IT Engineer Teammate
The IT Engineer Teammate is a new Agentic Teammate for infrastructure health, building on the Agentic AI capabilities for GreyMatter Health Alerts. For Teammates customers, it coordinates with your other Teammates — flagging infrastructure issues that impact detection, hunting, or threat intel operations — and answers cross-Teammate questions in GreyMatter Chat, such as "How is this SIEM parsing failure impacting my detection coverage?" It also analyzes firewall configurations on request: upload a configuration file in chat to receive prioritized recommendations and an updated configuration file compared against the original.
Redesigned Workflow Builder
The GreyMatter Workflow Builder has been redesigned to make authoring and editing automations faster and more intuitive. Build and rearrange workflows directly on the canvas with drag-and-drop editing, scan longer workflows more easily with the new top-to-bottom layout, and swap the trigger on a live workflow without rebuilding it. Five new trigger types expand what can kick off a workflow: Incident Closure, Intel Subscription, Respond Play, Post-Digital Risk Alert Analysis, and Discover Refresh.
Improved Respond Experience
A new Automated Response tab in Respond gives you a dedicated view of your Automated Response Playbooks — select any playbook to see which signatures have it available or configured, and view its active workflows. The Respond Activity tab now provides a full history of playbook runs across web and mobile, with new filters including Ran By Type, Integration, Company, and Proactive Blocks, plus a details side panel and full-screen playbook outputs.
Targeted Search
Targeted Search is a new priority execution mode in GreyMatter Hunt built for time-sensitive questions, returning results in minutes. Select the Targeted Search option at hunt creation to run a single priority query directly against your integrated technologies — searching the most recent 30 days of data and returning up to 1,000 records — without affecting other queued hunts.
Users can also submit Full Native Query hunts, written in a tool's native query language (SPL, KQL, and others) and executed directly against the technology, with an AI-generated summary of the results. Hunts initiated by ReliaQuest threat hunters now appear in your Hunt activity listing with source attribution and full audit history, and you can create a case directly from hunt results.
GreyMatter Ticket Sync — Splunk SOAR, ConnectWise, and Freshservice
Native bidirectional ticket sync now extends to Splunk SOAR, ConnectWise Manage, and Freshservice — joining Google SecOps SOAR and ServiceNow. Incidents created or updated in GreyMatter Investigate sync to your ticketing system in near real time, with updates from either side reflected in the other. You configure each integration yourself directly in GreyMatter using standard platform credentials — no custom API work required.
GreyMatter Cases — Attachments and Task Export
You can now add, download, and delete file attachments directly on Cases and Tasks, keeping relevant documentation organized in one place, with attachment activity recorded in the Activity Log. Tasks can also be exported: select one or more from the list and click Export in the bulk actions toolbar.
New Direct Sources
Source | Description | Supported GreyMatter Capabilities |
|---|---|---|
Corelight Investigator | This integration connects GreyMatter to Corelight's network detection and response (NDR) platform, surfacing network-based threats alongside the rest of the environment. Correlated detections — enriched with alert counts and MITRE ATT&CK tactics and techniques — and individual alerts are ingested as GreyMatter incidents. | Detection at Source — Vendor Authored |
Salesforce | This integration enables security analysts to investigate login and administrative activity in Salesforce and respond to identity threats directly within GreyMatter, with containment actions such as disabling users, resetting passwords and multi-factor authentication, and terminating active sessions. | Investigate / Hunt, Respond |
WatchGuard Firebox | By connecting GreyMatter to WatchGuard Cloud, this integration enables analysts to contain threats at the network edge — blocking or allowing IP addresses, domains, and URLs, and banning or allowing file hashes — with each change deployed to the physical Firebox devices. | Respond |
Cribl Search | This integration leverages Cribl's search-in-place platform to allow analysts to investigate, hunt, and run GreyMatter Detect rules across data where it already lives — object storage, observability backends, and other systems — without first moving it into a separate index. | Investigate / Hunt, GreyMatter Detect, Intel |
FortiAnalyzer | This integration connects GreyMatter to Fortinet's centralized log analytics and incident management platform, enabling analysts to investigate and hunt across collected logs, ingest FortiAnalyzer alerts and incidents as detections with state and note syncing, and enrich investigations with user and host context from FortiAnalyzer UEBA. | Investigate / Hunt, Detection at Source — Vendor Authored, Detection State and Note Syncing, Respond |
Workday | This integration enriches investigations with worker identity data from Workday, resolving a user to their full worker record so GreyMatter has identity context during an investigation. | Respond |
Azure Firewall | This integration connects GreyMatter to Azure Firewall, Microsoft's cloud-native managed network firewall service, enabling automated response actions that add and remove block and allow entries for IP addresses, domains, and URLs on a specified firewall policy. | Respond |
Tanium Asset | This integration pulls the full endpoint inventory from Tanium's IT Asset Management module into GreyMatter for comprehensive asset discovery — normalizing live data from online endpoints and retaining the last-known state of offline devices. | Asset Inventory |
Lacework FortiCNAPP | By connecting GreyMatter to Fortinet's cloud-native application protection platform, this integration streams security alerts into GreyMatter Detect and enables analysts to run investigation queries across activity and event data, enrich hosts, users, and vulnerabilities, and close alerts directly from GreyMatter. | Investigate / Hunt, Detection at Source — Vendor Authored, Detection State Syncing, Respond |
Source | Updated GreyMatter Capabilities |
|---|---|
Google Security Operations | Intel Push now supports data tables, ahead of Google's planned 2027 deprecation of reference lists. New permissions required: chronicle.dataTables.list chronicle.dataTables.create chronicle.dataTableRows.bulkUpdate chronicle.dataTableRows.bulkCreate |
Microsoft Entra ID | Respond - New playbooks: Add User To Group and Remove User From Group. New permissions required: Group.Read.All GroupMember.ReadWrite.All |
Microsoft Defender for Office 365 | Respond - New playbooks: Unquarantine Email and Enrich Quarantine Email. No new permissions required. |
