Skip to main content

Changelog — February 16 – March 1, 2026

New Features

  • Added a new Insights view for reviewing detection findings (e.g. from EDR tools) with severity filtering and a detail panel linking to related entities and MITRE ATT&CK mappings.
  • Scout can now proactively review and triage incoming security alerts as part of an investigation workflow.
  • Added CSV and JSON export for query results, including large result sets.
  • Introduced a new Workbench experience with a redesigned layout, chat, and workflow interface.
  • Added a queries sidebar in the hunt workspace that groups your queries by status (running, completed, failed).
  • Endpoint Control queries now report per-node progress and errors, and support streaming CSV/JSON export for large runs.
  • Added filters (by product, type, and tag) to the query Library, and category grouping for connections.
  • Organization owners can now delete their organization from settings, with a confirmation step.
  • Added self-serve subscription management — view your plan, update it, or cancel directly from settings.
  • Added parameter autocomplete and auto-closing brackets when writing query parameters in the query editor.
  • Added a bot-protection check to sensitive forms to help block automated abuse.

Improvements

  • Query runs are now more resilient — transient connection issues are automatically retried, and failures show clearer error messages.
  • Refreshed the admin panel with global lists, multi-select, and bulk actions across products and extensions.
  • Settings now displays legal/policy links and current version information.
  • The app now shows a friendly error screen instead of a blank page if something goes wrong unexpectedly.
  • Replaced silent failures with clear error notifications when an action doesn't succeed.
  • Clearer warnings and error messages when you don't have permission to access an organization-owned connection.
  • Query Library templates can now be filtered by multiple values at once.
  • Query details now show the source template name (with a link) and whether the query has been modified from the original.
  • Connection and product pages now use readable URLs instead of long ID strings.
  • Streamlined the Scout workspace to a single, simplified workflow.

Bug Fixes

  • Fixed incorrect product, connection, and organization counts shown in query results.
  • Fixed inaccurate result counts and run status for Endpoint Control queries.
  • Fixed the running animation getting stuck after a query run failed.
  • Fixed an issue that could expose internal error details in some API responses.
  • Strengthened access controls to prevent unauthorized changes to shared query schemas and mappings.
  • Strengthened access-control checks on account and organization settings to prevent unauthorized privilege changes.
  • Fixed an issue where Scout's parallel investigation tasks could interfere with one another.
  • Fixed the run detail view showing placeholder data instead of real query results.