Documentation

Managed SOC · Release Notes

Release notes

Notable changes to the Managed SOC service, detection content, and Portal experience.

Notable changes to the Managed SOC. Detection content updates continuously; only service-level and Portal changes are listed here.

2026-07

  • New: Case events (case.opened, case.updated, case.closed) are now available over webhooks for real-time SIEM/SOAR integration.
  • Improved: Data-health alerts now fire within minutes of a source going silent, with clearer remediation guidance in the Portal.
  • Improved: Expanded ATT&CK coverage for cloud control-plane techniques across AWS, Azure, and GCP.

2026-06

  • New: Response policy in the Portal lets you pre-authorize containment actions (endpoint isolation, identity disable) per severity.
  • New: Google Workspace identity connector.
  • Fixed: Duplicate notifications when a case was reassigned during triage.

2026-05

  • New: Managed SOC API v1 (cases, detections, data-health).
  • Improved: Correlation now links identity, endpoint, and email signals into a single case for account-takeover scenarios.
Need a hand with Managed SOC?Talk to our team →