GreyMatter Custom Reporting
Custom Reporting brings your security metrics into GreyMatter on demand, so everyone from your SOC analysts to your CISO can visualize and share the information most relevant to them.
On first launch you'll find a default dashboard already populated with widgets covering the most commonly requested metrics. From there, the layout is yours to control - each widget is an individual component you can rearrange by drag-and-drop and tailor to the way your team works.
OT Engineer Teammate
The OT Engineer Teammate is a new Agentic Teammate for industrial (OT) environments, bringing IT and OT visibility together in one place. It is included for Teammates customers at no additional purchase and activates automatically when a supported OT platform is connected.
The Teammate applies expertise in industrial protocols, PLC operations, and PCAP analysis to every alert, correlating OT telemetry with IT signals to show how an attacker got in and what else is at risk. Each incident is enriched with device identity, criticality, zone, and physical process role, so you can see which detections matter most to your operations. You can also ask the Teammate questions in GreyMatter Chat about alerts, assets, incidents, trends, and summaries. It recommends, routes, and assists only - it takes no autonomous actions in your OT environment.
Phishing Analyzer – Dedicated Workspace and Remediation Enhancements
All reported phishing emails now have a single, dedicated workspace at Investigate > Phishing Analyzer, bringing summary widgets, search, filters, and direct response actions together in one place.
Mass Delete remediation also gains more precise match criteria and broader coverage, including Message ID matching, configurable search lookback, stricter handling of unknown senders, and new Mass Soft Delete and Mass Hard Delete playbooks that remove copies of a phishing email across mailboxes.
Discover – Expanded Exposure Rule Library
Discover now includes a library of ReliaQuest-authored exposure rules. These rules are pre-built and validated, so you can activate them and scale coverage across your environment without writing custom logic of your own.
The library also extends Discover into new areas of risk, most notably identity misconfigurations. Identity findings that previously went unseen, or took significant manual effort to uncover, now surface automatically as exposures - giving you broader coverage of your attack surface with far less hands-on work.
Discover – AI Visibility
Discover now surfaces an inventory of the AI tools running in your environment, identified from the software and SaaS data already flowing into the platform. No new integrations or configuration are required.
You get continuous visibility into which AI tools are in use and where they appear, so you can assess the risk they introduce and apply the governance and policies your organization requires.
Discover – Onboarding Experience
Discover now walks you through setup the first time you open it. Four guided steps cover your refresh schedule, your inventory definitions across assets, identities, software, SaaS apps, and AI tools, your external scan targets, and your auto tags. Each inventory category gives you a preset option, a query builder for more specific conditions, or a ReliaQuest default you can accept as-is, so your inventory totals reflect what your team actually manages.
Every step is optional and resumable. Skip one and it resurfaces as a callout on the page it applies to, while a tracker in the navigation shows how far along you are and reopens setup at your first incomplete step. What you define in setup applies to everyone in your organization, not just your own view, and you can change any of your choices later in Discover settings.
Discover – Customizable Overview
The Discover Overview is now a dashboard you control. Add widgets, rearrange the grid by drag-and-drop, and save layouts as reports you can return to - the same experience as Custom Reporting. Widgets draw on assets, identities, software, SaaS apps, AI tools, exposures, and sources, and can be rendered as bar, line, donut, table, funnel, or single-score visualizations. The default Overview is itself a saved layout, so you can duplicate it and adapt a copy rather than starting from scratch. Saved reports and favorites are yours individually.
Pinned above the grid, a daily summary highlights the highest-risk scenarios in your environment so you know where to start. The Exposures widget also gains rule severity per row, the percent of objects impacted, and the ability to pin and reorder what matters most to you.
Respond in Mobile
You can now take response action from the GreyMatter mobile app. When you open an incident, AI-suggested playbooks appear based on that incident's artifacts, with the run form already populated - no more returning to the web to act. The full Respond library is available to you as well, both from inside an incident and on demand, and you can trigger response through GreyMatter Chat. Reversal plays are linked to the actions that created them, so undoing a response is a single step.
A Respond activity history in the app mirrors what you see on the web, giving you a record of what was run, by whom, and when. Playbook-complete notifications now take you straight to the play's detail view.
Transit – Forwarders Tab and Reference List Library
Transit has a new Forwarders tab, where you can view and manage every GreyMatter agent with the Transit capability installed. Within the tab you can create Groups of forwarders to apply pipelines at scale; forwarders inherit the pipelines assigned to their Group and can join or leave a Group without changing that Group's configuration.
GreyMatter Ticket Sync – Ivanti
GreyMatter's native bidirectional ticket sync now extends to Ivanti, joining Google SecOps SOAR, ServiceNow, Splunk SOAR, ConnectWise Manage, and Freshservice. Incidents created or updated in GreyMatter Investigate automatically sync to your ticketing system in near real-time, with updates from either side reflected in the other. You can configure the integration yourself using the Add Source button in Connected Sources.
New Direct Sources
Source | Supported Capabilities |
|---|---|
Adaxes | Discover |
AppOmni | Detect at Source, Investigate/Hunt, GreyMatter Detect, Discover, Detection State Syncing |
AWS CloudWatch | Detect at Source |
AWS WAF | Respond |
Azure WAF | Respond |
BeyondTrust EPM | Detect at Source, Investigate/Hunt, Discover, Respond |
BitSight SPM | Detect at Source, Investigate/Hunt, Discover |
Box Cloud Storage | Detect at Source, Respond |
Cato XDR | Detect at Source, Investigate/Hunt, Discover, Respond, Detection State Syncing |
Cisco CloudLock | Detect at Source, Investigate/Hunt, Discover, Respond, Detection State Syncing |
Cisco Secure Access | Investigate/Hunt, Respond, Asset Inventory |
Cloudflare Zero Trust | Respond, Asset Inventory |
CrowdStrike Falcon AIDR | Detect at Source, Investigate/Hunt |
CrowdStrike Falcon Cloud | Detect at Source, Discover, Respond |
Cyberhaven | Detect at Source, Asset Inventory |
Cyera DLP | Detect at Source, Respond, Detection State Syncing |
Delinea Secret Server | Investigate/Hunt, Discover, Respond |
Fastly NGWAF | Investigate/Hunt, Respond |
Forcepoint DLP | Detect at Source, Detection State Syncing |
Google Cloud Armor | Intel Push, Respond |
Grip Security | Detect at Source, Discover, Respond |
Illumio | Investigate/Hunt, Discover, Respond |
Imperva Cloud WAF | Investigate/Hunt, Respond |
Imprivata | Discover, Respond |
Ironscales | Detect at Source, Investigate/Hunt, Discover, Respond, Detection State Syncing |
Island Enterprise Browser | Investigate/Hunt, Discover, Respond |
Jamf Protect | Detect at Source, Discover |
Jira | Investigate/Hunt, Respond, Asset Inventory |
Netwrix Auditor | Investigate/Hunt |
OneLogin Workforce | Investigate/Hunt, Discover, Respond |
Oracle Cloud HCM | Respond, Asset Inventory |
Palo Alto Enterprise DLP | Detect at Source |
PingFederate | Discover, Respond |
ProofPoint DLP | Detect at Source, Investigate/Hunt, Discover, Respond |
ProofPoint TRAP | Detect at Source, Respond |
Rubrik Security | Detect at Source, Investigate/Hunt, Discover, Detection State Syncing |
Salesforce Shield | Detect at Source, Investigate/Hunt, Detection State Syncing |
SecurityScorecard | Detect at Source, Investigate/Hunt, Discover, Respond |
SentinelOne Cloud Workload Security | Detect at Source, Discover, Detection Push, Detection State Syncing |
SentinelOne Identity | Respond, Asset Inventory |
ServiceNow | Investigate/Hunt, Discover |
Tenable Security Center | Discover, Respond |
ThreatLocker | Investigate/Hunt, Respond, Asset Inventory |
Enhanced Direct Sources
Source | Updated GreyMatter Capabilities |
|---|---|
Microsoft Active Directory | Respond — New Playbook: Move User to OU, relocates a specified user account into a designated Active Directory organizational unit. |
