{"id":2510,"date":"2020-06-02T13:11:51","date_gmt":"2020-06-02T05:11:51","guid":{"rendered":"https:\/\/greycortex.hk\/?p=2510"},"modified":"2020-06-08T13:19:24","modified_gmt":"2020-06-08T05:19:24","slug":"mendel-3-6-now-available","status":"publish","type":"post","link":"https:\/\/greycortex.hk\/zh\/2020\/06\/02\/mendel-3-6-now-available\/","title":{"rendered":"MENDEL 3.6 NOW AVAILABLE"},"content":{"rendered":"<div data-elementor-type=\"wp-post\" data-elementor-id=\"2510\" class=\"elementor elementor-2510\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-31af760c elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"31af760c\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-6e781424\" data-id=\"6e781424\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-30e52a3e elementor-widget elementor-widget-text-editor\" data-id=\"30e52a3e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\n<p class=\"wp-block-paragraph\">GREYCORTEX has released the latest version of its MENDEL network traffic analysis solution. Version 3.6.0 brings important features, improvements, and bug fixes. The main features in MENDEL 3.6.0 include automatic plugin execution for faster response, more efficient storage for longer data retention, improved incident management, including generating incident reports, and many others.<\/p>\n\n<h2 class=\"wp-block-heading\">MAIN FEATURES<\/h2>\n\n<p class=\"wp-block-paragraph\"><strong>Incident management\u00a0<\/strong><br \/>Improves the ability to work with incidents, providing an easier way to define and describe security incidents and their management, and provide tools to export them into a final printable report (PDF) suitable for presentation and reporting<\/p>\n\n<p class=\"wp-block-paragraph\"><strong>Automated Threat Response<\/strong><br \/>MENDEL allows the automatic blocking of traffic on firewalls or sending notifications to external systems through custom scripts. The execution of the script is based on predefined event filter plugins.<\/p>\n\n<p class=\"wp-block-paragraph\"><strong>Application Detection\u00a0<\/strong><br \/>Enhanced flow detection, which can now recognize up to 4,000 commonly used applications to improve better visibility into specific services.<\/p>\n\n<p class=\"wp-block-paragraph\"><strong>Multitier storage for longer data retention<\/strong><br \/>A change in the way MENDEL stores data, with the goal of saving disk space and providing more effective storage for machines, with data retention over three months.<\/p>\n\n<p class=\"wp-block-paragraph\"><strong>Parsing new RDP protocol and enhance existing parsers<\/strong><br \/>Many improvements have been implemented for SMB, SNMP, SIP, SMTP, Modbus (TCP\/UDP), and many other protocols.<\/p>\n\n<p class=\"wp-block-paragraph\"><strong>JA3S support<\/strong><br \/>Enhanced support for the JA3 fingerprint method, making it possible to fingerprint the entire cryptographic negotiation between a client and it\u2019s server by combining JA3 + JA3S (server side fingerprinting).<\/p>\n\n<p class=\"wp-block-paragraph\"><strong>Enhanced detection of malicious encrypted communication<\/strong><br \/>MENDEL is able to detect malicious TLS certificates, malicious clients, or servers using JA3 fingerprints.<\/p>\n\n<h2 class=\"wp-block-heading\">ENHANCEMENTS<\/h2>\n\n<p class=\"wp-block-paragraph\"><strong>Processing Cisco ASA NetFlow<\/strong><br \/>Appliances are now able to process NetFlow data from Cisco ASA solutions in the NetFlow Secure Event Logging format.<\/p>\n\n<p class=\"wp-block-paragraph\"><strong>Cloning MENDEL instances from VM templates<\/strong><br \/>Allows the cloning of existing MENDEL instances in a virtual environment for faster deployment without installation.\u00a0<\/p>\n\n<p class=\"wp-block-paragraph\"><strong>DB Optimizations and maintenance processes<\/strong><br \/>Optimization and improvement for faster processing in user interface response for large networks.\u00a0<\/p>\n\n<p class=\"wp-block-paragraph\"><strong>Extended protocol detection<\/strong><br \/>Improvements in flow processing, with better flow direction for greater accuracy as well as support for dealing with asynchronous flows.<\/p>\n\n<p class=\"wp-block-paragraph\"><strong>Samba backup<\/strong><br \/>Enhanced configuration and password handling of data backup to Samba share, including a better connection error handling and consistency check for more reliable backup in the event of a backup error.<\/p>\n\n<h2 class=\"wp-block-heading\">OTHER IMPROVEMENTS<\/h2>\n\n<p class=\"wp-block-paragraph\">Removed deprecated IDS signatures from Proofpoint<br \/>Added a certificate valid date into TLS protocol<br \/>Added the option to cancel data requests to most pages<br \/>Added support for Citrix Xen virtualization platform<br \/>Enhanced processing for false positives for external networks<br \/>Improve the processing of network statistics on a huge number of subnets in the User Interface<br \/>Enhanced reporting for Active Directory errors during processing logs<br \/>Enhanced port filter with full text<br \/>Added IPv4 Link-local subnet (APIPA) to default subnets<br \/>Updated Dell hardware monitoring tools to the latest version<br \/>Upgraded to latest Intel 10Gbits network cards drivers<br \/>Removed deprecated blacklisted sources<\/p>\n\n<h2 class=\"wp-block-heading\">FIXED ISSUES<\/h2>\n\n<p class=\"wp-block-paragraph\">In general, our development team focused on improving user experience and reporting, as well as more improvements to user experience, system stability, and performance.<\/p>\n\n<h2 class=\"wp-block-heading\">MENDEL PRODUCT SUPPORT<\/h2>\n\n<p class=\"wp-block-paragraph\">Full support is provided for the new released version 3.6.0 and previous version 3.5.x. Limited support is provided for previous version 3.4.x. Versions 3.3.x and older are no longer supported, end-users with valid support and maintenance or active SW subscription can upgrade to the supported version(s).<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>","protected":false},"excerpt":{"rendered":"<p>GREYCORTEX has released the latest version of its MENDEL network traffic analysis solution. Version 3.6.0 brings important features, improvements, and bug fixes. The main features in MENDEL 3.6.0 include automatic plugin execution for faster response, more efficient storage for longer data retention, improved incident management, including generating incident reports, and many others. MAIN FEATURES Incident [&hellip;]<\/p>","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[9],"tags":[],"class_list":["post-2510","post","type-post","status-publish","format-standard","hentry","category-features"],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/paZ0Rf-Eu","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/posts\/2510","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/comments?post=2510"}],"version-history":[{"count":3,"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/posts\/2510\/revisions"}],"predecessor-version":[{"id":2515,"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/posts\/2510\/revisions\/2515"}],"wp:attachment":[{"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/media?parent=2510"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/categories?post=2510"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/tags?post=2510"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}