Mobile App - Respond in Mobile
Response actions can now be taken from the Mobile App: AI-suggested playbooks appear on each incident with the run form pre-populated, the full Respond library is available on demand, and response can be triggered through Chat. Reversal plays link to the actions that created them, and a Respond activity history mirrors the web.
Discover - Onboarding Experience
Discover now guides first-time setup in four optional, resumable steps: refresh schedule, inventory definitions across assets, identities, software, SaaS apps and AI tools, external scan targets, and auto tags. Choices apply to the whole organization and can be changed later in Discover settings.
Discover - Customizable Overview
The Discover Overview is now a configurable dashboard: add and rearrange widgets, save layouts as reports, and duplicate the default layout as a starting point, the same experience as Custom Reporting. A pinned daily summary highlights the highest-risk scenarios, and the Exposures widget gains rule severity, percent impacted, and pinning.
Transit - Forwarders Tab
A new Forwarders tab lists every GreyMatter agent with the Transit capability and lets teams group forwarders to apply pipelines at scale. Forwarders inherit their Group's pipelines and can join or leave without changing the Group's configuration.
Reporting - Custom Reporting
Custom Reporting brings security metrics into GreyMatter on demand, so everyone from SOC analysts to the CISO can visualize and share what matters to them. A default dashboard of commonly requested metrics is ready on first launch, and every widget can be rearranged and tailored.
Agentic Teammates - OT Engineer Teammate
The OT Engineer Teammate brings IT and OT visibility together, applying expertise in industrial protocols, PLC operations and PCAP analysis to every alert and enriching incidents with device identity, criticality, zone and process role. Included for Teammates customers at no additional purchase, it activates automatically when a supported OT platform is connected and recommends, routes and assists only, taking no autonomous action in the OT environment.
Enhanced Direct Sources
Source | Updated GreyMatter Capabilities |
|---|---|
Microsoft Active Directory | Respond: Move User to OU |
Phishing Analyzer - Dedicated Workspace and Remediation Enhancements
Reported phishing emails now have a single workspace at Investigate > Phishing Analyzer with summary widgets, search, filters and direct response actions. Mass Delete gains Message ID matching, configurable lookback, stricter unknown-sender handling, and new Mass Soft Delete and Mass Hard Delete playbooks.
Platform - Ticket Sync for Ivanti
Bidirectional ticket sync now extends to Ivanti, joining Google SecOps SOAR, ServiceNow, Splunk SOAR, ConnectWise Manage and Freshservice. Customers configure it themselves from Add Source in Connected Sources.
New Direct Sources
Source | Supported GreyMatter Capabilities |
|---|---|
Adaxes | Discover |
AppOmni | Detect at Source, Detect, Detection State Syncing, Investigate/Hunt, Discover |
AWS CloudWatch | Detect at Source |
AWS WAF | Respond |
Azure WAF | Respond |
BeyondTrust EPM | Detect at Source, Investigate/Hunt, Discover, Respond |
BitSight SPM | Detect at Source, Investigate/Hunt, Discover |
Box Cloud Storage | Detect at Source, Respond |
Cato XDR | Detect at Source, Detection State Syncing, Investigate/Hunt, Discover, Respond |
Cisco CloudLock | Detect at Source, Detection State Syncing, Investigate/Hunt, Discover, Respond |
Cisco Secure Access | Investigate/Hunt, Asset Inventory, Respond |
Cloudflare Zero Trust | Asset Inventory, Respond |
CrowdStrike Falcon AIDR | Detect at Source, Investigate/Hunt |
CrowdStrike Falcon Cloud | Detect at Source, Discover, Respond |
Cyberhaven | Detect at Source, Asset Inventory |
Cyera DLP | Detect at Source, Detection State Syncing, Respond |
Delinea Secret Server | Investigate/Hunt, Discover, Respond |
Fastly NGWAF | Investigate/Hunt, Respond |
Forcepoint DLP | Detect at Source, Detection State Syncing |
Google Cloud Armor | Intel Push, Respond |
Grip Security | Detect at Source, Discover, Respond |
Illumio | Investigate/Hunt, Discover, Respond |
Imperva Cloud WAF | Investigate/Hunt, Respond |
Imprivata | Discover, Respond |
Ironscales | Detect at Source, Detection State Syncing, Investigate/Hunt, Discover, Respond |
Island Enterprise Browser | Investigate/Hunt, Discover, Respond |
Jamf Protect | Detect at Source, Discover |
Jira | Investigate/Hunt, Asset Inventory, Respond |
Netwrix Auditor | Investigate/Hunt |
OneLogin Workforce | Investigate/Hunt, Discover, Respond |
Oracle Cloud HCM | Asset Inventory, Respond |
Palo Alto Enterprise DLP | Detect at Source |
PingFederate | Discover, Respond |
Proofpoint DLP | Detect at Source, Investigate/Hunt, Discover, Respond |
Proofpoint TRAP | Detect at Source, Respond |
Rubrik Security | Detect at Source, Detection State Syncing, Investigate/Hunt, Discover |
Salesforce Shield | Detect at Source, Detection State Syncing, Investigate/Hunt |
SecurityScorecard | Detect at Source, Investigate/Hunt, Discover, Respond |
SentinelOne Cloud Workload Security | Detect at Source, Detection Push, Detection State Syncing, Discover |
SentinelOne Identity | Asset Inventory, Respond |
ServiceNow | Investigate/Hunt, Discover |
Tenable Security Center | Discover, Respond |
ThreatLocker | Investigate/Hunt, Asset Inventory, Respond |
Discover - Expanded Exposure Rule Library
Discover now includes a library of pre-built, validated ReliaQuest-authored exposure rules that can be activated without writing custom logic. Coverage extends into new areas, notably identity misconfigurations that previously went unseen.
Discover - AI Visibility
Discover now inventories the AI tools running in the environment from software and SaaS data already in the platform, with no new integrations required. Teams see which AI tools are in use and where, and can apply the governance and policies their organization requires.
