v12.0.0
Pre-release
Pre-release
UTMStack v12.0.0 brings major improvements to multi-tenant management, AI-assisted operations, automated response, and log exploration. This release adds new dashboards, incidents, compliance, and threat intelligence capabilities while improving performance and fixing common issues.
What's New
- Multi-tenant support with separate settings, users, alerts, integrations, and response flows for each tenant.
- Docked SOC-AI assistant that helps with dashboards, incidents, and response workflows.
- ThreatWinds AI provider available as a zero-config default.
- Resizable tables and columns across Log Explorer, alerts, pipelines, and SOAR.
- Redesigned incidents with a creation wizard, custom assignment, and notifications.
- New automated response (SOAR) capabilities, including an interactive console, execution history, additional action nodes, and clearer run statuses.
- AI-assisted dashboard creation and editing, with copy and dismiss options.
- Dashboard refresh intervals and auto-refresh.
- Log Explorer manual query mode with autocompletion and related-event filters.
- Adversary view with a relationship chart showing connections between adversaries, alerts, and victims.
- Threat intelligence fallback data and cleaner indicator matching.
- Compliance reports that can be signed, with multi-tenant support and clearer completion percentages.
- Local user creation and tenant admin provisioning.
- API key settings.
- Tenant branding options, including dark-mode icons and highlight toggles.
- Collapsible sidebar with icon-only mode and an overview toggle.
- Broadcast UI and grouped notifications.
- Data source log timeline and offline counts.
- New Windows, macOS, and Linux detections/rules.
- Linux user auditor.
- Agents can self-update and show clearer status; Linux agents can monitor audit files.
- New web endpoint for sending logs into UTMStack.
- Remote enable/disable for forwarder integrations.
- Playground to test filters and rules before saving.
- Rule flood guard that can automatically disable noisy correlation rules and notify you.
Improved
- Faster and more efficient log storage and querying.
- Tenant-specific integrations, catalogs, connector settings, SOAR flows, and audit data.
- Pipeline filter order is now fully customer-controlled.
- Alert rules support synchronized visual, code, and test modes, plus export and disable options.
- Web response actions support query parameters, default headers, and cache clearing.
- Agents reconnect more reliably and maintain stable connections.
- Clearer AI assistant messages, smoother chat scrolling, and better context handling.
- Improved UI consistency, dark-mode labels, and layout spacing.
- Better tenant filtering for agents, collectors, and incidents.
- Improved integrations guides, success messages, and certificate handling.
- Improved alert list details, including severity and related counts.
- Improved data source command output and loading behavior.
- Improved AD audit parsing and persistent disabled-user state.
- Improved forwarder behavior for web integrations.
- Improved threat intelligence correlation by removing empty values.
- Improved rule deduplication and grouping, with failures shown instead of hidden.
- Improved compliance control status tracking.
- Improved notification scoping so tenants only receive relevant alerts.
- Improved dashboard visualization management and chart options.
- Improved SOAR canvas layout and table scrolling.
- Improved Log Explorer colors, scrolling, and filters.
- Improved incident details drawer and assignment options.
- Improved tenant cards, terminated tenant handling, and event purge options.
- Improved branding section interactions.
- Improved overview playbooks card interactivity.
- Improved ingestion stats default time window.
- Improved generated secret state in integrations.
- Improved alert status change options.
- Improved event processing pipelines for multiple data types.
- Improved AI usage metering per tenant.
- Authorized cross-tenant incident access for managed service provider installations.
Fixed
- Scheduled jobs no longer show errors when no instances are configured.
- Manual execution status now displays correctly.
- Pipeline order is preserved after changes.
- Duplicate AD users no longer appear.
- Windows install command works correctly.
- macOS detection filters now map host and field values correctly, and unverifiable rules are removed.
- Correlation rules no longer disappear after updates.
- Web action nodes no longer include unwanted default headers.
- Empty alert field values no longer affect threat intelligence matching.
- Updates no longer wipe manual memory settings.
- Agent connections are less likely to drop when idle.
- SOAR flow creation drawer works correctly.
- Duplicated broadcast close button removed.
- Integration disable button behaves correctly when already disabled.
- Unused AWS log group field removed from AWS configuration.
- Missing GCP translation keys added.
- Custom integrations now receive data correctly.
- Alert status options are correct when changing status.
- Dashboard widget query bugs and missing edit action fixed.
- Adversary grouping and dark-mode labels fixed.
- SOC-AI chat no longer overlaps the interactive console.
- Log Explorer duplicated components, header scrolling, and select colors fixed.
- Data source loading indicator no longer remains after command output.
- Missing confirmation modal and language keys fixed.
- Billing, integrations, and AI configuration issues fixed.
- Web integrations are preserved during forwarder config sync.
- Agent and collector tenant filtering fixed.
- Compliance framework completion percentage fixed.
- Purge button colors fixed.
- Visit tenant text centered.
- SOAR table horizontal scroll and bulk edit fixed.
- Alert severity displayed.
- Generated integration secrets now show the correct lifetime.
- Dashboard auto-refresh option translated.
- Log Explorer filters on Linux systems fixed.
- Filter form now accepts added entries correctly.
- Rule flood guard thresholds and notifications are now scoped correctly per tenant, rule, and data source.
- Playground returns all matching alerts.
Full Changelog: v11.2.15...v12.0.0