Detect - Auto-Close Discarded Alerts
Once enabled, Detect automatically closes vendor alerts that were evaluated in GreyMatter and discarded, closing them in the supported source technology with a standardized closure note. Alert lifecycle management takes less manual effort.
Phishing Analyzer - Recipient and Interaction Enrichment
Phishing Analyzer now lists an email's recipients, who clicked its links, who downloaded attachments, and who replied. Analysts see the full scope of impact for each reported phish. Only available for Microsoft Defender customers.
Transit - Detection in Transit
GreyMatter Transit is a cloud-native data ingestion and routing service that detects threats in near real time as data moves through the pipeline, before it reaches storage. Intelligent filtering and routing of telemetry help optimize cost and open up flexible data architecture options.
Discover - Saved Filters and Queries
Asset table filters and queries can now be saved, named, edited and cleared, so complex views do not need to be rebuilt after navigating away. A new Query on: Managed Assets option applies queries to managed assets.
Workflows - Case Triggers, Filter Nodes and Task Nodes
Workflows gains case creation triggers, artifact-based trigger conditions, advanced switch statements, data filter nodes, task creation nodes, and dynamic artifact context in notifications with domain control. Teams can build more tailored workflows and communicate more clearly.
Mobile App - Social Media Impersonation Takedowns
Takedowns in the GreyMatter Mobile App now include a takedown type for social media impersonations.
Intel - Default Subscriptions
New GreyMatter customers are automatically subscribed to Threat Advisories and Weekly Intelligence Summaries, and preferences for both can be updated within GreyMatter. Customers receive the latest ReliaQuest threat intelligence from day one.
Direct Sources
Source | Supported GreyMatter Capabilities |
|---|---|
iboss Zero Trust SASE | Detect, Investigate/Hunt, Asset Inventory, Respond |
Saviynt Enterprise Identity Cloud | Respond |
Direct Sources
Source | Updated GreyMatter Capabilities |
|---|---|
Qualys | Respond: Initiate Scan IP, Scan Results, Initiate Scan Host |
CrowdStrike Falcon Adversary Intelligence | Respond: Enrich Hash, Enrich Domain, Enrich URL, Analyze URL |
Google Workspace | Detect, Investigate/Hunt, Asset Inventory, Respond |
