GreyMatter Custom Reporting
Custom Reporting brings your security metrics into GreyMatter on demand, so everyone from your SOC analysts to your CISO can visualize and share the information most relevant to them.
On first launch you'll find a default dashboard already populated with widgets covering the most commonly requested metrics. From there, the layout is yours to control - each widget is an individual component you can rearrange by drag-and-drop and tailor to the way your team works.
OT Engineer Teammate
The OT Engineer Teammate is a new Agentic Teammate for industrial (OT) environments, bringing IT and OT visibility together in one place. It is included for Teammates customers at no additional purchase and activates automatically when a supported OT platform is connected.
The Teammate applies expertise in industrial protocols, PLC operations, and PCAP analysis to every alert, correlating OT telemetry with IT signals to show how an attacker got in and what else is at risk. Each incident is enriched with device identity, criticality, zone, and physical process role, so you can see which detections matter most to your operations. You can also ask the Teammate questions in GreyMatter Chat about alerts, assets, incidents, trends, and summaries. It recommends, routes, and assists only - it takes no autonomous actions in your OT environment.
Phishing Analyzer – Dedicated Workspace and Remediation Enhancements
All reported phishing emails now have a single, dedicated workspace at Investigate > Phishing Analyzer, bringing summary widgets, search, filters, and direct response actions together in one place.
Mass Delete remediation also gains more precise match criteria and broader coverage, including Message ID matching, configurable search lookback, stricter handling of unknown senders, and new Mass Soft Delete and Mass Hard Delete playbooks that remove copies of a phishing email across mailboxes.
Discover – Expanded Exposure Rule Library
Discover now includes a library of ReliaQuest-authored exposure rules. These rules are pre-built and validated, so you can activate them and scale coverage across your environment without writing custom logic of your own.
The library also extends Discover into new areas of risk, most notably identity misconfigurations. Identity findings that previously went unseen, or took significant manual effort to uncover, now surface automatically as exposures - giving you broader coverage of your attack surface with far less hands-on work.
Discover – AI Visibility
Discover now surfaces an inventory of the AI tools running in your environment, identified from the software and SaaS data already flowing into the platform. No new integrations or configuration are required.
You get continuous visibility into which AI tools are in use and where they appear, so you can assess the risk they introduce and apply the governance and policies your organization requires.
GreyMatter Ticket Sync – Ivanti
GreyMatter's native bidirectional ticket sync now extends to Ivanti, joining Google SecOps SOAR, ServiceNow, Splunk SOAR, ConnectWise Manage, and Freshservice. Incidents created or updated in GreyMatter Investigate automatically sync to your ticketing system in near real-time, with updates from either side reflected in the other. You can configure the integration yourself using the Add Source button in Connected Sources.
New Direct Sources
Source | Supported Capabilities |
|---|---|
Adaxes | Discover |
AppOmni | Detect at Source, Investigate/Hunt, GreyMatter Detect, Discover, Detection State Syncing |
AWS CloudWatch | Detect at Source |
AWS WAF | Respond |
Azure WAF | Respond |
BeyondTrust EPM | Detect at Source, Investigate/Hunt, Discover, Respond |
BitSight SPM | Detect at Source, Investigate/Hunt, Discover |
Box Cloud Storage | Detect at Source, Respond |
Cato XDR | Detect at Source, Investigate/Hunt, Discover, Respond, Detection State Syncing |
Cisco CloudLock | Detect at Source, Investigate/Hunt, Discover, Respond, Detection State Syncing |
Cisco Secure Access | Investigate/Hunt, Respond, Asset Inventory |
Cloudflare Zero Trust | Respond, Asset Inventory |
CrowdStrike Falcon AIDR | Detect at Source, Investigate/Hunt |
CrowdStrike Falcon Cloud | Detect at Source, Discover, Respond |
Cyberhaven | Detect at Source, Asset Inventory |
Cyera DLP | Detect at Source, Respond, Detection State Syncing |
Delinea Secret Server | Investigate/Hunt, Discover, Respond |
Fastly NGWAF | Investigate/Hunt, Respond |
Forcepoint DLP | Detect at Source, Detection State Syncing |
Google Cloud Armor | Intel Push, Respond |
Grip Security | Detect at Source, Discover, Respond |
Illumio | Investigate/Hunt, Discover, Respond |
Imperva Cloud WAF | Investigate/Hunt, Respond |
Imprivata | Discover, Respond |
Ironscales | Detect at Source, Investigate/Hunt, Discover, Respond, Detection State Syncing |
Island Enterprise Browser | Investigate/Hunt, Discover, Respond |
Jamf Protect | Detect at Source, Discover |
Jira | Investigate/Hunt, Respond, Asset Inventory |
Netwrix Auditor | Investigate/Hunt |
OneLogin Workforce | Investigate/Hunt, Discover, Respond |
Oracle Cloud HCM | Respond, Asset Inventory |
Palo Alto Enterprise DLP | Detect at Source |
PingFederate | Discover, Respond |
ProofPoint DLP | Detect at Source, Investigate/Hunt, Discover, Respond |
ProofPoint TRAP | Detect at Source, Respond |
Rubrik Security | Detect at Source, Investigate/Hunt, Discover, Detection State Syncing |
Salesforce Shield | Detect at Source, Investigate/Hunt, Detection State Syncing |
SecurityScorecard | Detect at Source, Investigate/Hunt, Discover, Respond |
SentinelOne Cloud Workload Security | Detect at Source, Discover, Detection Push, Detection State Syncing |
SentinelOne Identity | Respond, Asset Inventory |
ServiceNow | Investigate/Hunt, Discover |
Tenable Security Center | Discover, Respond |
ThreatLocker | Investigate/Hunt, Respond, Asset Inventory |
Enhanced Direct Sources
Source | Updated GreyMatter Capabilities |
|---|---|
Microsoft Active Directory | Respond — New Playbook: Move User to OU, relocates a specified user account into a designated Active Directory organizational unit. |
