Salem Cyber Doc Site
  • 🏠Documentation Home
  • ✨Initiation Guides
    • Quickstart: Deploy Salem
    • Admin Guide
    • Installing Teams App
    • Installing Browser Extension
    • Feature Overview
  • ✨General Guides
    • Managing Alerts
    • Managing Questions
    • Threat Notification Management
    • Uploading Files
    • Logical Operations
  • ✨Configurations Specification
    • Configuration Home
    • Action Conf
      • "match" ActionConfs
      • "webhook" ActionConfs
      • "llm" ActionConfs
    • Action Definition
      • Azure Log Analytics
      • Microsoft Graph API
      • Splunk Search
      • Bring Your Own LLM
    • Parsing Conf
      • Summary Details
    • Report Conf
    • LLM Configuration
  • 💾Changelog
    • Dec 5th '24: Get cracking on your holiday shopping list
    • July 18th, ’24: Beat the heat and the hackers
    • Apr 17th, '24: Alert showers make analysts sour... no longer with Salem!
    • Mar 5, '24: They're after me (and your) secure systems! We're na-tur-ally suspicious
    • Jan 31, '24: New year, new me... and a new way to extract data from your alerts
    • Dec 21, '23: Jingle bells, WannaCry smells, your escalated alert just laid an egg
    • Nov 14, '23: Stuff the turkey or stuff cyber alerts with context... Why not both?
    • Oct 25, '23: Llama, llama on the wall which alert is scariest of them all
    • Sept 19, '23: Context building via true positive/false positive workflow
    • Sept 1, '23: Alert report UI, webhook actions, and question upgrades
Powered by GitBook
On this page
  • ✨ New
  • True positive/false positive Context Building
  • ➕ Improved
  • 🔧 Fixed
  • In the Works
  1. Changelog

Sept 19, '23: Context building via true positive/false positive workflow

Salem v.1.4.5

PreviousOct 25, '23: Llama, llama on the wall which alert is scariest of them allNextSept 1, '23: Alert report UI, webhook actions, and question upgrades

Last updated 1 year ago

We've been hard at work improving Salem's context building through the true positive/false positive workflow, integrating Salem's webhook actions with external systems, and laying the foundation for future LLM features.

✨ New

True positive/false positive Context Building

Users can now generate context by selecting True Positive or False Positive on an alert's report card. After classifying an alert and selecting a key field for why the selection was made, if a user selects a single context label, they will be prompted to provide more information about how they knew that was the case and how Salem can learn to do the same in the future.

The user can teach Salem how to create context labels on alert details by providing a logical operation, identifying a data system where that information exists, or simply telling Salem to remember the association for the future.

➕ Improved

  • Removed the "do you have time for a question" workflow

  • Hardened authentication to improve Salem's security from man-in-the-middle attacks

🔧 Fixed

  • Fixed the webhook action workflow - see more details in the page on using this workflow

  • Fixed Microsoft Graph API webhook action to include optional parameters

  • Fixed interpretation of alert fields with spaces so they are matched correctly for alias identifiers

  • Fixed passing too many context labels to the model, delaying predictions

In the Works

Developing architecture to integrate BYOL (bring your own llama ) functionality for customers

💾
🦙
⚙️
ActionDefinition