IVX Cloud 25R3 introduces new features and enhancements.
New features and changes
You can now use the /health/integration/<connector_registration_id> API endpoint to monitor the operational status of each third-party applications integrated with IVX Cloud. This API checks the health status of each individual integration, allowing you to monitor their state and create alerts for any failures.
You can now download the original, password-protected malicious sample directly from the Artifacts column on the Submissions and Alerts pages in addition to the associated artifacts.
You can now download a comprehensive case file directly from the analysis reports page. Each case file contains:
All artifacts collected during the analysis
The detailed analysis report in PDF format
The original submitted sample.
The original sample is only included in the case file for submissions with a malicious verdict, as non-malicious samples are deleted immediately.
To prevent submission failures, a retry mechanism has been added to the Amazon S3 integration workflow.
IVX Cloud is now updated with the latest version of its dynamic analysis engine, improving detection capabilities for enhanced performance.
The Submissions and Alerts pages have been enhanced to display duplicate submission information to easily identify previously analyzed files. For any duplicate sample, the new Original Report ID column on both pages shows the ID of the initial analysis report. There is also a new Duplicate filter on both pages that allows you to isolate these submissions, helping you avoid redundant work.
To improve the reliability of automated workflows, the GCP integration for Pub/Sub now includes an automatic retry mechanism. The system will now retry publishing analysis results if it fails with a "service unavailable" error, ensuring all events are successfully delivered.
To easily track the source of submitted files, the Analysis Details report page is now enhanced with a new Additional Context section available for Threat Intelligence Exchange (TIE) users. This section displays key origin details, including the Machine Name and Agent GUID, allowing you to trace submissions back to specific endpoints.
Trellix Insights is now integrated into IVX Cloud to strengthen threat detection during file scans. When a file is scanned, the Trellix Intelligence engine helps determine the verdict. If a threat is detected, it is marked under the “threat_intel” engine. It also enriches the analysis by providing details such as campaign information, severity, and additional context for any Indicators of Compromise (IOCs) identified. All this detailed threat information is available in the Trellix Intelligence section of the analysis report.
The default browser used for web content during the sandbox analysis of file submissions has been updated from Internet Explorer to Microsoft Edge based on the supported OS profile. This improves threat detection and prevents malware from hiding by targeting an outdated browser.
Resolved issues
The following issues were resolved in the Intelligent Virtual Execution - Cloud 25R3 release.
Tracking number | Summary |
|---|---|
DOD-3772 | Fixes the issue where the /telemetry API endpoint incorrectly included the IOC field in the response when the query parameter |
Additional information
Date Filter time zone standardization
All date and time filters in the IVX Cloud portal operate in Coordinated Universal Time (UTC).