Skip to Content

May 2026 Product Releases

Enhancement

Investigate - Agentic Memories and Model Guidance

Agentic Memories now combine with model guidance in one place for managing the instructions given to GreyMatter's agentic systems. Memories apply in three categories: Global for every IR investigation, Adaptive when an investigation reaches a similarity threshold, and Conditional when user-specified criteria such as a Rule ID are met.

New Release

Platform - Source Health Monitoring

GreyMatter continuously monitors integrated sources for expired credentials, revoked permissions and connectivity failures in real time. Required API permissions show during setup, errors are deduplicated into an auto-updating health status, and alerts can be acknowledged and resolved with notes in the platform.

Direct Sources

New Direct Sources - Claude Compliance

Source

Supported GreyMatter Capabilities

Claude Compliance

Detect at Source, Investigate/Hunt, Respond

Enhancement

Chat - Digital Risk Protection Data in Chat

Chat now includes Digital Risk Protection data, so users can explore DRP alerts, trends and potential threat actor activity in natural language.

Enhancement

Mobile App - Intel on the Go and Session Settings

Intel Updates, Threat Advisories and Threat Profiles are now fully available in the Mobile App with search and filtering. Users can also set a preferred session timeout in app settings, up to a default of 8 hours, which resets at every log-in.

Enhancement

Agentic Teammates - Action Approval Notifications

A dedicated notification type now appears whenever a Teammate action is pending analyst approval, so AI-driven actions are reviewed on time.

Direct Sources

New Direct Sources - Proofpoint TRIC, SailPoint IdentityIQ

Source

Supported GreyMatter Capabilities

Proofpoint Cloud Threat Response (TRIC)

Detect at Source, Investigate/Hunt

SailPoint IdentityIQ

Investigate/Hunt, Asset Inventory, Respond

Enhanced Sources

Enhanced Direct Sources

Source

Updated GreyMatter Capabilities

CyberArk Workforce Identity

Authentication update: User ID and Password replaces manual tokens

Enhancement

Transit - Multi-Event Detection

Transit can now correlate multiple events to identify advanced, multi-stage attacks before data reaches storage. More complex detections run in transit, reducing reliance on storage technologies and lowering mean time to detect.

Enhancement

Cases - Attachments, Saved Filters and AI Summaries

Cases now supports attachments, saved filters, reusable Investigate queries, and a consistent UI for bulk actions on Tasks. An AI-powered summary gives an evolving overview of each Case as information is gathered.

New Release

Detect - Automated Detection Rule Tuning

When an alert is closed as False Positive with a tuning ticket, the recommendation is automatically reviewed, tested and surfaced for approval. Tuning tasks are managed in the new Detection Tuning section of Cases before any change is applied.

Enhancement

Workflows - Workflows Tab, Scheduling and Agentic Teammate Nodes

A dedicated Workflows tab, an improved builder, recurring schedules and workflow duplication are now available to all customers. Teammates customers can also build their own Agentic Teammate workflows with three new nodes: Teammate Instructions, Execute Prompt, and Teammate Action with an optional human approval gate.

Direct Sources

New Direct Sources - Akamai Traffic Peak

Source

Supported GreyMatter Capabilities

Akamai TrafficPeak

Detect at Source, Investigate/Hunt

See Our 300+ Supported Sources

Claude Enterprise activity data flows directly into GreyMatter for detection, investigation, and response—same workflows, same Agentic Teammates, same platform that already connects 300+ security technologies.