New and Changed Information

New and changed information in release 5.4.x

This table summarizes the feature updates and enhancements available in Cyber Vision release 5.4.x.

Table 1. Feature updates

Feature

Description

Restrict users to a specific Preset category

Enables precise data access control by assigning preset categories to Cyber Vision user roles, limiting users to the Explore menu with read-only permissions. See Create a user role.

Note

 

Once you restrict a user to a specific preset category, they will not have access to the New UI.

Group by network functionality in communications

The communication map displays all communications between network groups and simplifies network interaction analysis. See Communication map features.

Communication maps and their filter enhancements

Easily spot communications between assets, including those outside your active view. Communication maps highlight assets outside your active view filter with dotted lines. See Communication map features.

Network-based organization hierarchy alert configuration

Configure alerts at the organization hierarchy level with the new Organization Hierarchy (Networks) entity type. Existing alert rules with Organization Hierarchy are updated to Organization Hierarchy (Sensors) automatically. See Create alert rules.

MITRE mapping and additional details

View MITRE ATT&CK Tactic and Technique Mapping within vulnerability views for easier investigation and respond to security vulnerabilities of Cyber Vision assets. See Vulnerabilities details

Consistent Groups and Subgroups on the Zones and Conduits Map

Visualize network communications and device boundaries with support for one level of sub-zones in zones and conduits. Identify devices that should not communicate outside their networks. See Communication display options in map preset view.

Mute or unmute alert instances for prohibited vendor alert type

Use the mute and unmute feature to control prohibited vendor alerts. Mark alert instances as reviewed and not urgent, so they remain in the system but are not active. Select the duration to mute an alert instance; after that period, the alert becomes active again. See Mute prohibited vendor alert instances.

PCAP capture on the Cyber Vision Center interface

Capture PCAP data directly from the Cyber Vision Center interface in addition to sensor-based capture. See Generate a PCAP file.

External communications visibility

View all communications between a selected asset and external entities to identify unexpected activity that may expose your organization to attacks. See External communications in the New UI.

Sensor collected data quality report

Monitor sensor statistics quality in real time on the Status Overview page. Stay informed and ensure data reliability. See Sensor status overview.

Send GPS data to Center for sensor geolocation

Sensors can now report GPS coordinates (latitude/longitude) to the Cyber Vision Center for accurate mapping and visualization of the physical location of the platform hosting the Cyber Vision sensor application. See Sensor geolocation data.