{"id":23362,"date":"2021-03-11T16:31:20","date_gmt":"2021-03-11T08:31:20","guid":{"rendered":"https:\/\/version-2.com.sg\/?p=23362"},"modified":"2021-03-11T16:31:20","modified_gmt":"2021-03-11T08:31:20","slug":"greycortex-mendel-3-7-now-available","status":"publish","type":"post","link":"https:\/\/greycortex.hk\/zh\/2021\/03\/11\/greycortex-mendel-3-7-now-available\/","title":{"rendered":"GREYCORTEX MENDEL 3.7 NOW AVAILABLE"},"content":{"rendered":"<div data-elementor-type=\"wp-post\" data-elementor-id=\"23362\" class=\"elementor elementor-23362\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-4da8c5f9 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"4da8c5f9\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-133ba185\" data-id=\"133ba185\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-1c4c3258 elementor-widget elementor-widget-text-editor\" data-id=\"1c4c3258\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>GREYCORTEX has released the latest version of its Mendel Network Detection and Response solution. Version 3.7.0 brings important features and improvements. The main features in Mendel\u00a03.7.0 include\u00a0CISCO ISE user identity integration and response, CISCO Firepower incident response, SNMP appliance monitoring &amp; SNMP trap, or AWS, MS Azure and Google cloud deployability.<\/p><h2>ENHANCED INTEGRATION WITH YOUR INFRASTRUCTURE<\/h2><p><strong>Better visibility on user identity<\/strong><\/p><p>For use cases when Mendel\u00a0has no direct access to AD\/LDAP server or with limited permissions then user identity could be provided via integration with CISCO Identity Service Engine (ISE).<\/p><p><strong>Active response to threats<\/strong><\/p><p>For situations where it is necessary to respond to emerging threats, we will ensure appropriate steps through integration with CISCO network elements. If this is unavoidable, you can block endpoint communication, isolate part of the network, etc.<\/p><p><strong>SNMP Appliance Monitoring<\/strong><\/p><p>With incorporation of SNMP agent and trap functionality you are able to oversee MENDEL appliances with your current infrastructure monitoring solution.<\/p><h2>MORE EFFICIENT OPERATIONS\u00a0<\/h2><p><strong>New upgrade management to all your appliances<\/strong><\/p><p>Upgrade the whole Mendel deployment through a single point \u00a0= collector&#8217;s UI. Choose either \u201cOne click\u201d multi upgrade or upgrade each sensor individually. Upgrade is performed by two step method, to keep sensor running for maximum time and shorten the maintenance time.<\/p><p><strong>Mendel installation on common cloud services\u00a0<\/strong><\/p><p>Amazon Web Services, Microsoft Azure and Google Cloud are now supported for deployment of Collector or Central Event Management (CEM).<\/p><p><strong>Utilization of high-speed disks within MultiTier storage and optimized database queries<\/strong><\/p><p>Use your fast disks not only for the operation of the system itself, but also for a much faster response of the user interface when displaying the \u201ehot\u201c data and views of them. If your deployment does not have multi-tier storage with fast disks, we still bring you a faster response in the GUI by optimizing the database queries.<\/p><p><strong>False Positives for limited time period<\/strong><\/p><p>Hide events only for the time that is relevant and related to the maintenance of your infrastructure, tests, etc. Apply false positives with specific time frame and\/or recurrence.<\/p><p><strong>Conditional PCAP recording<\/strong><\/p><p>Data captures can be triggered on-demand or by specified conditions (user-defined &amp; event-based).<\/p><h2>OT\/ICS\/SCADA<\/h2><p><strong>Asset discovery\u00a0<\/strong><\/p><p>Ability to discover devices in network using various OT protocols to get asset details such as firmware versions, and many others.<\/p><p><strong>Policy monitoring<\/strong><\/p><p>We introduce a new script approach in IDS rules which allows you to define custom policy rules to monitor allowed values and perform whitelists\/blacklists operations inside OT protocols like IEC104, MMS and many others.<\/p><h2>ALL FEATURES &#8211; IT<\/h2><p>CISCO ISE user identity integration and response<br \/>CISCO Firepower incident response<br \/>SNMP appliance monitoring &amp; SNMP trap<br \/>Upgrade management over appliances<br \/>AWS, MS Azure and Google cloud deployability<br \/>High-speed disk utilization within multi-tier storage<br \/>False positives for limited time period<br \/>Trigger based PCAP recording<br \/>Processing netflow data with NAT information<br \/>Switch flow errors \u00a0from flags to real calculation<br \/>Connect Mendel sensor to secondary collector (HA)<br \/>Deactivate inactive Sensor on Collector<br \/>User Documentation available via GUI<br \/>Time validity of false positives<br \/>Connect Mendel sensor to secondary collector (HA)<br \/>Deactivate inactive Sensor on Collector\u00a0<\/p><h2>FEATURES &#8211; OT \/ ICS<\/h2><p>Asset Discovery<br \/>Parsing MQTT, COAP and Profinet protocols<br \/>Detection of LoRaWAN protocol<\/p><h2>ENHANCEMENTS<\/h2><p>Process VMware ESXi NSX-T IPFIX format<br \/>Add support for storing Suricata Variables in DB<br \/>Enhance update server update data sources<br \/>Semi-automated restoration of SMB backup<br \/>IDS signatures using the detected application<br \/>Display the logged-in user name on all pages<br \/>False positive change Priority field Default text<br \/>False positive not applicable into past by default<br \/>Import new JA3 hash codes from ja3er.com<br \/>Add description field into data exports<br \/>Hide user from managerial\/security reports and email<br \/>Added assignee, reporter and date of last updated to Incident exports (PDF)<br \/>Reworked Firewall settings with new location in UI<br \/>Better explanation over data transfer between hosts in peers graph<br \/>Evaluate and add IPv6 multicast address into monitored subnets<br \/>System logs in mshell<br \/>CAT tool for ME localization\u00a0<\/p><h2>OFFICIAL MENDEL PRODUCT SUPPORT<\/h2><p>With release of version 3.7.0 full-service support will be provided for the versions 3.7.x and 3.6.x. Limited service support is provided for previous version 3.5.x. Versions 3.4.x and older are no longer supported, end-users with valid support and maintenance or active SW subscription can upgrade to the supported version(s).<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>","protected":false},"excerpt":{"rendered":"<p>GREYCORTEX has released the latest version of its Mendel Network Detection and Response solution. Version 3.7.0 brings important features and improvements. The main features in Mendel\u00a03.7.0 include\u00a0CISCO ISE user identity integration and response, CISCO Firepower incident response, SNMP appliance monitoring &amp; SNMP trap, or AWS, MS Azure and Google cloud deployability. ENHANCED INTEGRATION WITH YOUR [&hellip;]<\/p>","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","_crdt_document":"","advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[23,20,21],"tags":[24,22],"class_list":["post-23362","post","type-post","status-publish","format-standard","hentry","category-year2021","category-greycortex","category-press-release","tag-24","tag-greycortex"],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/paZ0Rf-64O","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/posts\/23362","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/comments?post=23362"}],"version-history":[{"count":0,"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/posts\/23362\/revisions"}],"wp:attachment":[{"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/media?parent=23362"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/categories?post=23362"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/tags?post=23362"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}