What’s new.
Highlights across recent releases.
Active containment: contain a workload with NetworkPolicy/ANP, closed-loop verification with auto-reopen, learn observed egress into policy, and response playbooks with an opt-in auto-response switch.
Process-attributed incidents, MITRE ATT&CK Explorer, kill-chain fusion, real DNS telemetry, mesh/identity threats, runtime exec detection, crown-jewel assets and context-rich AI triage.
License-driven Observe / Segment / NDR tiers on a single operator install.
Istio AuthorizationPolicy generation for ambient and sidecar meshes, alongside L3/L4 NetworkPolicy.
Scan Git repositories and recommend policy before workloads go live.
Per-stream routing to Splunk indexes or syslog, each with its own destination and custom CA.