Skip to Content

GreyMatter Custom Reporting

Custom Reporting brings your security metrics into GreyMatter on demand, so everyone from your SOC analysts to your CISO can visualize and share the information most relevant to them.

On first launch you'll find a default dashboard already populated with widgets covering the most commonly requested metrics. From there, the layout is yours to control - each widget is an individual component you can rearrange by drag-and-drop and tailor to the way your team works.


OT Engineer Teammate

The OT Engineer Teammate is a new Agentic Teammate for industrial (OT) environments, bringing IT and OT visibility together in one place. It is included for Teammates customers at no additional purchase and activates automatically when a supported OT platform is connected.

The Teammate applies expertise in industrial protocols, PLC operations, and PCAP analysis to every alert, correlating OT telemetry with IT signals to show how an attacker got in and what else is at risk. Each incident is enriched with device identity, criticality, zone, and physical process role, so you can see which detections matter most to your operations. You can also ask the Teammate questions in GreyMatter Chat about alerts, assets, incidents, trends, and summaries. It recommends, routes, and assists only - it takes no autonomous actions in your OT environment.


Phishing Analyzer – Dedicated Workspace and Remediation Enhancements

All reported phishing emails now have a single, dedicated workspace at Investigate > Phishing Analyzer, bringing summary widgets, search, filters, and direct response actions together in one place.

Mass Delete remediation also gains more precise match criteria and broader coverage, including Message ID matching, configurable search lookback, stricter handling of unknown senders, and new Mass Soft Delete and Mass Hard Delete playbooks that remove copies of a phishing email across mailboxes.


Discover – Expanded Exposure Rule Library

Discover now includes a library of ReliaQuest-authored exposure rules. These rules are pre-built and validated, so you can activate them and scale coverage across your environment without writing custom logic of your own.

The library also extends Discover into new areas of risk, most notably identity misconfigurations. Identity findings that previously went unseen, or took significant manual effort to uncover, now surface automatically as exposures - giving you broader coverage of your attack surface with far less hands-on work.


Discover – AI Visibility

Discover now surfaces an inventory of the AI tools running in your environment, identified from the software and SaaS data already flowing into the platform. No new integrations or configuration are required.

You get continuous visibility into which AI tools are in use and where they appear, so you can assess the risk they introduce and apply the governance and policies your organization requires.


Discover – Onboarding Experience

Discover now walks you through setup the first time you open it. Four guided steps cover your refresh schedule, your inventory definitions across assets, identities, software, SaaS apps, and AI tools, your external scan targets, and your auto tags. Each inventory category gives you a preset option, a query builder for more specific conditions, or a ReliaQuest default you can accept as-is, so your inventory totals reflect what your team actually manages.

Every step is optional and resumable. Skip one and it resurfaces as a callout on the page it applies to, while a tracker in the navigation shows how far along you are and reopens setup at your first incomplete step. What you define in setup applies to everyone in your organization, not just your own view, and you can change any of your choices later in Discover settings.


Discover – Customizable Overview

The Discover Overview is now a dashboard you control. Add widgets, rearrange the grid by drag-and-drop, and save layouts as reports you can return to - the same experience as Custom Reporting. Widgets draw on assets, identities, software, SaaS apps, AI tools, exposures, and sources, and can be rendered as bar, line, donut, table, funnel, or single-score visualizations. The default Overview is itself a saved layout, so you can duplicate it and adapt a copy rather than starting from scratch. Saved reports and favorites are yours individually.

Pinned above the grid, a daily summary highlights the highest-risk scenarios in your environment so you know where to start. The Exposures widget also gains rule severity per row, the percent of objects impacted, and the ability to pin and reorder what matters most to you.


Respond in Mobile

You can now take response action from the GreyMatter mobile app. When you open an incident, AI-suggested playbooks appear based on that incident's artifacts, with the run form already populated - no more returning to the web to act. The full Respond library is available to you as well, both from inside an incident and on demand, and you can trigger response through GreyMatter Chat. Reversal plays are linked to the actions that created them, so undoing a response is a single step.

A Respond activity history in the app mirrors what you see on the web, giving you a record of what was run, by whom, and when. Playbook-complete notifications now take you straight to the play's detail view.


Transit – Forwarders Tab and Reference List Library

Transit has a new Forwarders tab, where you can view and manage every GreyMatter agent with the Transit capability installed. Within the tab you can create Groups of forwarders to apply pipelines at scale; forwarders inherit the pipelines assigned to their Group and can join or leave a Group without changing that Group's configuration.


GreyMatter Ticket Sync – Ivanti

GreyMatter's native bidirectional ticket sync now extends to Ivanti, joining Google SecOps SOAR, ServiceNow, Splunk SOAR, ConnectWise Manage, and Freshservice. Incidents created or updated in GreyMatter Investigate automatically sync to your ticketing system in near real-time, with updates from either side reflected in the other. You can configure the integration yourself using the Add Source button in Connected Sources.


New Direct Sources

Source

Supported Capabilities

Adaxes

Discover

AppOmni

Detect at Source, Investigate/Hunt, GreyMatter Detect, Discover, Detection State Syncing

AWS CloudWatch

Detect at Source

AWS WAF

Respond

Azure WAF

Respond

BeyondTrust EPM

Detect at Source, Investigate/Hunt, Discover, Respond

BitSight SPM

Detect at Source, Investigate/Hunt, Discover

Box Cloud Storage

Detect at Source, Respond

Cato XDR

Detect at Source, Investigate/Hunt, Discover, Respond, Detection State Syncing

Cisco CloudLock

Detect at Source, Investigate/Hunt, Discover, Respond, Detection State Syncing

Cisco Secure Access

Investigate/Hunt, Respond, Asset Inventory

Cloudflare Zero Trust

Respond, Asset Inventory

CrowdStrike Falcon AIDR

Detect at Source, Investigate/Hunt

CrowdStrike Falcon Cloud

Detect at Source, Discover, Respond

Cyberhaven

Detect at Source, Asset Inventory

Cyera DLP

Detect at Source, Respond, Detection State Syncing

Delinea Secret Server

Investigate/Hunt, Discover, Respond

Fastly NGWAF

Investigate/Hunt, Respond

Forcepoint DLP

Detect at Source, Detection State Syncing

Google Cloud Armor

Intel Push, Respond

Grip Security

Detect at Source, Discover, Respond

Illumio

Investigate/Hunt, Discover, Respond

Imperva Cloud WAF

Investigate/Hunt, Respond

Imprivata

Discover, Respond

Ironscales

Detect at Source, Investigate/Hunt, Discover, Respond, Detection State Syncing

Island Enterprise Browser

Investigate/Hunt, Discover, Respond

Jamf Protect

Detect at Source, Discover

Jira

Investigate/Hunt, Respond, Asset Inventory

Netwrix Auditor

Investigate/Hunt

OneLogin Workforce

Investigate/Hunt, Discover, Respond

Oracle Cloud HCM

Respond, Asset Inventory

Palo Alto Enterprise DLP

Detect at Source

PingFederate

Discover, Respond

ProofPoint DLP

Detect at Source, Investigate/Hunt, Discover, Respond

ProofPoint TRAP

Detect at Source, Respond

Rubrik Security

Detect at Source, Investigate/Hunt, Discover, Detection State Syncing

Salesforce Shield

Detect at Source, Investigate/Hunt, Detection State Syncing

SecurityScorecard

Detect at Source, Investigate/Hunt, Discover, Respond

SentinelOne Cloud Workload Security

Detect at Source, Discover, Detection Push, Detection State Syncing

SentinelOne Identity

Respond, Asset Inventory

ServiceNow

Investigate/Hunt, Discover

Tenable Security Center

Discover, Respond

ThreatLocker

Investigate/Hunt, Respond, Asset Inventory

Enhanced Direct Sources

Source

Updated GreyMatter Capabilities

Microsoft Active Directory

Respond — New Playbook: Move User to OU, relocates a specified user account into a designated Active Directory organizational unit.

See Our 300+ Supported Sources

The GreyMatter Universal Translator automatically normalizes every field from any connected technology to OCSF—enabling detection, investigation, and response across your entire stack from one place, without centralizing data first.