September 2026
8 min
match analysis for events release date september 17, 2026 match analysis shows why an event did or did not match a given identifier, so you no longer have to guess how an event ended up in your feed or why one is missing from it match analysis is available on the advanced tab of an event's details with match analysis, you can pinpoint why an event you expected did not match, down to the exact condition that filtered it, so you can adjust your configuration accordingly confirm why an event did match, so you can understand your coverage and refine your identifiers to reduce noise, if needed learn more docid\ qr6g95n7rwiiogfy2ipc4 new emerging data source for spam emails release date september 11, 2026 spam emails is a new emerging source containing spam messages collected from a spamtrap each message includes full headers, recipient list, sender address, and content, which can help you identify campaigns that reference your organization or abuse your domain this source must be added as a category on an identifier before related events are surfaced learn more docid\ oc9qrltimxbohtzxbvskj automatic severity escalation for risky ips release date september 11, 2026 a new flare severity rule is now available when the ip address in an event's metadata matches an ip surfaced in the intelligence browser, the event is marked \<font color="#c2410c">`high`\</font> severity, flagging the host as potentially risky like all flare severity rules, it is active by default and requires no configuration existing events the rule impacts only new events coming into the platform historical events are unaffected, so existing \<font color="#c2410c">`high`\</font> severity event counts on your dashboard remain unchanged as new matching events arrive, the number of \<font color="#c2410c">`high`\</font> severity events might increase gradually over time event volume no new sources or event types are introduced, so no change in total event volume is expected threat categories for identifiers release date september 9, 2026 when creating an identifier, you can now select one or more threat categories a threat category is a predefined set of categories most relevant to a particular type of threat selecting one pre selects its recommended categories as a starting point, which you can then customize the following threat categories are available, with more to be added over time identity exposure surfaces compromised identity data such as leaked credentials and infected devices tied to your identifiers dark web monitoring tracks mentions and leaked data across dark web sources, including marketplaces, ransom leak sites, and forums domain impersonation detects lookalike domains that imitate your legitimate domains technical exposure finds exposed technical assets such as buckets and source code these selections are recommendations rather than restrictions you can select any combination of individual categories, choose multiple threat categories, or clear the selection before saving learn more docid\ bpcmrpdohzer0cc83vcdn filter the intelligence browser by ioc type release date september 4, 2026 intelligence objects can now be filtered by specific ioc types in both the intelligence browser and the entities api, making it easier to operationalize the data the observable types filter lets you pull a targeted list of a one or more ioc types, such as ip addresses or file hashes, to feed directly into your detection and blocking tools learn more docid 05uqcn5rinzdxddsrktmy intelligence objects event category release date september 1, 2026 the intelligence objects event category connects the entities surfaced in the intelligence browser to your identifiers and your tenant feed when enabled on an identifier, a match against an intelligence object surfaces an event in your feed, so exposures flagged by third party risk lists appear alongside your other events coverage intelligence objects cover indicators of compromise, malware families, named campaigns, vulnerabilities, threat actors, and adversary infrastructure event details each event includes the object type, source, provider, and relevant dates, along with severity scoring and complete raw data configuration and alerting the category can be enabled during identifier configuration and used with alert central to route matches to the right stakeholders api access intelligence object events are available through the api using the intelligence object event type on the tenant, identifier, and identifier group endpoints learn more docid\ xd3cspwpznjtcaoke5bqe