Added a new Insights view for reviewing detection findings (e.g. from EDR tools) with severity filtering and a detail panel linking to related entities and MITRE ATT&CK mappings.
Scout can now proactively review and triage incoming security alerts as part of an investigation workflow.
Added CSV and JSON export for query results, including large result sets.
Introduced a new Workbench experience with a redesigned layout, chat, and workflow interface.
Added a queries sidebar in the hunt workspace that groups your queries by status (running, completed, failed).
Endpoint Control queries now report per-node progress and errors, and support streaming CSV/JSON export for large runs.
Added filters (by product, type, and tag) to the query Library, and category grouping for connections.
Organization owners can now delete their organization from settings, with a confirmation step.
Added self-serve subscription management — view your plan, update it, or cancel directly from settings.
Added parameter autocomplete and auto-closing brackets when writing query parameters in the query editor.
Added a bot-protection check to sensitive forms to help block automated abuse.