Investigate - Agentic Memories and Model Guidance
Agentic Memories now combine with model guidance in one place for managing the instructions given to GreyMatter's agentic systems. Memories apply in three categories: Global for every IR investigation, Adaptive when an investigation reaches a similarity threshold, and Conditional when user-specified criteria such as a Rule ID are met.
Platform - Source Health Monitoring
GreyMatter continuously monitors integrated sources for expired credentials, revoked permissions and connectivity failures in real time. Required API permissions show during setup, errors are deduplicated into an auto-updating health status, and alerts can be acknowledged and resolved with notes in the platform.
New Direct Sources - Claude Compliance
Source | Supported GreyMatter Capabilities |
|---|---|
Claude Compliance | Detect at Source, Investigate/Hunt, Respond |
Chat - Digital Risk Protection Data in Chat
Chat now includes Digital Risk Protection data, so users can explore DRP alerts, trends and potential threat actor activity in natural language.
Mobile App - Intel on the Go and Session Settings
Intel Updates, Threat Advisories and Threat Profiles are now fully available in the Mobile App with search and filtering. Users can also set a preferred session timeout in app settings, up to a default of 8 hours, which resets at every log-in.
Agentic Teammates - Action Approval Notifications
A dedicated notification type now appears whenever a Teammate action is pending analyst approval, so AI-driven actions are reviewed on time.
New Direct Sources - Proofpoint TRIC, SailPoint IdentityIQ
Source | Supported GreyMatter Capabilities |
|---|---|
Proofpoint Cloud Threat Response (TRIC) | Detect at Source, Investigate/Hunt |
SailPoint IdentityIQ | Investigate/Hunt, Asset Inventory, Respond |
Enhanced Direct Sources
Source | Updated GreyMatter Capabilities |
|---|---|
CyberArk Workforce Identity | Authentication update: User ID and Password replaces manual tokens |
Transit - Multi-Event Detection
Transit can now correlate multiple events to identify advanced, multi-stage attacks before data reaches storage. More complex detections run in transit, reducing reliance on storage technologies and lowering mean time to detect.
Cases - Attachments, Saved Filters and AI Summaries
Cases now supports attachments, saved filters, reusable Investigate queries, and a consistent UI for bulk actions on Tasks. An AI-powered summary gives an evolving overview of each Case as information is gathered.
Detect - Automated Detection Rule Tuning
When an alert is closed as False Positive with a tuning ticket, the recommendation is automatically reviewed, tested and surfaced for approval. Tuning tasks are managed in the new Detection Tuning section of Cases before any change is applied.
Workflows - Workflows Tab, Scheduling and Agentic Teammate Nodes
A dedicated Workflows tab, an improved builder, recurring schedules and workflow duplication are now available to all customers. Teammates customers can also build their own Agentic Teammate workflows with three new nodes: Teammate Instructions, Execute Prompt, and Teammate Action with an optional human approval gate.
New Direct Sources - Akamai Traffic Peak
Source | Supported GreyMatter Capabilities |
|---|---|
Akamai TrafficPeak | Detect at Source, Investigate/Hunt |
