Skip to content

Releases: panther-labs/panther-analysis

v3.5.0

09 May 18:28
6f3cc47
Compare
Choose a tag to compare

What's Changed

๐Ÿ•ต๏ธ New Detections

๐Ÿ› Bug Fixes and Tunes

New Contributors

Full Changelog: v3.4.0...v3.5.0

v3.4.0

26 Apr 19:50
6a176bb
Compare
Choose a tag to compare

What's Changed

๐Ÿ•ต๏ธ New Detections

  • Slack: User's role changed to User by @miotke in #693

๐Ÿก Miscellaneous

New Contributors

Full Changelog: v3.3.0...v3.4.0

v3.3.0

21 Apr 19:40
a8c7aab
Compare
Choose a tag to compare

What's Changed

๐Ÿ•ต๏ธ New Detections

๐Ÿ› Bug Fixes and Tunes

  • Adding Panther.Audit to the Greynoise LUTs by @nkulig in #732
  • fix: AWS ELBs now have TLS 1.3 SSL Policies by @edyesed in #734

Full Changelog: v3.2.2...v3.3.0

v3.2.2

17 Apr 17:48
fd0574d
Compare
Choose a tag to compare

What's Changed

๐Ÿ•ต๏ธ New Detections

  • feat: Snyk detections for OU changes and external access changes by @edyesed in #729

๐Ÿก Miscellaneous

New Contributors

Full Changelog: v3.2.1...v3.2.2

v3.2.1

05 Apr 21:07
25ffff8
Compare
Choose a tag to compare

New Detections

๐Ÿ” Snowflake Account Admin Assigned Query
๐Ÿ” Snowflake Brute Force IP Query
๐Ÿ” Snowflake Brute Force Username Query
๐Ÿ” Snowflake Login Without MFA Query
๐Ÿ•ต๏ธโ€โ™‚๏ธ GCP BigQuery Large Scan Detection
๐Ÿ•ต๏ธโ€โ™‚๏ธ GCP Cloud Storage Bucket Modified or Deleted Detection
๐Ÿ•ต๏ธโ€โ™‚๏ธ GCP Destructive Queries Detection
๐Ÿ•ต๏ธโ€โ™‚๏ธ GCP Logging Settings Modified Detection
๐Ÿ•ต๏ธโ€โ™‚๏ธ Snyk System Policy Change Detection
๐Ÿ•ต๏ธโ€โ™‚๏ธ Snyk SSO Modified Detection

Full Changelog: v3.2.0...v3.2.1

v3.2.0

15 Mar 20:28
ce0b63f
Compare
Choose a tag to compare

What's Changed

๐Ÿ•ต๏ธ New Detections

  • new detection: alert when an asana user starts an export for an organization by @andrea-youwakim in #702
  • new detection: alert when a zoom user changes an organization's sign in requirements by @andrea-youwakim in #692

๐Ÿ› Bug Fixes and Tunes

  • adding additional logic to drop alert severity to low if outcome is DENY by @andrea-youwakim in #709

๐Ÿก Miscellaneous

  • feat: vscode one click debugging by @edyesed in #706
  • GCP VPC Flow Logs Disabled and Request Violating VPC Service Controls by @calkim-panther in #707
  • Fix/edyesed/ignore aws distributed policies by @edyesed in #710

Full Changelog: v3.1.0...v3.2.0

v3.1.0

06 Mar 19:03
35b399a
Compare
Choose a tag to compare

What's Changed

๐Ÿ•ต๏ธ New Detections

  • new detection: alerts when an asana user changes an organization's password requirements to 'simple' by @andrea-youwakim in #701
  • New detection: alert when an asana user makes saml optional for an organization by @andrea-youwakim in #696
  • New detection: alerts when asana user disables app approval requirements for an organization by @andrea-youwakim in #697
  • Feat: global filter for github log sources by @edyesed in #705

๐ŸŒฏ Packs changes

  • Asana pack -> New detections
  • GitHub pack -> global filter added to pack and detections

๐Ÿ› Bug Fixes and Tunes

๐Ÿก Miscellaneous

  • chore: let automagic release note generation do more for us by @edyesed in #698

Full Changelog: v3.0.1...v3.1.0

v3.0.1

01 Mar 17:15
57c811b
Compare
Choose a tag to compare

Miscellaneous

๐Ÿ  chore: make fmt wanted to reorder a few imports based on panther being renamed panther_default by @edyesed in #700

Full Changelog: v3.0.0...v3.0.1

v3.0.0

01 Mar 00:25
19a9e47
Compare
Choose a tag to compare

Why a major version change

We've updated the name of the global helper previously known as panther to panther_default.

This change aligns the python module name of the global helper to be the same as the file name which provides the module. With the two names in sync, your IDE's code completion features should be working. If you have already informed your IDE to use global_helpers as an autocomplete and/or analysis path, no action is needed. If you haven't set that up already, there are some vscode specific examples on #691

New Detections

๐Ÿ•ต๏ธโ€โ™‚๏ธ new asana service account is created by @andrea-youwakim in #695

Bug Fixes

๐Ÿ› new format for AWS resource tags by @calkim-panther in #664

Miscellaneous

๐Ÿ  fix: update panther_default global helper use its file name for IDE happiness by @edyesed in #691
๐Ÿ  feat: logtype global filter for cloudflare events by @edyesed in #690
๐Ÿ  fix: sync policyuniverse version to backend by @edyesed in #699

Full Changelog: v2.2.0...v3.0.0

v2.2.0

28 Feb 17:27
f877c59
Compare
Choose a tag to compare

New Detections

๐Ÿ•ต๏ธโ€โ™‚๏ธ Add Dropbox Team Member Linked App Rule by @egibs in #687

Bug Fixes

๐Ÿ› Refactor: slack_user_privilege_escalation by @miotke in #686
๐Ÿ› Snowflake Query DisplayName Updates by @mbellifa in #682
๐Ÿ› tuning: high vol events blocked greynoise by @andrea-youwakim in #688

Miscellaneous

๐Ÿ  Bump PAT version to 0.19.6 by @egibs in #684 & #685

New Contributors

Full Changelog: v2.1.0...v2.2.0