We’re excited to announce the release of Cortex-Analyzers 3.5.0, a significant update for our Cortex engine, packed with features & enhancements.
This version introduces a complete set of Microsoft Entra ID integrations, a new customizable YARA analyzer, a ValidateObservable analyzer for observable syntax checking, and significantly reduced Docker image sizes (up to 95% smaller).
Here’s a closer look at what’s new:
| Full name |
Short name |
Description |
| JA4 |
JA4 |
TLS client fingerprinting |
| JA4Server |
JA4S |
TLS server response / session fingerprinting |
| JA4HTTP |
JA4H |
HTTP client fingerprinting |
| JA4Latency |
JA4L |
Client to server latency measurement |
| JA4LatencyServer |
JA4LS |
Server to client latency measurement |
| JA4X509 |
JA4X |
X.509 TLS certificate fingerprinting |
| JA4SSH |
JA4SSH |
SSH traffic fingerprinting |
| JA4TCP |
JA4T |
TCP client fingerprinting |
| JA4TCPServer |
JA4TS |
TCP server response fingerprinting |
| JA4TCPScan |
JA4TScan |
Active TCP fingerprint scanner |
Microsoft Entra ID—Identity insights, management & response
This update offers a suite of analyzers and responders glueing TheHive and Microsoft Entra ID tightly together for thorough identity management in incident response scenarios. See the line-up below!
| Criteria |
JA4+ |
JA3 |
| Sensitive to extension order |
No |
Yes |
| Resistant to GREASE |
Yes |
No |
| Supported protocols |
TLS, HTTP, SSH, TCP |
TLS only |
| Human-readable format |
Yes (structured) |
No (MD5 hashs) |
| Evolvability |
Modular and extensible |
Limited |
Get User Info
Retrieve numerous details about a user including user information, membership groups, authentication methods & assigned licenses to get contextual information on a selected identity.
Get Sign-Ins
Inspect recent user login activities, including applications used, devices involved, IP addresses, risk information and geographical locations to detect unusual or unauthorized access patterns.
Get Directory Audit Logs
Review recent changes and operations in directory audit logs tied to specific users, helping your security team pinpoint suspicious account modifications or permission escalations.
Get Managed Devices
Gather detailed information on devices linked to a specific hostname or user for better contextualization in case of investigation.
Revoke Sign-In Sessions
Immediately terminate all active sessions for a user, including refresh tokens and browser cookies—critical in scenarios involving compromised credentials or stolen devices.
EnableUser / DisableUser
Modify access rights in real time during incidents by disabling or enabling user accounts, strengthening containment and recovery efforts.
ResetPassword / ResetPassword with MFA
Force password change at next sign-in, optionally with an MFA prompt before password reset, to secure affected accounts.
YARA File Analysis—GitHub public & private repositories support
We’ve refreshed our YARA analyzer enabling you to scan files for malware, exploits and suspicious patterns. You can now easily fetch rules directly from both public and private GitHub repositories and it’s all configurable from within your Cortex instance.
Not sure which rules to start with? Feel free to check the awesome-yara repository from InQuest and get started!
ValidateObservable—Syntax & format checking for observables
The ValidateObservable analyzer verifies observables for correct syntax and structure on multiple data types. Additionally, it may give context or flag suspicious indicators—like punycode domains, malformed URLs, or filenames containing Unicode obfuscation.
Going light!—Alpine-based Docker images
We’ve updated most of our analyzers and responders to support Alpine-based Docker images, reducing image sizes by up to 95%. This means faster downloads, quicker deployments and less resource usage.
Along with these highlights, there are various bug fixes, improvements and analyzer templates enhancements, but most importantly… notable contributions from our beloved community!
- Cisco Umbrella—Support for API V2 by Noatun
- LDAP Query 3.0—More customizable parameters to fit customer-specific needs around your LDAP environment by kiaora17
- PaloAlto Wildfire URL submission—responder addition by korteke
See the complete changelog on our GitHub repository.
Since TheHive version 5.0.14 and Cortex version 3.1.7, catalogs are automatically fetched. To fully enjoy this release, please:
Lorem Ipsum is simply dummy text of the printing and typesetting industry. Lorem Ipsum has been the industry's standard dummy text ever since the 1500s, when an unknown printer took a galley of type and scrambled it to make a type specimen book. It has survived not only five centuries, but also the leap into electronic typesetting, remaining essentially unchanged. It was popularised in the 1960s with the release of Letraset sheets containing Lorem Ipsum passages, and more recently with desktop publishing software like Aldus PageMaker including versions of Lorem Ipsum.
Bogdan
Lorem Ipsum is simply dummy text of the printing and typesetting industry. Lorem Ipsum is simply dummy text of the printing and typesetting industry.