Video: Exabeam Quarterly Launch Update: New Features and Innovations | Duration: 2814s | Summary: Exabeam Quarterly Launch Update: New Features and Innovations | Chapters: Welcome and Introduction (19.935s), New Chapter (26.435001s), New Chapter (33.879997s), NuScale Analytics Upgrade (163.715s), Exabeam Product Updates (329.935s), Upgrading Analytics Platforms (1288.79s), Advanced Automation Updates (1386.99s), Google Partnership Highlights (1561.07s), AI Agent Security (1694.78s), Partnership Announcements (2122.4849s), Concluding Product Updates (2234.575s)
Transcript for "Exabeam Quarterly Launch Update: New Features and Innovations": Alright. I think we are live. Good morning, everybody. Good afternoon. Good evening, depending on where you're joining us from. Welcome to our quarterly launch update. We've got a lot of great stuff to share with you today. So let's go ahead and dive right in. My name is Kevin Binder. I'm on the product marketing team here at Exabeam. Joining me is Matt Willems, Matt's senior director of product management. We'll be tag teaming this call together. So when one of us is talking, the other will be working the chat window. So please feel free to ask your questions. If there's something we can't answer, either, because we don't have time or maybe something that requires a confirmation, we will follow-up with you after the call. So, please, you know, don't be shy. Alright. So in terms of the agenda, we're gonna start things off talking about, the new scale analytics, upgrade program, give you some updates on that. Then we're gonna talk a little bit about market conditions and some opportunities for Exabeam. This is basically about where we think our customers might need the most help and where where we're investing, in developing the product. And then you'll see how some of those decisions are are paying off. Matt in, section three is gonna go over some of the MVP, most valuable features for the launch. We picked out a few that we think are gonna add the most value to you. And, you know, if you've been following Exabeam in the press, you know that we've, had a few announcements lately at some new partnerships. If you did miss those, that's okay. We're gonna, quickly review those partnerships, show you a neat demonstration on one of those. We'll then talk about the best of the rest features. We had over 40 features in this release. There were a lot. So we'll highlight a few others that we think, might be of interest to you, and then we'll finish things off with probably the most exciting part, which will be the demonstration. We'll show you all the new features or the top features in action. So, Matt, I'm gonna hand this slide up to you. Awesome. Thanks, Kevin. And thanks everybody for your time today. We know everybody's got busy schedules, so, you know, really appreciate spending an hour with us to learn learn more about updates in the platform. So one of the big updates we rolled out at the beginning of the year is the new scale analytics platform. This is kind of the the wholesale new version of advanced analytics, for those of you who are are using that either as part of Exabeam, Exabeam Fusion or, potentially augmenting a a third party SIM. This is essentially the new version of advanced analytics. Some really, really huge advancements in here that we wanna make sure you're aware of so you can start taking advantage of them. These are things like, rather than needing a rule for every single scenario, or or very specific behaviors, Now we can use a a smaller set of rules and and look for combinations of things, which dramatically simplifies the user workflow, dramatically increases the the high end of the scale and performance. It says 250,000 plus events per second because we've never actually been able to max it out. And and we try to make the upgrade to, New Scale analytics as easy and as seamless as possible, doing things like helping to helping to migrate content. So if you have custom rules, our team can help migrate those over for you. We've ensured a zero downtime upgrade by actually running the New Scale analytics engine in the background so it can perform training while you're still working in case manager with advanced analytics rules. And then, you know, when things are ready, the training's complete, your team's ready, we can cut the workflow over to NSA. Just a a huge number of benefits in here and, try to make it as as easy and seamless as possible. So for anybody who hasn't done that upgrade yet, you know, we're scheduling those upgrades. Your account team should be reaching out to help get that scheduled. If what you see in here is exciting, feel free to reach out to your account team, or you may have seen a notice in the application that this is something that you can sign up for. You can always go back into the, the resource center and open that guide and fill in your email and, get that process started. So this is some of what we're gonna be showing, throughout the the rest of the webinar. Some of these features will apply specifically to NSA. Some of it is more platform wide. So, yeah, a lot of exciting, work going on that we're we're excited to share with you. Yeah. And it's, you know, it's a partnership. It's a team effort too. So I know sometimes these things can feel a little bit intimidating, but we will be working with you, on this stuff every step of the way. We've had a lot of really success doing this so far. I think we're six months into doing this, so we've developed a pretty good system, to make this happen and and ensure success. Okay. So now for the next section, you know, how can Exabeam help? We're gonna look at some of the market conditions, before we look at the new features. We wanted to start with some basic context around where we at Exabeam are focused in terms of areas of product development and what we think are really important and are gonna have the biggest impact, for you, our customers. And, you know, let's start with the something that almost feels like sci fi. Right? These AI agents as the new insider threat. And, you know, we used to think the biggest insider threats were disgruntled employees, compromised credentials, maybe bad behavior, and, on behalf of employees in terms of, their safety with, how they access applications and and things. So now we've got these AI agents. These are essentially autonomous software employees, and, you know, they're carrying full user identities. They're executing workflows. They're making decision. And even in some of the own research we saw, you know, agents like Devon, you know, operating under developer credentials, accessing internal systems. So, you know, it's you know, what's scary is that, you know, most companies don't know which AI agents have access to critical systems. There is a recent survey that were 85% of organizations claimed, yes, we are AI ready, but fewer than half of those actually monitor the behavior of those agents. So, you know, you're just you're not fighting against those human insiders anymore. You're defending it against a whole new class of, non human identity. So, you know, that shift really demands a rethink of how we govern identity, how we monitor behavior, and most importantly, so how we flag those anomalous actions, in real time. Little bit of a validation here from Axios. Without proper guardrails, agents could, at the very least, cause incidental data breaches, misuse login credentials, and leak sensitive information. So, you know, how do we how do we best solve for that? And, you know, this is where Exabeam really shines, turning scattered events into cohesive insider timelines. And we build these timelines automatically, by the way, using AI. So, you know, when it comes to insider risk, whether it's a human or an agent, the question isn't always, you know, if something abnormal will happen. It's whether or not you're gonna see it in time. And, you know, most sims look at events in a very isolated way, right, a very small window of correlation where they're looking for things. And they might flag a login or they might flag a policy violation. And then in a lot of cases, they're gonna move on. And, you know, Exabeam takes a completely different approach to that. We've been doing it for a long time, with new scale analytics. It's our UEBA foundation, and we learn what normal looks like for every user, device, and now for every agent. And we don't just look at the single events. Right? We stitch together weeks or months of activity together, and we call those sessions. And one way to think of it is these are essentially living timelines of behavior. Late arriving events, we're gonna add it to to that time line, just sort of like you see the puzzle pieces here coming in in real time and adding to the puzzle. And you need this because this is where insider risk actually reveals itself. Right? It's the small anomalies that add up to something big. And as new evidence emerges, you need those risk scores to adjust automatically, and you need to see the full the full story line. So, you know, this whole continuous learning is is what makes Exabeam uniquely suited for this this new wave of of insider threats. And, you know, obviously, a top need is is the ability to secure and monitor AI agents. We'll talk more about that later. We're even gonna show you a demo. But let's shift gears a little bit to another topic that's top of mind. It's how can leaders better communicate with the board. And, you know, security leaders aren't just defending against bad guys anymore. They're defending their budgets. They're defending their reputations, and the board now expect the c, the CISOs to show, in plain English how secure the company really is. They want measurable outcomes. What does my coverage look like across key use cases? How do I compare? And, you know, they want proof that every dollar actually lowers risk. And, you know, the problem is that most SOCs don't have defensible metrics. They've got dashboards that are full of events, but they don't really have the good evidence that translates into business language. And, you know, that's where Exabeam, we've been shifting the game, helping security teams move from those basic alert counts, mean time to this, mean time to that. But really focus more on those outcomes. What's covered? What's exposed? And what new investments are gonna have the biggest impact. And hopefully, a lot of you are already familiar with and using, Outcomes Navigator. And so, you know, we we know we need to communicate better with the board, and, we're gonna show you a demonstration later of Outcomes Navigator so you'll be able to actually see this in action. But, you know, beyond helping the security leaders with these boardroom discussions, Outcomes Navigator, which is powered by our advisor agent, is really helping our customer shift from something that we're seeing in the industry, which is, you know, being reactive, waiting for the alerts, investigating those alerts, and then sort of cleaning up the mess to being more preventative and more proactive in our security. So Outcomes Navigator is helping sort of to flip that premise, and it's really about giving security leaders a real time map of their coverage so they can, you know, essentially prevent problems before they start. So, this is a big area of investment for us. We're keeping our pedal to the metal here, and, Matt's gonna show you some, some neat additions that we've made to Outcomes Navigator. I wanna finish this up with a a customer quote. Because we're in cybersecurity, we can't always use the names, but I really, really love the quote. Exabeam gives us instant clarity on what's happening across our environment, helping us prioritize where to focus and what to improve. The visibility is essential, not just for daily operations, but for reporting to leadership and advancing our broader risk management goals. So, really like the quote. It sort of validates what I've been telling you the last few minutes. And now we're gonna learn what we delivered in October and how that sort of relates back to all those items I was just talking about. So, Matt, are you ready to take control? Yeah. Absolutely. Alright. Kevin. Yeah. So we've been, like I said, doing a huge amount of work across, product management, product marketing, engineering, field teams. You know, this is this is a huge team effort to build all this functionality and and get it launched. So let's take a quick look at, kind of in slide form, at at some of the key features, and then I'll come back and and demo some of that a little bit later on. So, really to kick things off, it was just what Kevin was talking about. So adding an industry comparison to Outcomes Navigator. You know, really the goal here is expand the visibility of kinda comparing the the security coverage, the security posture. You you've always been able or for quite some time, you've been able in Outcomes Navigator to kinda compare you to yourself over time. This really adds the ability to compare you to others, to to, you know, industry peers, organizations of a similar size, things like that, that, you know, you can see in the screenshot there, and we'll come back and demo in a little bit. So I can I can pick from a list, Hey? Here are the industries that are that I participate in. There might be multiple. You know, you might be in in, if you manufacture aircraft components, maybe you wanna show manufacturing and, the air industry, things like that. So we tried to make it pretty configurable, and then it'll show you the nice graph there with, you know, how how that score has trended over time, and I'll get into some of the other kind of smaller enhancements around that. But, really, the goal here was make it crystal clear, not just how I've progressed over time, but how my organization stacks up, against my industry or against my, you know, relative size. That way you can help prioritize. You can look at things like, oh, you know what? I'm really weak in this use case compared to my industry. If this is an area where the industry is being targeted, maybe that's somewhere that that I need to go shore up my coverage. So that that's still the idea of outcomes navigator is, helping organizations prioritize where to increase coverage. Alright. Moving right along, we're gonna look at, there there are kind of a couple of big enhancements around, new scale analytics and the the rule authoring workflow. But one of the really key enhancements is adding customizable risk ratings. So in the past, this was kind of a fixed value. Now users can actually go in and and tweak the, the severity rating on each rule to allow for things like, hey. I know this is a problem anytime it shows up in my environment. You know, some something that's just always bad regardless of the context, I need to know about it. So now you can go in and set that to something like, like, critical so that you could, automatically create a case or effectively automatically create a case anytime that detection is made. And interestingly, you can go all the way the other directions. You you can turn it down and and have the detection, weighted less against the eventual case score, the the risk score. But you can also set it to none, which allows for things like, I don't want this to automatically create a case kinda regardless of how many times it fires, but it's important context to a user who might be investigating that case. So the detection can still fire, would still create an event, but then when you go, you know, it's not creating cases on its own, but it would still get attached to a case if there's a correlated activity. So really handy feature there, to be able to to kind of, adjust that score. We are always looking for ways to stay in closer contact with customers. We know that you being able to get a hold of us, know who your account team is, get information from your account team, things like that. Like, that's critical to the success of, of Exabeam customers. So we're trying to make that easier by rolling out this success center. This is something that's kind of in a phased rollout right now, so you'll probably see it show up in the near future. Though if you, find it interesting, please reach out to me, and I will see if I can get it enabled for you. The this essentially allows, just like I was saying, that you have quick access to, not just key resources like the community site, documentation, training and enablement portal, support portal, things like that, but also your account teams. You can quickly schedule time with somebody on your account team if you need to. Your team and your, account team can kinda shared, put together an an onboarding plan or a success plan. You know, here are my objectives for the 2026, and then you have a shared list that you can go through and check things off. There's, you know, q and a information in there. We can push, announcements through there for things like this webinar that you're on. You may see that show up in there in the future. It's a really nice way to, stay in closer contact with Exabeam. So one that I'm I'm really looking forward to. Furthermore, we know that, you know, really the fuel that runs the engine of Exabeam New Scale is the data that we collect. So we've gotta keep, on top of making sure that that the data sources that are present in your environment that are top of mind for our customers, you can quickly and easily get onboarded and it's all, you know, seamless and and handled accurately. So we've got a a couple of key updates here. On the brand new collection side, kind of far on the right there, you see things like Qualys and Databond. If you're not familiar with Databond, it's kind of a a data pipeline tool. So there there's a huge capability there, as well as, migrating the SaaS cloud connectors over to the the current modern cloud collector strategy. So these are collectors that we've had in the product under the old, cloud connector strategy, and and now they've been updated to be, the the proper modern solution. Dramatically simplifies the onboarding workflow, keeps the management all in one place, has the proper monitoring tools. So really, really nice workflow here. So, yeah, some some huge updates on that side. Another one that I'm really excited about is, the ability to convert Sigma rules over to, New Scale. This works in a couple different ways, but, you know, really the key here is, you know, there there's detection logic out in the community for things like emerging threats, new vulnerabilities, things like that that you you just wanna be able to take advantage of really quickly. Uncoder, if you're not familiar with it, is a tool specifically for converting back and forth between vendor formats and some of these, kind of vendor agnostic formats like Sigma and Ruta. And so we've added New Scale support there. Encoder, Soc Prime is the is the company behind it. They're still working on getting this deployed into their, kinda live instance, But you can actually, pull it directly off GitHub and and run it in Docker if you wanna run it locally. Something that's cool in here is, you can convert encoder IOCs so they can convert these directly into, Exabeam New Scale EQL queries for doing historical IOC searches. But it can also build New Scale correlation rules and analytics rules for future detection logic. So there's a lot going on in there. And I'll also say watch this space. There's there's a lot of work going on in here around working with, the these various formats, in this type of tooling, because we know that, you know, if if you're migrating from another technology, maybe you're using, Exabeam Fusion today and or sorry. Maybe you're you you're augmenting a third party SIM today, and in the future, you wanna actually adopt the Exabeam SIEM and and build that New Scale Fusion platform. Well, if you're using a third party SIM today or something else that's doing detection logic, we we have tools like this available that can help convert existing detection logic in a current technology over to the the new scale detection logic. So, yeah. So a a fantastic update here. Watch this space. There's there's more and more going on. Really excited about it. So there was actually a question in chat that I answered that hits right on this topic. So, I won't really read the slide. Long story short is we know that as advanced analytics customers are moving over to new scale analytics, we have to make that an absolutely seamless workflow. So we've taken on the burden of building out the technologies and processes for converting multiple types of content from advanced analytics over to new scale. I don't need to get into the weeds on how those things work. But, you know, be it to say, we we've really taken care of that for you, and we can apply that technology, when customers are are upgrading. We also have some customers who, you know, maybe they're fusion customers, and they wanna go to New Scale fusion, and they've never really fully onboarded advanced analytics and and, you know, detection logic there. We actually have the ability then to say, okay. Well, we're not worried about a a migration or an upgrade. We just wanna pull the plug on AA and jump straight into NSA and ThreatCentre because that's where all the the, you know, the new goodness is that that we've been talking about. So, multiple options there. Like I said before, something to talk to your account team about because we've got a lot of options in this, in this this upgrade workflow. So like I said, make it as seamless, make it fit, what what works in your organization the best. So, lots of good options there. We also have, the, advanced automation platform. Is this kind of the replacement for incident responder if you were using that in advanced analytics. If you weren't using it in advanced analytics, advanced automation is the the SOAR component that can be added on to, the the New Scale platform. It's a full no code, low code SOAR platform, you know, out of the box integration library, all the things that you would expect. But, you know, we know that that just like cloud collectors being able to pull data from third party sources is what really drives the the SIM and the the analytics detection logic. Well, similarly, having that integration library out of the box is what drives the, the automation platform. So we're constantly working on building out that integration library, and you see some of the the key highlights here, things like CrowdStrike and SentinelOne for endpoint, some kind of communication tools and things like PagerDuty and Jira, doing issue tracking in Jira, as well as, some account management tools like Active Directory and IntraID. So, really just a way to get get onboarded really that much faster in advanced automation. So some great updates there. Now changing gears just a little bit, we actually have some updates on the LogRhythm platform as well. We know that's not the target for this webinar. We we've got a a dedicated session for the Logarithm platform. But just as kind of a teaser there, we actually have some shared customers who use both platforms for for different environments or things like that. So we've done some things on, kind of the way clustering works on the data side to make sure that that we've got, you know, data available and reliable. There's actually a new metric widget, for for dashboards to be able to to do things like counts of events and just display a simple count. It's a great one. But I was actually, I was the product manager for the the web console on the Logger Than product for some time, and that's one that I always wanted to get in there. So kudos to that team for for getting it finished. The unified threat center, so those of you who are familiar with the logarithm platform, there's kind of an alarms tab and a case management tab. This kind of brings that into a tighter workflow. There's a lot more work going on there to to join things even more closely. But, yeah, some huge updates on, kind of the the case management workflow, through this this new threat center. Better collection capabilities around the Office three sixty five, to to really simplify the onboarding workflow, making sure that the collector is working properly. And we're always doing work on the back end to make sure that's a a secure, reliable platform. So, there's gonna be a a number of updates on the security side with things like certificate updates. So huge amount of work there. Alright. I think with that, I get to hand things back over to Kevin, if I recall correctly. And, Kevin, I will let you take over for a bit, and I will see you all again in just a little bit for a demo on the New Scale side. Alright. Thank you, Matt. Exciting stuff for sure. So yeah. Now that everyone's seen some of the new features, we wanted to take a couple minutes to share some of the new partnership announcements that have taken place since the last time we got together. So let's start with, this one, which is really exciting, the Google partnership. We've been partners with Google for a very long time. If you're a customer, you know that, you know, our deployment, our Exabeam infrastructure runs on Google Cloud. So we've got a great relationship, and we're able to really complement each other in a number of different ways, and this is just a fantastic example. You know, securing AI agents, this is the stuff that we talked about earlier. We know that AI agents are acting like insiders. We need to treat them like insiders. You know, they're logging in, they're accessing data, executing tasks. But if you can't see what they're doing, you're you're essentially blind. Right? And that's why our partnership with Google is so powerful. Exabeam, our new scale platform, we can now ingest telemetry from Google agent space and ModelArmor. So you get real time visibility into these agent driven workflows that you've deployed. And you can see here in the screenshots, you know, logs from agent space, logs from model ModelArmor are literally informing our AI driven detections and our TDIR workflows. So, you know, Exabeam, we've all we've already had the behavioral analytics capabilities. We're the leader in this space. And now we can baseline the same way we do with humans. We can baseline nonhuman behavior in the exact same way. So, you know, new scale analytics essentially becomes your brain for monitoring agent activity. And, you know, this is really gonna help you stay ahead of what what we see as this next wave of insider, threats. Alright. We have got a new webinar system. I'm gonna attempt to play a video here. Everyone cross your fingers for me. Hi, everyone. This is Warby, and I'm here today to talk about a new integration that we announced on Tuesday, September 9. I'm going to introduce the use case with a few slides and then show you a demo. So we're all seeing lots of examples and news of not only the adversaries using AI to attack and try to get access to data, but it's enabling them to create attacks much faster, and it's making them far more efficient. We need a way to respond faster to keep up. AI agents really are a new insider threat. Just like people, they have autonomy, they have access to lots of information, and that poses a risk. They are given the ability to execute tasks, and there's a potential for an adversary to abuse that autonomy and that access to reveal sensitive information. We need to be able to monitor what those agents are doing, make sure they're not being abused, and if they are, we need to react quickly. Okay. So this is gonna be a demo showing how we can take logs from agent space in Model Armor and bring them into the Exabeam platform and use that to create alerts and ultimately cases based on how users are using an agent. So this is agent space from Google. We set up a simple agent using model armor for guardrail protection, and it's just simply a chat bot that runs in front of Gemini. And so I'm gonna go into this chat experience. I'm gonna ask it a couple questions. Initially, I'm gonna ask it, you know, something simple. What's the weather gonna be like next week where I live in San Jose? And it gives me an answer like you would expect. Now I'm gonna put in something that it shouldn't answer and Model Armor correctly refuses to answer that. Now the great thing is that this generated some information on the back end that we can then inject and ingest into the SOC platform. So this is our landing page for the Exabeam security operations platform. Down the left hand column, you can see all of the ways that we can collect different log sources, including what we did for this demo. The second column is where the security engineering workflows are contained in all those applications. For this demo, I'm gonna use Threat Center, and I'm gonna show specifically some alerts related to how agent space was being used. So I'm gonna pull up in this demo environment some logs from a few days ago, and I'm gonna show, one particular user who's generating a lot of alerts. And we can see holistically all the activity that this user has been doing. This user is b hanna. And in addition to some other bad behavior that we're seeing, we can also see logs related to how b hanna was trying to use the AI agent. So down below where it says rules triggered, I can see lots of different rules were triggered including specifically the data exfiltration attempt via AI agent. So these are alerts that came from ModelArmor that ultimately drove the score that was used to calculate the risk. The original score based on just rarity was a 48. Based on some criticality of some of the entities, that got automatically adjusted, but an extra 31 points to 79. That adjustment is automatically learned based on the context that is imported from the customer's environment. No tuning is needed for that to happen. So we have this summary on the left hand side that helps speed up the triage. We also have this chat experience. So I'm gonna ask you the question here. What was BeHanna trying to use the agent for? And this is powered by Gemini, and it comes back with an answer saying it's the explicit data explicit data exfiltration attempts. So now I wanna know where did those logs come from. And so I asked the question, and it's gonna come back and tell me that those were learned from a product called ModelArmor. The vendor is Google. So it very clearly understands all the aspects of the case, including how it learned this information. Now one of the nice things about our platform is we have this great timeline view, which is a really good visual experience for understanding the sequence of events that a user or entity was involved with. So I'm gonna pivot over to all the activity that BeeHanna do did. And if I scroll down, I can see the detections, related to these, data exfiltration attempts in this time line view and see the order that things happen without having to pour through many, many different raw logs. And I might wonder as an analyst, was anyone else doing this kind of behavior? So I'm gonna pull up all the logs in this time frame coming from agent space, and I'm going to see all of the raw logs that we consumed. And I can go click on one of these and look at the event details and look at the other fields that aren't displayed by default, including the query that they actually ran. So I can add that to the output. So now in the summary view, I can see each, log with the actual query was, including my weather question and some other activity. Now that I have all the logs from this collector shown, I can do a quick view and a summary view and see how many users were generating these logs. And in this case, I can see it's just be Hannah. So as an analyst, I know kind of the scope of what I need to do in my investigation when I'm checking to see how this agent might have been used as an insider threat. So I hope you found the demo helpful, and I really wanna emphasize that when we think about insider threats, it's no longer just people who have access to sensitive data and are trying to be tricked by attackers to reveal that. It's also agents that have access to sensitive data, and they're trying to be tricked. So you need a strategy for both. We're hoping this demo showed how Exabeam can learn information about not only how users and devices are normally behaving and showing when there are deviations that need to be investigated, but we can also learn about agent behavior and also create alerts about those and help your SOC not only find detections quickly using AI, but respond to those with AI. We're using AI to help secure AI. Thank you for your time, and have a wonderful day. Alright. I think I'm back. Awesome video. Very timely in terms of the content and, you know, just another awesome proof point of, you know, Exabeam has been doing UEBA and looking at behavioral, analytics for a long time. And so, you know, we're really in good shape to, support our customers with this, you know, next wave of insider threat. Got one more, slide here. Another a couple other partnership announcements. If you've been reading our press releases and blogs, you may have seen this. In addition to Google, we've also recently made some announcements around data pipeline management, both with Cribl and DataBond. So these, you know, these are two vendors, and they're solving some real life challenges in security operations. Right? We know the volume of logs, is growing exponentially year over year, and so are the ingestion costs of bringing all those logs in. And, you know, the more data you pull in, obviously, the more expensive it's gonna get. And, you know, essentially, these two partnerships are gonna allow our customers to, you know, route only that high fidelity, high value data into the exhibiting platforms. You know, allowing them to archiving what they don't need, putting stuff in in frozen storage that they don't need, and really lowering those ingestion costs without losing any visibility or paying a penalty in that sense. So, this is gonna really help maximize the return on your Exabeam investment. Alright. Matt, I'm gonna hand things back to you. Cool. Yeah. Thanks, Kevin. So we we've seen but a snippet of, all all the work that's gone on, everything that's been released in New Scale. Just to reiterate, you know, we do these webinars quarterly. You see a press release come out quarterly. We actually update New Scale much more often than that. You'll see new functionality come out monthly. We can we we push fixes for things even more frequent than that. So this is kind of a a snippet of, this October release and some of the other things that we just didn't have time to really highlight and go through. There's some some favorites in here because I worked on them. These would be things like, global email notifications, which might sound simple, but was a kind of long standing feature request. We're always doing a huge amount of work on, public APIs, taking APIs that we use internally and making them available publicly for, you know, deeper integration with third party tools, ticketing systems, SOAR tools, data visualization tools, internal applications if you need to do that. Huge amounts of work. We're always refining the workflow. Our our UX team, user experience team works so hard designing, you know, analyst first workflow. We know, you know, they're the ones that actually have to to use this to be successful in their day job. So we we do a lot of interviews with analysts to understand where the sharp edges are, where we can make things faster and easier, take clicks out of the workflow, make things more intuitive. So that's why you see some of the items in here, around, like, search enhancements and and adding entity insights and things like that. Yeah, just a huge amount of work going on in, so many areas. Would take far too long to to go through all of this. Actually, one one other, item that I'll highlight in here is, on the response sides in the upper right hand corner of the slide. And that's things like having the advanced automation platform be able to execute on premise actions. So, obviously, New Scale and advanced automation or SaaS applications living in the cloud. So now we have, essentially, like a a proxy agent available to, to run actions behind a firewall. So if you need to interact with that firewall or hosts that are on the network, you're not gonna expose them to the Internet. This is kind of a a task runner for, for handling that workflow. So some great updates there. And, let's see. I think, if I remember correctly, the next piece that we need to go to is actually the demo. So this is the first time I've done this in this platform. We're gonna learn things together. So we'll take down the screen share or the, slides, and I will go ahead and share my screen. And, hopefully, everything works as expected. So while this pulls up, just wanna reiterate, you know, really appreciate the time that you guys are spending with us today. We're getting some great questions coming in. If you have questions on what you've seen so far or anything that I'm about to demo or any of the closing information, please feel free to throw those in the the q and a box. We may or may not get to everything because we got so many coming in, but we'll certainly be able to follow-up with with q and a as we need to. So where we wanted to start, in the demo is on the, industry benchmarking capability. So I'll just come in here to, Outcomes Navigator. Those of you that are already customers and and kind of familiar with outcomes navigator, we updated this view some time ago to actually show the numeric score and and the trend chart here. So I can I can see again, where where my coverage has been over time, with some different different time ranges available if I wanna do some long term trending and things like that? And where this is really update is now I have this configurable peer comparison. So I can pick a a size, that I wanna compare against and an industry that that I participate in or I wanna benchmark against. And then those data points are shown, on the graph here as these trend charts. This actually created another interesting little feature in and of itself that, had been kind of a long standing feature request that we just happened to slot in here, which is now I can show, this tool tip with the current score and the change from from the previous time period, essentially. So, you know, now I get this, like, week to date or month to date box on the end here, showing my current score so that I can see already in October, you know, things are are trending upward from where they were in September, and then I can hover over it to get the the exact change. Couple other things to highlight in here. This does work for MITRE ATT and CK as well, so I get the same kind of, benchmark score in here. And it actually works for, MITRE techniques and use cases as well. So maybe I wanna look at something in here that I'm kinda weak in and see how I compare to my industry. Well, now you can see that, you know, even though this is one of my lower rated, use cases as far as coverage, I'm actually doing better than the rest of the education industry. So some important context in there as as well as you're, as you're going through this, this feature. So I think that's the majority of what we wanted to show on the industry benchmarking. The other one that I that I wanted to highlight that we talked about a little bit at the beginning. So now we're inside of threat detection management, and we can see, the, analytics rules that are are running on this system. Potentially, there's some activity in here, that I I know is important in my organization, maybe something that we've fallen victim to in the past, or I just know, hey, that this should always be bad activity. There there's really no legitimate use case for something that that I might see in this list. So now I have this easy option here to adjust the severity. It's currently marked as high. If I needed to make it critical so that effectively a case is always going to, to be created when this activity is observed, I can set it to critical. Or like I said, kinda during the the slide portion, I could set it all the way down here to none. And and I I talked through it before the way the way that I did for a specific reason. This is the difference between setting it to none and just disabling that rule. Disabling that rule means I'm not going to look for, this activity at all. Right? It is just irrelevant to my environment. The engine doesn't need to spend the cycles on it. Don't worry about it. I can I can, shut off that rule? Or I can set it to, none on the severity rating, which means we're still gonna look for that activity. We may have lost Matt. Hopefully, everyone can see me. Can you hear me? Pauline or Eileen, can you confirm? You can see me and hear me. Matt's back. Yeah. There we go. There you go. I think I think my connection dropped for a little bit, but we were right at the end of the demo anyway. So okay. So yeah. So that was the end of the demo. Perfect timing on that. Let's bring the slides back up here. We're, we're looking at the, the q and a window, and I think we're up to date on all of the questions. So, if we didn't get to one of your questions, we will follow-up. Does someone, was there a question? You know, I I will I will shout one out from here. I see a question in there around, a data validation tool in the UI for things like parsers and content. I might need some more information on on that one, in order to answer it. So, you know, feel free to either either clarify it in, in chat or reach out to your account team, and they can get in touch with me if they need to. To be honest, a big part of the way that I would answer that without more information is outcomes navigator, the application that we were looking at just a minute ago. The idea of outcomes navigator is it's looking at data that's incoming into the platform being ingested and fields that are being parsed out of, out of that log data and comparing that to the fields that are required for detection logic and dashboards and things like that so that you can say, okay. Well, I have these rules turned on, but I don't actually have the data sources necessary to populate that detection logic and ever have it fire. So that that's the main validation tool that I would probably highlight. And and, you know, there's lots of things around Cribl and DataBond and things like that, the the kind of data brokerage services, the data pipeline services that can live upstream. So there there's a lot going on there. It's probably more than we can can talk through, in a quick webinar, but, happy to to continue that conversation if there's more, more questions around that. Yeah. No. Great point, Matt. And, yeah. I should have mentioned a special shout out to our VP of product man Alright. We we may have lost Kevin there. We're having some, some technical challenges, apparently. Hopefully, you all can still see and hear me. I think I think, Kevin was starting to give a shout out to, to VP of product, Warby, for the the demo that he provided on