added

Write Access for Cases and Alerts

You can now update Threat Center cases and alerts using the Exabeam API. This feature allows you to modify alert properties, including name, description, priority, and tags using the alert ID. For cases, you can update the stage, closure reason, queue, and assignee. These capabilities enhance your ability to monitor, automate assignments, and streamline investigations, improving the efficiency of your security operations. For more information, see Update alert details, Update case details, and Create a new case.

added

Extended Support for Site Collector Agents

You can now create additional collector agents using the Exabeam API. Types include Fortinet, File (Windows and Linux), Archive (Windows), Kafka, Qradar, and EStreamer. For more information, see Create a Site Collector agent.

added

New Region Support for Saudi Arabia

A new API gateway is now available in the Kingdom of Saudi Arabia (KSA) region. This expansion enables seamless integration with the Exabeam Security Operations Platform for customers operating in the Middle East. For more information, see API Gateways.

added

New Endpoints to Onboard Site Collectors

You can now use the Exabeam API to configure Site Collector templates for rapid deployment of multiple Site Collector collectors (also known as agents). For more information, see Site Collector Templates and Site Collector Agents.

added

New Threat Center Endpoint

To effectively and efficiently respond to threats, you can now use the Exabeam API to search and retrieve details for alerts and cases in Threat Center. For more information, see the Threat Center endpoint.

added

New Region Support for Switzerland

The Exabeam API now supports deployments in the Switzerland region (europe-west6 in GCP).

added

New Site Collector Onboarding Support

​
You can now use the Exabeam API to programmatically set up Site Collectors without using the user interface. For more information, see Site Collectors endpoints.

added

New Use Cases Endpoint

You can now use the Exabeam API to retrieve use case information including description, scenarios, and category. For more information, see the Get a list of all use cases endpoint.

added

​New Delete Context Table Endpoint​​

​
​A new endpoint is available for the Context Management service that allows for the deletion of specific context tables. A table ID is required to specify the table for deletion along with All table records are deleted. Optionally, unused custom attributes can also be deleted. The new API endpoint is: ​DELETE /context-management/v1/tables/{id}​​
​
To try the new API, see Delete a specific context table.

added

New Endpoint to Retrieve MITRE Information

You can now use the Exabeam API to retrieve MITRE ATT&CK® tactics and techniques. This can be useful to help automate security operations related to MITRE information in security content (for example in correlation rules, behavioral rules, dashboards, alerts, and cases).