This release expands user-risk analysis, data-collection visibility, AI-assisted detection engineering, platform integration, investigation, and workflow operations across SecNova AI-SIEM.
Key Feature Updates
User Management and UEBA
SecNova introduces a user inventory that centralizes user identity and related information, providing a unified entry point for user-risk analysis.
User risk scoring and behavioral detection identify high-risk users and anomalous activity, helping security teams prioritize investigations and assess risk with complete user and behavior context.
Agent Data Collection Health Checks
New checks assess Agent data-collection status and effectiveness, helping users continuously verify that security data is being ingested correctly and completely.
The system identifies missing data, collection anomalies, and insufficient coverage before they create detection blind spots, improving confidence in security analysis and detection results.
AI Detection Rule Optimization and Recommendations
AI evaluates rules that are installed, enabled, or available in the current tenant and combines this information with data sources, field availability, and recent data to recommend rules to install or enable, together with the recommendation rationale.
Rule health presents operational effectiveness across enablement, execution, performance, and alert quality. It also provides installation, enablement, and optimization guidance to broaden effective detection coverage, reduce maintenance effort, and improve alert quality.
OpenAPI Availability
SecNova now provides standardized OpenAPI access to available data and security-operations capabilities.
Users can integrate SecNova with existing business platforms, security systems, and automated processes, reducing information silos and extending data collaboration, analysis, and response capabilities.
Report and Dashboard Drill-Down
Aggregated metrics in reports and dashboards now support drill-down. Users can move directly from a metric to related details and investigation context, reducing page switching and making it easier to understand the security information behind metric changes.
Enhanced Incident Relationship Graph
The Incident relationship graph has been enhanced to present event-related objects and their relationships more clearly.
Users can select graph nodes or relationships to drill down into related information and detailed context, then continue investigating along the relationship graph for a clearer understanding of complex incidents.
Workflow Run History
Workflow now provides access to historical runs, execution results, and run logs.
Users can review an individual run to trace automation outcomes, troubleshoot execution issues, and reconstruct the complete automated process.
Custom Skills for AI Agent
Users can create and use custom Skills for their business scenarios, extending AI Agent capabilities across analysis, investigation, and automation.
Custom Skills can be applied to specific security-operations tasks, allowing AI Agent to align more closely with each organization's processes, analytical methods, and automation requirements.
Tenant Management Platform Upgrade
Tenants can now be created directly in the tenant management platform. Tenant administrators can enter tenant information and complete creation from one place, reducing operational steps and improving tenant onboarding and administration efficiency.
Security Product Integration Upgrade
This upgrade covers eight security product packages: Broadcom Carbon Black EDR, CYFIRMA DeCYFIR, DAS WAF, Fortinet FortiEDR, ModSecurity WAF, PAN-OS, QAX SkyEye NDR, and Sangfor Cyber Command NDR.
These packages enhance data collection, log parsing, detection rules, and alert analysis. The upgrade broadens threat-detection coverage, reduces the effort required to integrate and operate multiple security-data sources, and improves security-operations efficiency.
Experience and Reliability Improvements
Improved Rule, Alert, and Incident Analysis Experience
Rule-data matching, alert field presentation, and incident correlation have been improved to make the relationships between detection results, alert information, and investigation context clearer during security analysis.
Improved Data Processing, AI Interaction, and Page Reliability
This release improves the stability of complex data processing, contextual tasks, and query completion. It also enhances AI task interactions, access control, result presentation, page layouts, form feedback, and operation responses to reduce interruptions and unexpected behavior.
Resolved Issues
- Data Processing and Queries: Fixed known issues affecting complex data processing, contextual tasks, and query-completion stability.
- Detection Rules and Alerts: Fixed known issues involving rule-data matching, alert field presentation, and incident correlation.
- AI Interactions and Permissions: Fixed known issues involving AI task interactions, access control, and result presentation.
- Page Display and Operations: Fixed known issues involving selected page layouts, form feedback, and operation responses.