Skip to content

Securing the Future of Work: Agent Behavior Analytics with Google Cloud — Read the Blog

What’s New in Exabeam Product Development – November 2023

  • Dec 11, 2023
  • Jeannie Warner
  • 3 minutes to read

Table of Contents

    The Exabeam November feature release is now available to customers. As part of our commitment to developing an open security operations platform that doesn’t limit customer choice, we’ve added new partner integrations with Cribl, Teams, and Slack. Improved MITRE ATT&CK framework mapping allows customers to closely align their Exabeam deployment with ATT&CK in Outcomes Navigator as well as Correlation Rules. 

    We have also completed an IRAP assessment at the PROTECTED level for the Exabeam Security Operations Platform, a testament to our continuous dedication to delivering and maintaining AI-driven and cloud-native security operations solutions in accordance with the most rigorous security benchmarks. To further streamline SOC workflows and boost analyst productivity, we’ve also simplified the correlation rule lookup process and added nine new pre-built dashboards. 

    Exabeam Cribl Collector via Google Cloud Storage for accelerated threat detection

    In August, we announced a strategic partnership with Cribl to accelerate threat detection for Exabeam customers. The Exabeam Cribl Collector is now available via Google Cloud Storage buckets. This continued integration with Cribl allows security teams to gain additional control over telemetry data, and the flexibility to shape logs into any format needed.  

    The Cribl Collector works with Exabeam to provide efficient data ingestion while reducing storage costs by ensuring that only relevant data gets ingested into the platform. Additional benefits of the Exabeam and Cribl integration include the ability to route log data to multiple locations, reprocess logs, and optimize data flow dependencies.

    Together, Exabeam and Cribl provide security teams with better visibility into the right data sets to accelerate threat detection, investigation, and response (TDIR).

    What’s New in Exabeam Product Development — November Release 2023
    Figure 1. Exabeam and Cribl data flow optimization

    Learn more about how Exabeam and Cribl work together to accelerate security operations, then get a demo to see how Exabeam and Cribl work together to improve security operations.

    Microsoft Teams and Slack notifications meet you where you work

    Every organization and security operations team is different in how they best communicate with one another, and the tools they use for everyday work. For November, Exabeam has added support for Teams and Slack notifications. These new notification options reduce the time it takes to acknowledge and respond to threats by notifying users in their preferred daily workflow. 

    https://tinyurl.com/ylyrr9yb
    Figure 2.  Exabeam notification in Microsoft Teams

    Figure 2 above represents an example of a Teams or Slack notification. Expanding on the existing options of in-app, email, and webhooks, these new notifications can be sent to multiple channels and include information on the event, severity, Exabeam application, and a remediation recommendation.

    Mapping Outcomes Navigator to the ATT&CK framework

    The ATT&CK framework is a global knowledge base of adversary tactics and techniques, derived from real-world cybersecurity threat observations. Security organizations now lean towards using tactics, techniques, and procedures (TTPs) to detect adversaries. Unlike indicators of compromise (IoCs), which are attack artifacts, TTPs detail the ongoing attack behaviors, empowering analysts for proactive threat detection. 

    Exabeam has expanded Outcomes Navigator to map to the ATT&CK framework. This allows customers to assess their environment, receiving insights into configuration strengths and recommendations for improvements. This feature also advises on optimal configurations for better defense against TTPs, pinpointing security gaps and vulnerabilities. It’s a valuable resource for organizations aligning with or benchmarking against the ATT&CK framework, offering actionable insights for a stronger cybersecurity stance.

    What’s New in Exabeam Product Development — November Release 2023
    Figure 3. MITRE ATT&CK coverage in Outcomes Navigator

    Streamlined workflows boost security operations productivity

    Analysts can now look up correlation rule names and IDs via API. With this new simplified workflow, the API will return all matching names with the corresponding IDs. This feature improves analyst productivity by allowing them to enter the partial name of a correlation rule with a return of all potential matches with corresponding rule IDs.

    With limited IT resources, security teams are being asked to do more with less. The Exabeam November release helps customers streamline security operations with new pre-built compliance dashboards:

    • Exabeam – Default Account Access Dashboard
    • Exabeam – Disabled User Account Summary Dashboard

    With just a few clicks, users can get broad dashboard visualizations that help measure the effectiveness of SOC operations while speeding compliance and reporting.

    Exabeam completes IRAP assessment at the PROTECTED level

    The Information Security Registered Assessors Program (IRAP) is a framework by the Australian Cyber Security Centre (ACSC), a division of the Australian Signals Directorate (ASD), to evaluate an organization’s security controls, ensuring alignment with Australian government security requisites. In August, Exabeam initiated the IRAP assessment process. We are excited to announce that Exabeam has completed an IRAP assessment at the PROTECTED level for the Exabeam Security Operations Platform.

    We are excited about this opportunity to expand Exabeam capabilities to organizations and government agencies in Australia. The completion of an IRAP assessment illustrates our continuous dedication to delivering and maintaining AI-driven and cloud-native security operations solutions in accordance with the most exacting security benchmarks.

    Dig into the new release in the Exabeam Community. Engage in live ExaExpert Q&A sessions every other week, or join technical discussions at your convenience. Your curiosity and questions are always welcome.

    Exabeam Community
    Jeannie Warner

    Jeannie Warner

    Director, Product Marketing | Exabeam | Jeannie Warner, CISSP, is the Director of Product Marketing at Exabeam. Jeannie is an information security professional with over twenty years in infrastructure operations/security starting her career in the trenches working in various Unix help desk and network operations centers. She started in Security Operations for IBM MSS and quickly rose through the ranks to technical product and security program manager for a variety of software companies such as Symantec, Fortinet, and Synopsis (formerly WhiteHat) Security. She served as the Global SOC Manager for Dimension Data, building out their multi-SOC “follow the sun” approach to security. Jeannie was trained in computer forensics and practices, and plays a lot of ice hockey.

    More posts by Jeannie Warner

    Learn More About Exabeam

    Learn about the Exabeam platform and expand your knowledge of information security with our collection of white papers, podcasts, webinars, and more.

    • White Paper

      Using MITRE ATT&CK® in Threat Hunting and Detection

    • Webinar

      New-Scale Security Operations Platform: October 2025 Quarterly Launch

    • Blog

      Can You Detect Intent Without Identity? Securing AI Agents in the Enterprise 

    • Blog

      Securing the Future of Work: Agent Behavior Analytics with Google Cloud

    • Brief

      Exabeam and Google Cloud: Securing AI Agents and LLM Usage With Behavioral Analytics

    • Blog

      Enabling OJK Regulatory Compliance and Cyber Resilience for Indonesia’s Banking and Financial Sector With Exabeam

    • Show More