Skip to Content

December 2025 Product Releases

Enhancement

Detect - Auto-Close Discarded Alerts

Once enabled, Detect automatically closes vendor alerts that were evaluated in GreyMatter and discarded, closing them in the supported source technology with a standardized closure note. Alert lifecycle management takes less manual effort.

Enhancement

Phishing Analyzer - Recipient and Interaction Enrichment

Phishing Analyzer now lists an email's recipients, who clicked its links, who downloaded attachments, and who replied. Analysts see the full scope of impact for each reported phish. Only available for Microsoft Defender customers.

New Release

Transit - Detection in Transit

GreyMatter Transit is a cloud-native data ingestion and routing service that detects threats in near real time as data moves through the pipeline, before it reaches storage. Intelligent filtering and routing of telemetry help optimize cost and open up flexible data architecture options.

Enhancement

Discover - Saved Filters and Queries

Asset table filters and queries can now be saved, named, edited and cleared, so complex views do not need to be rebuilt after navigating away. A new Query on: Managed Assets option applies queries to managed assets.

Enhancement

Workflows - Case Triggers, Filter Nodes and Task Nodes

Workflows gains case creation triggers, artifact-based trigger conditions, advanced switch statements, data filter nodes, task creation nodes, and dynamic artifact context in notifications with domain control. Teams can build more tailored workflows and communicate more clearly.

Enhancement

Mobile App - Social Media Impersonation Takedowns

Takedowns in the GreyMatter Mobile App now include a takedown type for social media impersonations.

Enhancement

Intel - Default Subscriptions

New GreyMatter customers are automatically subscribed to Threat Advisories and Weekly Intelligence Summaries, and preferences for both can be updated within GreyMatter. Customers receive the latest ReliaQuest threat intelligence from day one.

Direct Sources

Direct Sources

Source

Supported GreyMatter Capabilities

iboss Zero Trust SASE

Detect, Investigate/Hunt, Asset Inventory, Respond

Saviynt Enterprise Identity Cloud

Respond

Enhanced Sources

Direct Sources

Source

Updated GreyMatter Capabilities

Qualys

Respond: Initiate Scan IP, Scan Results, Initiate Scan Host

CrowdStrike Falcon Adversary Intelligence

Respond: Enrich Hash, Enrich Domain, Enrich URL, Analyze URL

Google Workspace

Detect, Investigate/Hunt, Asset Inventory, Respond

See Our 300+ Supported Sources

The GreyMatter Universal Translator automatically normalizes every field from any connected technology to OCSF—enabling detection, investigation, and response across your entire stack from one place, without centralizing data first.