service accounts) as technical/non-technical
  * SafeBreach simulation matching improved with multi-node evaluation, run deduplication, and IP extraction from OCSF evidences

  **Bug Fixes**

  * Fixed team settings inbox input dark mode styling
  * Fixed Halcyon integration fetching when no tenant ID is present
  * Fixed user deletion failing when user had created custom detections
</Update>

<Update label="Mar 05, 2026">
  **Features**

  * Integrations now track license usage and display a summary on the integration's details page
  * Remediation settings show a posture summary banner with status and quick links to Identity/Endpoint sections

  **UI/UX Improvements**

  * Remediation banner contrast improved in dark mode

  **Detection & Threat Intelligence**

  * Fixed LOTL masquerade reasoning for endpoint detections when file names include full paths
  * Restored contain user/endpoint actions for non-technical LOTL scenarios

  **Bug Fixes**

  * Fixed escalation emails not saving in the team settings form
  * Fixed service provider csv exports
</Update>

<Update label="Feb 27, 2026">
  **New & Updated Integrations**

  * New [Halcyon](/integrations/halcyon) anti-ransomware endpoint integration. Import alerts and manage endpoints from Halcyon, with detection enrichment, artifact extraction, and OCSF-mapped evidence for ransomware-related threats
  * New [Halo ITSM](/integrations/halo-itsm) ticketing integration (beta). Create and sync incident tickets bi-directionally — cases and detections in Wirespeed automatically create Halo tickets, and status changes sync back via webhook. Supports configurable ticket categories, teams, and custom fields
  * New [Horizon3 NodeZero](/integrations/horizon3) simuliation integration. Validates detections against active pentest/simulation activity — correlates escalated detections with Horizon3 ops to reduce noise from authorized security testing
  * Updated [Cisco Duo](/integrations/cisco-duo) now supports user syncing and remediation: disable and re-enable users in Duo directly from Wirespeed when remediating or releasing identities.

  **Features**

  * Calendar date picker now has year and month dropdown selectors for faster navigation

  **Detection & Threat Intelligence**

  * SentinelOne now ingests unified alerts for broader detection coverage and richer enrichment data
  * Linux endpoint detections are now automatically recategorized to Live Off The Land (LOTL) when all associated endpoints are Linux
  * Removed noisy RMM detections from Darktrace
  * Fixed null host grouping incorrectly clustering unrelated detections
  * Fixed private credential exposure classification for theft-of-passwords detections
  * External users are now excluded from ChatOps notifications

  **Bug Fixes**

  * Fixed button overlap on ChatOps settings page
  * Fixed "Learn More" animation in Manage Exclusions
  * Fixed FortiAnalyzer syslog ingestion
</Update>

<Update label="Feb 25, 2026">
  **Features**

  * Service provider dashboard now displays a stacked bar chart for Cases by Client, breaking down case counts by severity (Critical, High, and Other) with tooltips and period filtering for 7, 30, 90, and 365-day windows
  * New "External" user category automatically identifies third-party contractors, vendors, and external guests in your directory. External users can also be tagged manually from the user detail page or directory table actions menu
  * Have I Been Pwned (HIBP) detections now automatically match to existing open or escalated cases by integration and category, reducing duplicate case creation for ongoing breach monitoring

  **Detection & Threat Intelligence**

  * Improved user identity correlation with bidirectional username-to-email matching — when only a username or email is available, Wirespeed now resolves the corresponding identity from your directory for more accurate alert attribution
</Update>

<Update label="Feb 24, 2026">
  **UI/UX Improvements**

  * Team Analytics page now loads progressively — each section renders independently with skeleton loading for a significantly faster experience
  * Integrations browse page now shows available integrations first when no filters are active, making it easier to find and add new integrations
  * Home dashboard metric thresholds now match the Cases dashboard for consistent performance color-coding
  * Navigation sidebar on mobile now properly closes when navigating to a new page

  **Detection & Threat Intelligence**

  * Login hunts now close detections when failed logins are identified, reducing noise from unsuccessful authentication attempts
  * Microsoft risk dismissals are no longer automatically trusted — Wirespeed continues its own independent analysis for more thorough threat detection
  * Fixed RMM verdict rule incorrectly classifying detections with no associated files as admin-installed tools

  **Bug Fixes**

  * Fixed remediation alerts incorrectly firing during cooldown periods or duplicate remediation attempts
  * Fixed team analytics statistics endpoint returning incorrect data
</Update>

<Update label="Feb 22, 2026">
  **Features**

  * Test Mode is now indicated by a prominent full-width banner with an inline toggle to disable it directly, replacing the previous header pill
  * Okta `threatSuspected` events are now ingested and classified as login detections, expanding identity threat visibility for suspicious authentication activity
  * Monitors now correctly respect disabled verdict rules, ensuring your customized verdict configurations are honored during automated analysis

  **UI/UX Improvements**

  * Detections page loads significantly faster — results render immediately while total counts load in the background
  * Added 1-day and 7-day timeframe options to Cases and Detections dropdowns for more granular filtering
  * Password fields on login and registration pages now include a show/hide toggle for easier input verification
  * Endpoint details page now displays the integration platform source
  * Updated MTTV thresholds on the Cases dashboard for more accurate performance color-coding (green \< 3 min, yellow 3–10 min, red > 10 min)
  * Updated registration page with revised Terms of Service and Privacy Policy language

  **Integrations & Detection**

  * Expanded detection categorization mappings with new low-confidence triage rules across network, lateral movement, discovery, and custom detection categories
  * CrowdStrike detections tagged as "ignored" are now automatically closed as benign
  * System log now shows the specific reason when a user is locked due to being disabled in a linked integration

  **Bug Fixes**

  * Fixed "Was Remediated" filter on Cases and Detections to include both manually and automatically remediated items
  * Fixed stale case auto-close logic incorrectly closing new detections when creating replacement cases
  * Fixed bulk close ChatOps filter not properly filtering by detection criteria
</Update>

<Update label="Feb 19, 2026">
  **Features**

  * Stale cases older than 5 days are now automatically closed and replaced with a new case when a fresh detection arrives, keeping case queues current and reducing analyst fatigue from outdated investigations
  * New lateral movement verdict rule automatically closes detections with low or informational source severity, reducing noise from benign lateral movement events
  * New Network Discovery verdict category under Network automatically closes routine network discovery activity as benign, reducing noise from expected scanning behavior
  * Trial teams now see a persistent banner displaying remaining trial days with a direct "Upgrade Now" link

  **UI/UX Improvements**

  * Hovering over automated user tags (e.g., VIP, NHI) now displays a tooltip showing the automation rule and matching pattern that applied the tag
  * Integrations are now organized into refined categories — Endpoint, Identity, Network, Cloud, SaaS, Email, and Remote Access — for easier browsing and clearer subscription entitlement mapping
  * Noise reduction statistics now display with proper decimal rounding for more accurate reporting
</Update>

<Update label="Feb 18, 2026">
  **Features**

  * Service provider clients page redesigned with a stats panel showing aggregated metrics and advanced filtering by remediation status, HVA/VIP flags, demo/test mode, and escalation email source
  * Custom detection test queries now support configurable timeframes (1, 7, 14, 30, or 90 days) for more flexible backtesting
  * Added "Copy link" button on the Events page to share direct URLs to the current query, including search filters and team context
  * Improved verdict time accuracy by measuring actual processing duration rather than queue time

  **UI/UX Improvements**

  * Navigation counts between 1M and 10M now display one decimal place (e.g., "2.7m" instead of "3m") and pagination totals are comma-formatted
  * Integration custom fields can now be edited directly from the connected integrations list
  * New entity chips in detection descriptions for users, endpoints, and integrations with inline logos
  * Fixed Events page search not persisting in URL when switching between basic and advanced query modes
  * Fixed duplicate verdict categories and misaligned search on the Verdicts settings page

  **Integrations & Detection**

  * Improved CrowdStrike detection enrichment with better file path extraction and macro file hash support
  * New Darktrace detection category mappings
  * New Orca Security detection category mappings
  * Mimecast blocked URL events now correctly categorized as blocked actions
  * Fixed VIP title matching to prevent false positives (e.g., "Onboarding Coordinator" no longer incorrectly tagged as a board member VIP)

  **Bug Fixes**

  * Fixed boolean and JSON custom fields not saving correctly in the integration update form
</Update>

<Update label="Feb 13, 2026">
  **Integrations**

  * New [Custom SMTP](/integrations/smtp) integration allows customers to use their own SMTP server for ChatOps notification emails
  * Improved email directionality tagging across Vectra, Google, Mimecast, and Checkpoint Harmony integrations

  **Features**

  * Subscription tier system (Identity, Core, Unlimited) to manage integration entitlements per account
  * Service provider clients page now displays team member counts per client
  * ChatOps messages are now suppressed for actively remediated users
  * File path risk assessment for living-off-the-land binary detection
  * New verdict rules for low-severity outbound network connections and VIP phishing scenarios

  **UI/UX Improvements**

  * Significantly improved Endpoints page performance for large datasets with optimized queries and debounced search
  * Added Endpoints by Source card to the endpoints dashboard with source filtering
  * Consolidated duplicate integration sources in endpoint and user stats
  * Shortened number formatting in Users and Endpoint stats panels (e.g., 1.3M)
  * Improved OAuth integration connection pages with clearer success and error states

  **Bug Fixes**

  * Fixed bulk case closure not properly updating detection status
  * Fixed CrowdStrike IOC domain detections being miscategorized as Endpoint Execution
  * Fixed integration enable/disable toggle not working correctly
  * Fixed double scrollbar on Endpoints and Users list views
  * Fixed filter dropdowns closing on first checkbox selection
  * Fixed remediation modal text clipping for long names
</Update>

<Update label="Feb 10, 2026">
  **Integrations**

  * [Palo Alto Networks Cortex](/integrations/palo-alto-networks-cortex) integration added for importing alerts and managing endpoints from Cortex XDR/XSIAM
  * [Cisco Secure Access](/integrations/cisco-secure-access) integration added for log ingestion
  * Cases can refresh the notes and logs from CrowdStrike Falcon alerts
  * Improved SentinelOne endpoint sync with UUID support

  **Features**

  * User and endpoint tables now support billable filter for service provider billing
  * SMS ChatOps invite reset allows admins to resend enrollment emails to users who previously reached max attempts
  * System log now has Security Events Only filter for quick filtering of security-related events
  * Integration logs view now supports pagination for better performance with large datasets
  * Users page redesigned with stats panel, type filters, and source filtering
  * Endpoints can now be tagged automatically as Domain Controllers
  * Account activity emails will alert you when an integration needs your attention
  * Enhanced file risk assessment in email detections to improve accuracy of malware identification

  **UI/UX Improvements**

  * User detail page now shows integration source and icon
  * User first and last names are now optional in profile and registration
  * Redesigned case detail page header for clearer case context
  * Tagging rules and custom detection modals now use slide-over sheets
  * Integration connect flow supports collapsible Advanced Options for optional configuration fields
  * Added clear button to users and endpoints More Filter dropdown
</Update>

<Update label="Feb 4, 2026">
  **UI/UX Improvements**

  * Endpoint dashboard now shows OS distribution chart, live/remediated stats, and redesigned search filters
  * Remediation dialog now shows live loading status when refreshing asset states
  * Integration detail pages with creation date, status badge, event stats, log level legend
  * Enhanced integrations browse page with connection status filter and clearer styling for connected integrations
  * Authentication locations now display region/state for more precise location context
  * Removed duplicate header on Team Analytics page

  **Bug Fixes**

  * Fixed bug preventing team settings from saving when support email was not configured
  * Optimized tagging of unmanaged users

  **Integrations & Threat Intelligence**

  * CrowdStrike detections now extract IPv4/IPv6 IOCs as IP address observables
  * In CrowdStrike true/false positives tags are now applied when the case is updated in Wirespeed
  * New and improved detection categorizations for persistence and other techniques
  * Domain Takeout alerts from Google Alert Center now properly categorized
  * Improved endpoint name matching to handle special characters
</Update>

<Update label="Jan 29, 2026">
  **Integrations**

  * [Bitwarden](/integrations/bitwarden) integration added for organization event logs
  * [Check Point Firewall](/integrations/checkpoint-firewall) and [SonicWall](/integrations/sonic-wall) added as first class firewall log ingestion integrations

  **Features**

  * Improved email detection analysis with sender/receiver direction tracking

  **UI/UX Improvements**

  * Streamlined custom detection creation flow so you can build and save detections in one place
  * Redesigned Integrations page with category filtering, grid/list views, and improved connect modal
  * New hierarchical navigation and breadcrumbs for Verdict settings
  * Fixed Events table empty state alignment
</Update>

<Update label="Jan 27, 2026">
  **Features**

  * Successful brute force detections are now categorized as Login events
  * Optimized how we track progress on Events queries

  **UI/UX Improvements**

  * API keys pages now use table layout with clearer empty states
</Update>

<Update label="Jan 26, 2026">
  **Features**

  * Notification frequency can now be managed from the Profile page
  * User tagging rules now support regex matching

  **UI/UX Improvements**

  * Updated theme switcher to make dark mode toggle more prominent
</Update>

<Update label="Jan 23, 2026">
  **Platform**

  * Upgraded to the [Bun 1.3.6](https://bun.com/blog/bun-v1.3.6) runtime

  **Integrations**

  * [1Password](/integrations/1password) integration added for audit events, item usages, and sign-in attempts monitoring
  * [Orca Security](/integrations/orca-security) integration added for cloud security alerts
  * Simplified JAMF Pro integration setup - you can now paste the JSON configuration directly
  * Integration enable/disable actions are now logged to the system audit log

  **Features**

  * Bulk Actions! Close multiple cases at once from the Cases table
  * Generic syslog and JSON integrations support custom labels for easy identification
  * Team API keys can be created independently of user accounts

  **UI/UX Improvements**

  * Redesigned profile page with organized sections for user details, notification settings, and API keys
  * Users can now edit their profile information including name, phone number, and timezone
  * Improved remediation dialog with better asset selection and clearer actions
  * New verdict configuration UI with tree navigation and search to easily find and configure rules
  * Added ability to review and apply secure defaults across all verdict categories at once
  * Clearer timeline messages when searching for related authentication events
  * Service providers: Demo clients are now hidden by default in cases/detections tables
</Update>

<Update label="Jan 15, 2026">
  **UI/UX Improvements**

  * Added OS search filter to endpoints table for easier endpoint filtering by operating system
  * Improved remediation UI in detection pages with better button and panel layout
  * Enhanced dark mode contrast for toggles, selects, inputs, and text fields for better visibility
  * Updated filter button to visually show applied filters with a clear button for easier filter management
  * Improved mobile UX for action panels with better alignment and responsiveness
  * Updated input component styling for consistency across the application
  * Updated documentation tooltips for better user guidance
  * Added `countIf` function for Events queries

  **Integrations & Threat Intelligence**

  * Updated Microsoft IDP categorization rules
  * Optimized user automations to reduce false positives and incorrect tagging

  **Bug Fixes**

  * Fixed incorrect calculation of Mean Time To Respond (MTTR) and Mean Time To Detect (MTTD) metrics in team statistics
</Update>

<Update label="Jan 12, 2026">
  * Added Team API Keys allowing admins to create service account API keys for programmatic access at the team level
</Update>

<Update label="Jan 9, 2026">
  **UI/UX Improvements**

  * Added secure defaults preview dialog allowing you to review and selectively apply recommended security settings before changes are made
  * Added category filter to exclusion backtesting to test against specific detection categories
  * Improved automation UX with tabbed interface, renamed "Automations" to "Tagging Rules", and added live preview when creating rules
  * Updated navigation hierarchy and removed onboarding link for cleaner navigation
  * Added empty states to tables and widgets across the application for better user guidance
  * Improved events table with advanced vs basic layout options and fixed dropdown menu behavior
  * Fixed case search UI disappearing when filters return no results
  * Removed warning screen when switching teams for a smoother team switching experience
  * Added white-labeling the platform name to case logs

  **Integrations**

  * Enhanced SafeBreach integration to handle detections with multiple IP addresses
  * CrowdStrike domain controllers are now automatically tagged as Highly Valued Assets (HVA)
  * Unmapped SentinelOne high-severity detections now escalate properly

  **Detection & Threat Intelligence**

  * Improved primary file IOC detection to better highlight the actual threat indicator in detection summaries
  * Added Impacket, SecretsDump, and GoToResolve to the tool catalog
  * Fixed Python tool detection to avoid false positives with malware names
  * Some detections are now mapped to informational events to reduce noise

  **Service Provider**

  * Service providers can no longer add integrations (integrations only work at client tenant level)
</Update>

<Update label="Jan 7, 2026">
  * Added ability to skip onboarding for faster team setup
  * Service providers can now opt out of subscribing to notifications when creating a team
  * Improved UI layout for custom detections and exclusions pages with action buttons now at the top right
  * Improved detection categorizations for evasion and discovery alerts
</Update>

<Update label="Dec 31, 2025">
  * Fixed bug where team inbox escalation emails were incorrectly updated when switching teams.
</Update>

<Update label="Dec 27, 2025">
  * Added support for multiple team inboxes, allowing teams to configure and manage multiple email inboxes for case notifications
  * Improved search UX with a new clearable input component across the application
  * Added light and dark mode logos for Okta and AWS integrations
  * Improved UI performance for the sidebar, users page, and endpoints page
  * Enhanced SentinelOne STAR alert processing with better user and device extraction
  * Fixed bug where automation tag rules failed to tag users correctly
  * Improved OAuth JWT security with token expiration and versioning
</Update>

<Update label="Dec 18, 2025">
  * [SafeBreach](/integrations/safebreach) integration added so that detections can be correlated to both actively running or past simulations
  * Added support for SentinelOne STAR alerts
  * Upgraded the Azure blog SDK used for syncing Entra sign-in logs
  * Improved JWT usage when adding integrations
</Update>

<Update label="Dec 11, 2025">
  * Enhanced status transition handling for cases and detections to prevent race conditions
  * Added new RMM tools to our catalog
  * Improved Crowdstrike categorizations
  * Updated how productivity events are tagged to improve query performance
  * Jira comments are now marked as private when created in Jira Service Desk context
</Update>

<Update label="Dec 4, 2025">
  * Added a Chat Ops status so that you can easily view cases and detections actively awaiting user feedback
  * More details about chat ops and remediations have been added to the timeline and summary views
  * Improved Activity Summary emails, offering a more concise view of your env health and what requires your attention
  * A new dedicated Activity Summary email for Service Providers to give them a view of all clients
  * Events and WEL queries now support regex matching
  * Fixed bug where endpoints that failed to lookup would overwrite existing endpoint data
  * Fixed SentinelOne URL link issue
  * Improved performance for ingestion of historic detections
  * Improved search endpoint performance
  * Added new items to our RMM tool catalog
</Update>

<Update label="Nov 5, 2025">
  * Initial support for Gmail subscriptions
  * Case and Detection tables now have the ability to filter by Integration
  * Crowdstrike Falcon Cloud Security is now parsed and ingested. No need to update your existing integration, it will begin to pull if present.
  * Added a new configuration in Verdicts where you can stipulate what to do if a monitor cannot run (for example if there is not enough data for the monitor, then escalate!)
  * New category mappings for Defender's suppressed and discovery events
  * Endpoint Exploitation added as a new category
  * Jamf Protect integration now logs when your token is expired
  * Improved extraction of parent process files
</Update>

<Update label="Nov 3, 2025">
  * AI verdicts for live off the land executions are now shown in the detection timeline
  * Thinkst Canary console settings now map to informational event
  * Simplified table filters, all filters can now be found at the right-hand side of the search bar
</Update>

<Update label="Oct 28, 2025">
  * Improved Case and Impact UI on mobile devices
  * Exclusion creations, edits, and deletions are now tracked in the system log
  * Increased the amount of data extracted from Jamf Protect detections
  * Chat Ops tests are now easier with typeahead user searching
  * Various SMS chatops improvements
  * Fixed how we extract command line arguments for SentinelOne
  * Remapped how we handle Entra Connect tampering
  * Fixed a bug in manager chatops verdicts
  * Added average MTTV, MTTD, and MTTR to cases
</Update>

<Update label="Oct 24, 2025">
  * 🍞 Upgraded to the [Bun 1.3](https://bun.com/blog/bun-v1.3) runtime
  * Improved background job processing for added resiliency during long-running jobs
  * Added non-interactive sessions in Microsoft sign-in logs
  * Verdict rules can now insert a friendly explanation into your timeline
  * Added new categories for private credential exposure for VIPs, evasive activities in email, and more
</Update>

<Update label="Oct 22, 2025">
  * SMS chat ops is now available! Learn more [here](/chat-ops/communication-plan#sms-chat-ops)
  * [Mimecast](/integrations/mimecast) integration added
  * AI analysis for some live off the land executions is now live
  * Automated impact identification is now in beta testing, Wirespeed will identify all activities performed by a user after suspicious activity is alerted on.
  * Fixed API bug when attempting to enable LOTL endpoint auto remediation
  * Directory/Endpoint tag automations are now logged to the system log
  * Case reopening is now added to the case timeline
</Update>

<Update label="Oct 10, 2025">
  * Improved next steps granularity when remediation is partially successful
  * Added detection from 3 new RMM tools
  * Add 200 new detection mappings for Vectra integrations
  * CSV exports are now available on the cases and detections pages. Exports have a limit of 100k rows.
  * Bug fix for billable user counts on the Clients page for service providers
</Update>

<Update label="Oct 8, 2025">
  * Improved retry handling for ticket creation in external systems
  * Benign chat ops responses are now saved as exclusions
  * Refactored login verdict handling to remove low confidence verdict rules
  * New experimental AI analysis for live off the land executions is now being run in read-only mode
  * Verdict is now available in the Case details view
  * Reduced false positives for suspicious email identification after a suspicious login
  * Team, Case, and User deletion bug fixes
  * Service Providers can now whitelabel the following:
    * Email "from" name
    * Email reply-to address
    * In-product support button email address
    * Email signature and footer address
  * Historic Cases can now be reopened for further inspection
</Update>

<Update label="Sep 29, 2025">
  * Increased webhook durability
  * Enhanced file grouping
  * Optimized memorary usage on detection consumption
  * Improved JSON parsing date parsing
  * Enhanced OAuth client credential grant handling
  * Fixed monitor logic for better accuracy
  * Improved duplicate detection lookups
  * Updated bun version
</Update>

<Update label="Sep 25, 2025">
  * [Vectra](/integrations/vectra) integration is now available!
  * Enhanced NATS consumer durability
  * Prevented chat ops when a monitor is already active
  * Enhanced chat ops to avoid notifying users who have timed out recently
  * Improved HVA value handling to not override manually set values during endpoint syncing
  * Optimized malware algorithms
  * Added categorizations for Falcon Cloud Security
  * Allowed VIP chat ops during testing
</Update>

<Update label="Sep 17, 2025">
  * Improved AITM behavior detection
  * Improved unicode handling
  * Upgraded Crowdstrike Falcon endpoint syncs to use bulk fetching
  * Refactored enrichment to analyze files concurrently
</Update>

<Update label="Sep 15, 2025">
  * Updated our algorithm to more accurately detect live off the land scenarios
  * Improved JSON parsing across all integrations
  * Adjusted our parser to better support inconsistencies observed in Microsoft data
  * If a detection is added to a case, ticket integrations (e.g. Jira) will note so via a comment
</Update>

<Update label="Sep 10, 2025">
  * Service Provider name will now be used in client Timelines
  * Team list now identifies external members, easing Service Provider team management
  * Improve monitoring so that detection monitors in the same case stay in sync with one another
  * Improve date parsing for syslog ingestion
  * Update Jira Cloud integration to faciliate templated summary and optional sending of closed detections
  * Fixed bug where the IP page would not load for private IP addresses
</Update>

<Update label="Sep 9, 2025">
  * 20 new and updated integration categorizations
  * Simulated breach detection
  * Identification and new verdict rules for masquerading files
  * Added category for Business Email Compromise (BEC), was previously mapped to Login alerts
  * Added category for Account Compromise
  * Added category for Lateral Movement
  * Fixed bug on events page where click-to-search functionality duplicated values
  * Clients table for Service Providers is now sortable
  * Improved detection of authorized RMM tools
  * Active monitors are displayed below escalated cases in the navigation bar
</Update>

<Update label="Aug 31, 2025">
  * 11 new and updated integration categorizations
</Update>

<Update label="Aug 28, 2025">
  * Webhooks are now processed asynchronously to increase reliability
  * Billable users & endpoints are available underneath your Team page, or the Clients page for service providers
  * 47 new and updated integration categorizations
</Update>

<Update label="Aug 24, 2025">
  * User and Endpoint details pages have been updated to show related detections
  * User details page exposes authentication patterns
  * Dedicated category for business email compromise added
  * Updated details grid available on all entity details pages
  * Removed files, user agents, locations, processes, ip addresses, and domains from left-hand navigation
  * New command pallette available via `cmd+k` or `ctrl+k` to search the removed navigation items above
  * AI summary is now the default case description
</Update>

<Update label="Aug 22, 2025">
  * You can now delete your team by navigating to the Teams page and selecting "Delete Team". This action is irreversible.
  * New API endpoint `POST /team/switch` - Service providers can use this with a service provider API key to manage multiple tenants.
</Update>

<Update label="Aug 20, 2025">
  * Fixed custom detection query timeouts by updating query generation logic to use proper partitioning keys.
  * Generic Syslog and JSON log importers are now generally available.
  * Improved endpoint and user correlation to prioritize active managed users over dormant ones.
</Update>

<Update label="Aug 17, 2025">
  * Improved cases dashboard now shows mean time to detect, verdict, respond, and contain.
  * Timeline logging improvements for ingestion of historic detections on initial integration.
  * Improved live off the land tool detection for `pwsh.exe` and `winpty-agent.exe`.
  * Improved remote management tool detection for ScreenConnect and NinjaOne.
</Update>

<Update label="Aug 12, 2025">
  * Jira comments sync back to Wirespeed and are shown in the cases view.
  * IPv6 addresses are flattened by default
  * Integration categorization and parsing improvements for Crowdstrike and Okta
</Update>

<Update label="Aug 5, 2025">
  * In the **Events** view, you can now click properties to automatically add them to the search bar.
  * When creating a user you can now opt them out of activity emails.
  * New and updated mappings for Microsoft.
</Update>

<Update label="July 30, 2025">
  * Jira Cloud is now available! Review [our documentation](/integrations/jira-cloud) to learn how Wirespeed cases can create Jira issues and how closing issues in Jira can close the issue in Wirespeed.
  * Updated Microsoft UAL parsing and tidying of AWS GuardDuty permissions checks.
  * Prioritize managed users in directory user searches.
</Update>

<Update label="July 28, 2025">
  * **Hunts** and **Monitors** are now generally available!
    * Hunts are deep analyses using 30-day patterns, threat intelligence, and device validation that hunts for any clues or indications that may inform a detection.
    * Monitors are continuous surveillance executing rules at regular intervals to detect repeat patterns over extended periods (days to weeks), generating cases when specific threat patterns match.
  * New mappings for JAMF Protect.
  * Added the ability to test ChatOps with unamanaged user, making it easier than ever to see a live demo of ChatOps in action.
</Update>

<Update label="July 23, 2025">
  * Cisco Duo authentications logs are now available in Wirespeed! Check out our [integration docs](/integrations/cisco-duo) to learn how to get started.
  * Custom detection changes are logged to your [audit log](/settings/team#audit-log).
  * Detections table verdict and page size filters were not working as expected.
  * New and fixed mappings for detections from Microsoft and Crowdstrike.
</Update>

<Update label="July 18, 2025">
  * Certain OCSF observables were not being properly identified on authentication events.
  * Remediation and chat ops actions are more clear in the What Happened summary.
  * Improved detection mappings for vulnerable drivers, brute force, and email malware alerts.
</Update>

<Update label="July 12, 2025">
  * Check Point Harmony spam and graymail alerts are no longer considered detections. They will still be enriched and available in the data lake.
</Update>

<Update label="July 11, 2025">
  * Need a quick birds eye view of [your Detections](https://app.wirespeed.co/detections)? Go checkout out the new stats at the top!

  <Frame>
    <img className="block dark:hidden" src="https://mintcdn.com/wirespeed/B3u6AtQgDIeycrGU/images/changelog/20250711-detection-stats-light.png?fit=max&auto=format&n=B3u6AtQgDIeycrGU&q=85&s=8854d0e35dcf543fa0bbafcb0a27a3f0" width="1430" height="330" data-path="images/changelog/20250711-detection-stats-light.png" />

    <img className="hidden dark:block" src="https://mintcdn.com/wirespeed/B3u6AtQgDIeycrGU/images/changelog/20250711-detection-stats-dark.png?fit=max&auto=format&n=B3u6AtQgDIeycrGU&q=85&s=5c0035912b7456c80cc625c4cf8309ed" width="1430" height="330" data-path="images/changelog/20250711-detection-stats-dark.png" />
  </Frame>

  * You asked for it, we delivered: **Apple Private Relay** 🍏 handling has been added to our verdict rules.
  * You're not using [Chatops](https://wirespeed.co/#chat-ops)? [Onboard a group](/chat-ops/communication-plan#onboarding-group) today to instantly increase the effectiveness and intelligence of your Wirespeed deployment.
  * Subscribe to changelog updates at `https://docs.wirespeed.co/changelog/rss.xml`.
</Update>

<Update label="July 7, 2025">
  * Leverage the full power of Clickhouse by using Wirespeed's [Advanced Queries](/events/advanced-queries). *Seriously, go check out the docs for this one*. Start or continue your journey to become a Wirespeed Superuser!
  * Updated our user algorithm, making our directory decision making even smarter.
  * Ever wonder if your mobile endpoints are responsible for more cases? You can now filter cases by "Was Mobile" to learn more about what your mobile devices are triggering.
</Update>

<Update label="July 1, 2025">
  * [Custom Detections](/events/custom-detections) are here: use SQL to create *your own custom detections*.
  * Jira integration added. Check out our [Jira integration docs](/integrations/jira-data-center) to learn how Wirespeed and Jira can stay in sync!
</Update>

<Update label="June 27, 2025">
  * Added ability for Service Providers to provide default ChatOps messaging for client teams.
</Update>

<Update label="June 25, 2025">
  * Updated verdict ordering for better prioritization
  * Added TOR logins to verdict algorithm
  * Fixed timeline display issues for improved event tracking
</Update>

<Update label="June 23, 2025">
  * Microsoft sign-in log processing is now generally available
</Update>

<Update label="June 19, 2025">
  * Okta sign-in log processing is now generally available
  * Enhanced directory user automation rules for email domain matching
  * Increased clarity of threat indicator data
</Update>

<Update label="June 18, 2025">
  * AI Case Summaries: you can now view a AI-generated summary of every case
  * Added ability to ingest all assets from detection sources and option to tag them as HVT
</Update>

<Update label="June 11, 2025">
  * JAMF Protect integration has been enabled for Beta testing
</Update>

<Update label="June 10, 2025">
  Welcome to our new changelog! Items will be added here as soon as they are released.
</Update>
