Release notes
This topic describes the change history of Security Center features and documentation.
2026
August 2026
Type | Feature | Update title | Update details | Release date | Region | Related documentation |
New feature | Attack surface management | Attack surface management supports pay-as-you-go and site-independent credential configuration | Pay-as-you-go commercialization: The attack surface management feature now supports the pay-as-you-go billing model (China site and international site), lowering the usage threshold and flexibly meeting security detection needs. | August 17, 2026 | All regions | Pay-as-you-go、Purchase and unsubscribe from Attack Surface Management |
August–December 2025
Feature | Change type | Description | Release date | Related documentation |
Agentic SOC | Enhancement | Data import now supports Azure. | December 2025 | Import Azure log data |
Vulnerability management | New feature | Vulnerability management now supports automated vulnerability remediation. | December 2025 | View and handle vulnerabilities |
Agentic SOC | Enhancement | Automated response rules now include the following capabilities: Trigger rules based on security event updates. The Add Alert to Whitelist and update owner actions are now available. | December 2025 | Automated response rule |
Agentic SOC / Detection and Response | New feature | The update owner feature is available for security event handling. | December 2025 | Assess and handle Agentic SOC security events, Assess and handle CWPP security events |
Agentic SOC | New feature | Data import now supports ingesting data from Alibaba Cloud OSS. | November 2025 | General data import process |
Agentic SOC | Enhancement | Add enrichment information to custom alerting rules. | November 2025 | Detection rules |
Connect to Baidu Cloud assets | New feature | Manage Baidu Cloud assets in Security Center. | November 2025 | Onboard Baidu Cloud assets by using an AccessKey |
Agentless detection | Enhancement | Agentless detection now supports default scanning for new assets. | November 2025 | Agentless detection, One-click onboarding policies and billing for pay-as-you-go services |
Malicious file detection | New feature | Handle malicious file detection results. | November 2025 | Handle detection results |
One-click Policy Activation | Enhancement | One-click Policy Activation now includes Log Management, anti-ransomware, and vulnerability remediation. | November 2025 | One-click onboarding policies and billing for pay-as-you-go services |
Log Analysis and Log Management | Enhancement | Purchase and use Log Analysis and Log Management concurrently. | November 2025 | Purchase Security Center, Migration guide from Log Analysis to Log Management |
Overview | Deprecation | The previous overview page is deprecated. | November 2025 | Assess and handle CWPP security events |
Anti-ransomware | Enhancement | The anti-ransomware feature now supports the pay-as-you-go billing method. | October 2025 | Anti-ransomware service overview, Purchase Security Center, Activate and purchase the anti-ransomware service |
Agentless detection | New feature | Agentless detection now supports scanning of host assets on AWS. | October 2025 | Agentless detection |
Cloud Security Posture Management (CSPM) | Enhancement | Cloud Security Posture Management (CSPM) now supports onboarding of assets from Volcengine. | September 2025 | Onboard Volcengine assets by using an AccessKey, Add cloud assets for configuration checks |
Agentic SOC | Enhancement | Schedule updates to the global_white_list watchlist using trusted IP address sources from Alibaba Cloud products and services. | September 2025 | Watchlist |
Billing | Enhancement | The pay-as-you-go plan now includes a basic service fee. Additionally, the term "protection level" replaces "protection edition". | September 2025 | Purchase Security Center, Billing, [Notice] Pay-as-you-go billing change |
Agentic SOC | Enhancement | Configure entity mapping for alerts in custom alerting rules. | September 2025 | Detection rules |
Detection and Response / Agentic SOC | Enhancement | The security event handling feature is now available to CWPP users. | September 2025 | Assess and handle Agentic SOC security events |
Agentic SOC | New feature | Response orchestration now includes the TaskContext, Threatbook, and Fortinet components. | August 2025 | TaskContext component, Threatbook component, Third-party components (OpenAPI) |
Attack Analysis | Migration | The Attack Analysis feature has been moved to network defense alerts under Security Alerts. | August 2025 | Manage alerts, [Notice] Changes to Attack Analysis and Event Investigation |
Agentic SOC | Enhancement | Product integration now supports batch onboarding of Alibaba Cloud native products and auto-discovery of multi-account Logstore data sources. | August 2025 | Multi-account management |
July 2025
Feature name | Change type | Description | Affected editions | Release date | Related documents |
Log management | Enhancement | The log management feature now supports the pay-as-you-go billing method. | All editions | July 29, 2025 | Log management |
Container security | Enhancement | Bind ACK assets to the Ultimate Edition. | Ultimate Edition | July 29, 2025 | |
Agentless detection | Enhancement | Agentless detection now supports scanning in the Indonesia (Jakarta) region. | Users on the pay-as-you-go plan for agentless detection | July 29, 2025 | Agentless detection |
Malicious file detection | Enhancement | The malicious file detection feature now supports scanning OSS files up to 1 GB in the Security Center console, an increase from 500 MB. | Requires the malicious file detection add-on | July 16, 2025 | Malicious file detection |
Response orchestration | New feature | New workflow components are now available. | All editions | July 9, 2025 | About workflow components |
Agentic SOC | Enhancement | Access the upgrade assessment for Agentic SOC 2.0. | All editions | July 9, 2025 | [Notice] Agentic SOC upgrade [Notice] Enhancements to process file write logging and file read/write logging capabilities |
Host and container security license binding | Enhancement | Only the Ultimate Edition protects Lingjun assets, so they must be bound to this edition. | Anti-Virus Edition, Enterprise Edition, Advanced Edition | July 3, 2025 | Manage host and container security licenses |
June 2025
Feature name | Change type | Description | Affected versions | Release date | Related documents |
Cloud product configuration risk check | New | Adds configuration risk checks for cloud-native AI products on Azure and AWS. | Requires the cloud security posture management add-on. | June 18, 2025 | Cloud product configuration risk check |
AI security posture management | Enhancement | Adds an Overview card to the AI Asset page. | All versions | June 13, 2025 | AI security posture management |
Malicious file detection | Enhancement | Malicious file detection now supports pay-as-you-go. | Requires the malicious file detection add-on. | June 9, 2025 | Malicious file detection Billing details |
Application protection | Enhancement | Application protection now supports pay-as-you-go. | Requires the application protection add-on. | June 9, 2025 | Billing details |
May 2025
Feature | Change type | Description | Affected versions | Release date | Documentation |
Agentless detection | Enhancement | Agentless detection now supports alert notifications. | Available to users who have enabled pay-as-you-go for agentless detection. | 2025-05-28 | Notification settings |
Security report | Enhancement | The optimized security report page now includes a cover page. The report now includes data from CSPM and SDK scan tasks. It also provides additional data for attack analysis and RASP, and consolidates data across networks, hosts, and applications. High-risk data, such as weak passwords, is now included in the report. | Advanced Edition, Enterprise Edition, and Ultimate Edition | 2025-05-16 | Security report |
Log analysis | Enhancement | Log analysis now supports the delivery and storage of alert logs from agentless detection. | All editions | 2025-05-12 | Log types and field descriptions |
April 2025
Feature name | Change type | Description | Affected versions | Release date | Related documentation |
Anti-ransomware | Updated | Database protection policies now support selecting specific instances. | Requires the Anti-ransomware value-added service. | 2025-04-29 | Manage protection policies and clients |
Cloud Security Posture Management | Updated | Cloud product configuration risk now supports custom check items. | Requires a paid subscription for Cloud Security Posture Management. | 2025-04-25 | Custom check items |
March 2025
Feature name | Change type | Description | Affected editions | Release date | Related documentation |
Baseline risk check | Updated | The entry point for this feature has been moved to the Baseline Risk tab on the Risk Governance > CSPM page in the Security Center console. | Advanced, Enterprise, and Ultimate | 2025-03-31 | Baseline risk check |
Asset fingerprinting | New | Asset fingerprinting now supports collecting information about AI components. | Enterprise, Ultimate | 2025-03-31 | Asset fingerprinting |
Asset exposure analysis | New | Asset exposure analysis can now identify exposed AI services deployed on servers. | Enterprise, Ultimate | 2025-03-31 | Asset exposure analysis |
Vulnerability management | New | The application vulnerability feature can now detect vulnerabilities in AI applications. | Enterprise, Ultimate | 2025-03-31 | View and manage vulnerabilities |
Image security scan | New | The image security scan can now flag images deployed through Platform for AI-Elastic Algorithm Service (PAI-EAS). It also detects sensitive information, such as API keys for Alibaba Cloud Model Studio, stored in plaintext during AI API calls. | Requires the image security scan add-on. | 2025-03-31 | View image risks and remediation instructions |
Agentless detection | New | Agentless detection can now detect sensitive information, such as tokens for PAI-EAS, stored in plaintext during AI API calls. | Available to users who enable pay-as-you-go for agentless detection. | 2025-03-31 | Agentless detection |
Cloud Security Posture Management | Updated | The cloud product configuration risk check feature now checks for AI Security Posture Management (AI-SPM). | Available to users who purchase or enable Cloud Security Posture Management. | 2025-03-31 | Cloud product configuration risk check |
The cloud product configuration risk check feature now checks for Kubernetes Security Posture Management (KSPM). | Available to users who purchase or enable Cloud Security Posture Management. | 2025-03-28 | |||
Log management | Deprecated | Security Center no longer supports the delivery and storage of network logs through Log Analysis or the log management feature of Agentic SOC. | Affects users who have purchased storage capacity for Log Analysis or Agentic SOC. | 2025-03-27 | [Notice] Updates to Log Analysis and Agentic SOC |
Anti-brute-force cracking | Updated | Security Center has added configuration options for SQL Server to mitigate the risk of brute-force attacks and database breaches. | Advanced, Enterprise, Ultimate | 2025-03-14 | Anti-brute-force cracking |
Host and container security | Updated | Enable pay-as-you-go for host and container security and bind different protection editions to your servers. | All editions | 2025-03-14 | Purchase Security Center Manage licenses for host and container security |
February 2025
For Security Center feature releases before 2024, see Release notes (Before 2024).
January 2025
Feature name | Change type | Description | Affected editions | Release date | Related documentation |
Multi-cloud asset onboarding | Enhancement | Configure an account name when onboarding multi-cloud assets to distinguish assets from different accounts of the same third-party cloud provider. | All editions | 2025-01-12 | Add third-party cloud assets |
Agentic SOC | Enhancement | To avoid ingesting logs with low investigation value, Security Center checks whether you have purchased a paid edition (Anti-Virus Edition, Advanced Edition, Enterprise Edition, or Ultimate Edition) before ingesting ActionTrail logs based on the recommended policy. | Requires the Agentic SOC value-added service. | 2025-01-12 | What is Agentic SOC |
Serverless assets | Enhancement | The serverless security feature supports the protection of Container Service assets. | Available for users who have enabled pay-as-you-go for serverless assets. | 2025-01-09 | Serverless security |
Client status change | Enhancement | The Security Center client supports additional statuses, including client offline, server powered off, and client not installed. | All editions | 2025-01-07 | Install client |
Application Protection | Enhancement | Resource statistics include the number of PHP applications. | Requires the Application Protection value-added service. | 2025-01-07 | View RASP-protectable application list |
December 2024
Feature name | Change type | Description | Affected versions | Release date | Related documentation |
Agentic SOC | Enhancement | When you enable pay-as-you-go for Agentic SOC, you can select a recommended log ingestion policy. This policy automatically ingests 14 types of logs from Alibaba Cloud products, including Security Center, Web Application Firewall, Cloud Firewall, and ActionTrail. | Requires the Agentic SOC add-on. | 2024-12-27 | What is Agentic SOC |
Ransomware protection | Enhancement | Ransomware protection for servers is now available in China (Ulanqab), China (Heyuan), and China (Guangzhou). | Requires the ransomware protection add-on. | 2024-12-20 | Ransomware protection service overview |
Agentless detection | Enhancement | Agentless detection now supports incremental scans for custom images. | Available for users who have enabled pay-as-you-go for agentless detection. | 2024-12-20 | Agentless detection |
Agentless detection now supports remediation for malicious samples and sensitive files. | |||||
Malicious file detection | Enhancement | The maximum file size for a single malicious file scan in OSS is now 500 MB. | Requires the malicious file detection add-on. | 2024-12-18 | Malicious file detection |
Billing | Enhancement | Enable pay-as-you-go for Agentic SOC to access threat analysis and response capabilities, including product integration, incident response, security alerts, and response orchestration. | All editions | 2024-12-13 | Billing |
Billing | Enhancement | Switch from full protection to on-demand protection. Select specific servers to protect for more flexible billing and protection. | All paid editions | 2024-12-12 | [Notice] Upgrade from full protection to on-demand protection |
Cloud Security Posture Management | Enhancement | The cloud platform configuration check feature has been renamed to Cloud Security Posture Management. | Available to users with the cloud platform configuration check add-on. | 2024-12-10 | Cloud Security Posture Management |
Application protection | New Feature | Application protection now supports PHP applications. | Requires the application protection add-on. | 2024-12-06 | What is application protection |
November 2024
Feature name | Change type | Description | Availability | Release date | References |
Image security scan | Enhancement | Export sensitive file information from image security scans, including image version and repository name. | Requires the image security scan add-on. | 2024-11-21 | View and handle image risks detected by scans |
CI/CD integration settings | Enhancement | The documentation for Jenkins-Freestyle and Jenkins-Pipeline integration now provides more detailed steps and screenshots for integrating the plugin and configuring the image security scan. | Enterprise Edition | 2024-11-19 | Jenkins-Freestyle integration Jenkins-Pipeline integration |
Cloud platform configuration check | Enhancement | This feature now comprehensively scans and analyzes access paths between Alibaba Cloud resources, such as an ECS instance with a RAM role that grants access to an OSS bucket, and presents the results in a visual graph. | Requires the cloud platform configuration check add-on. | 2024-11-19 | Attack path analysis |
Agentic SOC | Enhancement | The recommended log ingestion policy for Agentic SOC now ingests 14 log types from Security Center, Web Application Firewall, Cloud Firewall, and ActionTrail. | Requires the Agentic SOC add-on. | 2024-11-15 | What is Agentic SOC |
Anti-ransomware | Enhancement | The anti-ransomware feature for databases now supports viewing backup tasks. | Requires the anti-ransomware add-on. | 2024-11-15 | Troubleshoot exceptions in database anti-ransomware policy status and backup tasks |
The anti-ransomware feature now supports backing up data from Rocky Linux systems. | Requires the anti-ransomware add-on. | 2024-11-13 | Anti-ransomware overview |
October 2024
Feature | Change type | Description | Affected edition | Release date | Related documentation |
Container microsegmentation | Enhancement | The container firewall feature is renamed to container microsegmentation. | Ultimate Edition | October 31, 2024 | container microsegmentation |
Image security scan | Enhancement | Now supports scanning GitLab image repositories. | Ultimate Edition | October 31, 2024 | Configure and perform image security scans |
Container assets | Enhancement | Now supports adding GitLab image repositories. | Ultimate Edition | October 31, 2024 | Add an image repository |
Anti-ransomware | Enhancement | Anti-ransomware policies for servers can now exclude non-local mount paths. | Requires the anti-ransomware add-on. | October 30, 2024 | Create a protection policy and a client |
Application Protection | Enhancement | Configure an application onboarding allowlist to control which applications RASP protects. | Requires the Application Protection add-on. | October 30, 2024 | Onboard Application Protection |
Agentic SOC | Enhancement | Cloud Workload Protection Platform (CWPP) and Agentic SOC alerts are now consolidated on a single page. | All editions | October 24, 2024 | None |
Brute-force protection | Enhancement | Advanced Edition users can now install the Alinet client plug-in to enhance brute-force protection with a cloud-based dynamic defense model. | Advanced Edition | October 24, 2024 | [Notice] Enhancements to Brute-Force Protection in Security Center |
Application Protection | Enhancement | The manual onboarding process for applications in container environments has been optimized, allowing you to customize the download and installation of the probe. | Requires the Application Protection add-on. | October 21, 2024 | Onboard Application Protection |
Core file monitoring | Enhancement | Now supports monitoring on Windows servers. | Enterprise Edition, Ultimate Edition | October 16, 2024 | core file monitoring |
Proactive container defense | Enhancement | Image restrictions for defense rules that target non-image programs have been optimized. | Ultimate Edition | October 16, 2024 | Container image restrictions for rule effectiveness |
Log Analysis | Enhancement | Log Analysis now supports shipping and storing alert logs from the core file monitoring feature. | Enterprise Edition, Ultimate Edition | October 15, 2024 | Log Types and Field Descriptions |
Anti-ransomware | Enhancement | The database anti-ransomware feature now supports backing up data from MySQL 8.0. | Requires the anti-ransomware add-on. | October 11, 2024 | Anti-ransomware Service Overview |
September 2024
Feature | Type | Description | Editions | Date | Documentation |
Serverless assets | Enhancement | Extends security checks to Serverless App Engine (SAE) products. | Users on the pay-as-you-go plan for serverless assets. | September 30, 2024 | Serverless security |
Asset exposure analysis | Enhancement | Asset exposure analysis now supports detection of additional asset types, including ApsaraDB for Tair (Redis-compatible), ApsaraDB RDS, and ApsaraDB for MongoDB. | Enterprise Edition and Ultimate Edition | September 27, 2024 | Asset exposure analysis |
Agentic SOC | Enhancement | The Attack Timeline tab on the security event details page is enhanced. Timeline cards now include alert and log evidence, and an event traceability graph. This feature also automatically traces suspicious attack paths. The graph displays rich node types, such as alerts, logs, vulnerabilities, baselines, assets, and entities, and lets you view details for each. | Requires the Agentic SOC add-on. | September 24, 2024 | Security events |
Deprecation | To improve the Agentic SOC log management experience, Security Center has discontinued the cold data feature, which was in public preview. | September 12, 2024 | [Notice] End of public preview and discontinuation of the Agentic SOC cold data feature |
August 2024
Feature | Change type | Description | Affected versions | Release date | Related documentation |
Agentic SOC | Enhancement | Added the aliyuncloudOpenAPI basic orchestration group. | Requires the Agentic SOC value-added service. | August 30, 2024 | Response rules |
Enhancement | Supports ingesting logs from third-party vendors, such as Chaitin WAF and Fortinet Firewall. | Requires the Agentic SOC value-added service. | August 20, 2024 | Ingesting logs from security vendors | |
application protection | Enhancement | Supports runtime circuit breaker configuration. | Requires the application protection value-added service. | August 19, 2024 | Onboarding application protection |
cloud product configuration check | Enhancement | Lowered prices and introduced tiered billing for the pay-as-you-go method. Lowered prices and introduced tiered billing for the subscription method. | Requires the cloud product configuration check value-added service. | August 19, 2024 | Billing Cloud security posture management overview |
application protection | Enhancement | Uses a large model to analyze attack alerts and webshell detection alerts, and provides detailed explanations and reasoning for each. | Requires the application protection value-added service. | August 16, 2024 | Handling attack alerts |
cloud product configuration check | Enhancement | Added new, free check items. Added allowlist policy management. | All versions | August 2, 2024 | Cloud security posture management overview Configuring and running check policies |
serverless assets | General availability | The commercial version is now available, ending the public beta. Supports security risk detection for assets from Elastic Container Instance (ECI), ACK Serverless clusters, and Serverless App Engine (SAE). | All versions | August 2, 2024 | Serverless security |
application protection | Enhancement | The webshell detection alert details page now includes a toggle to decompile Java files. | Requires the application protection value-added service. | August 1, 2024 | Webshell protection |
July 2024
Feature | Type | Description | Versions | Date | Documentation |
Malicious file scan SDK | Enhancement | Supports decrypting and scanning OSS data configured with server-side encryption. | Requires the malicious file detection add-on. | July 26, 2024 | Malicious file detection |
Agentless detection | Enhancement | Supports snapshot and custom image scanning. | Requires the pay-as-you-go service for agentless detection. | July 8, 2024 | Agentless detection |
Agentic SOC | Enhancement | Supports copying playbooks. | Requires the Agentic SOC add-on. | July 3, 2024 | Response rule |
June 2024
Feature | Change type | Description | Affected editions | Release date | Related documentation |
Malicious file detection SDK | Enhancement | The Security Center console now displays detection results for malicious files identified as risky by API detection. | Requires the malicious file detection value-added service. | June 28, 2024 | Malicious file detection |
Deliver malicious file detection logs to a dedicated Logstore in Security Center. | Malicious file detection logs | ||||
Configure DingTalk chatbot notifications to receive real-time alerts about detected malicious files. | Configure DingTalk chatbot notifications | ||||
Vulnerability management | Enhancement | Vulnerability management now supports scanning for vulnerabilities in SUSE and Kylin operating systems. | All editions | June 20, 2024 | Vulnerability management overview |
Application Protection | Enhancement | Identify and list application processes eligible for Application Protection. On the Vulnerabilities tab of the Application Vulnerability page, you can now onboard assets that have application vulnerabilities to Application Protection. On the Application Protection page, the Application Analysis tab now displays statistics and trend charts related to vulnerability defense. | Requires the Application Protection value-added service. | June 19, 2024 | What is Application Protection? |
Agentic SOC | Enhancement | Agentic SOC now supports ingesting DCDN Edge Routine logs, DCDN user access logs, and DCDN WAF logs for threat detection, incident response, orchestration, and log storage. | Requires the Agentic SOC value-added service. | June 19, 2024 | What is Agentic SOC? |
Baseline check | Enhancement | Baseline check now supports additional operating systems, including Debian 10, 11, and 12, and TencentOS Server 3.1. | Advanced, Enterprise, and Ultimate | June 19, 2024 | Baseline risk checks |
Enhancement | Upload weak password dictionaries up to 40 KB. | Advanced, Enterprise, and Ultimate | June 7, 2024 | Baseline risk checks | |
Agent deployment | Enhancement | The agent now supports installation on Kylin V7 and RHEL 9. | All editions | June 6, 2024 | Operating systems supported by the agent |
May 2024
Feature | Change type | Description | Affected editions | Release date | Related documentation |
Image security scan | Enhancement | The image security scan feature is now available in the China (Ulanqab) region. | Requires the image security scan add-on. | 2024-05-31 | Image security scan overview |
Container assets | Enhancement | Export risk detection results for individual image assets. | Ultimate Edition | 2024-05-31 | Manage container assets |
Product purchase | Enhancement | When you purchase a subscription Security Center instance, you can select the number of servers and the vCPU count. You must then manually manage the number of licenses. | Anti-Virus Edition, Advanced Edition, Enterprise Edition, Ultimate Edition | 2024-05-30 | Manage licenses for host and container security |
Security alert handling | Enhancement | The alert name Anomalous Process Behavior - Suspicious Command has been changed to Command and Control. | Anti-Virus Edition, Advanced Edition, Enterprise Edition, Ultimate Edition | 2024-05-22 | Overview of CWPP security alerts |
Application protection | Enhancement | The wording on the attack alert details page has been revised for clarity. | Requires the application protection add-on. | 2024-05-15 | Handle attack alerts |
Malicious file detection | Enhancement | The maximum file size for malicious file detection has been increased from 20 MB to 100 MB. | Requires the malicious file detection add-on. | 2024-05-14 | Malicious file detection |
Cloud platform configuration check | Enhancement | The number of free check items available to users of the Free Edition has increased from 25 to over 60. Free checks do not consume the quota for users of paid editions. | To use this feature, you must either purchase a quota for cloud platform configuration checks or enable pay-as-you-go. | 2024-05-11 | Cloud Security Posture Management overview |
April 2024
Feature | Change type | Description | Affected editions | Release date | Related documentation |
Agentic SOC | Enhancement | The service uses a tiered pricing model based on the volume of logs ingested and the amount of hot storage required. Analysis and response capabilities, such as security alerts, incident response, and orchestrated response, are separate from log storage. This allows you to flexibly choose whether to purchase log storage capacity. You can designate a global administrator to centrally manage security incidents across multiple Alibaba Cloud accounts. | Users who have purchased the Agentic SOC value-added service. | April 26, 2024 | [Notice] Agentic SOC Billing Changes |
Application protection | New feature | The new memory trojan defense feature detects threats hidden in memory. | Users who have purchased the application protection value-added service. | April 17, 2024 | Memory trojan defense |
Cloud platform configuration check | Enhancement | Security Center now provides a one-click fix for over 50 check items. | Users who have purchased a quota for cloud platform configuration checks or enabled pay-as-you-go for this feature. | April 17, 2024 | Configure and run a check policy |
Anti-ransomware (decoy capture) | Enhancement | This feature now supports Linux servers. | Advanced, Enterprise, or Ultimate | April 17, 2024 | Host protection settings |
Baseline check | Enhancement | The CIS compliance baseline type has been renamed to International General Security Best Practices. | Advanced, Enterprise, or Ultimate | April 11, 2024 | Baseline risk check |
Malicious file detection | Enhancement | Malicious file detection can now decompress and scan compressed files. | Users who have purchased the malicious file detection value-added service. | April 11, 2024 | Malicious file detection |
Agentic SOC log management | New feature | The Log Analysis page has been renamed to Log Management. The original Log Management feature has been renamed to Hot Data. The log management feature now includes a new Cold Storage Settings feature, which provides a lower-cost storage option. | Users who have purchased the Agentic SOC value-added service. | April 2, 2024 | Log management |
March 2024
Feature | Type | Description | Versions | Date | Documentation |
Agentic SOC | Updated | The threat analysis feature has been renamed to Agentic SOC. | Requires the Agentic SOC add-on. | 2024-03-29 | What is Agentic SOC (formerly threat analysis) |
Container file protection | Updated | You can configure a process whitelist and a file and directory whitelist when you create rules for container file protection. | Ultimate Edition | 2024-03-19 | Container file protection |
February 2024
Feature name | Change type | Description | Affected edition | Release date | Related documentation |
core file monitoring | Enhancement | Receive core file monitoring alert notifications via a DingTalk robot. | Enterprise Edition, Flagship Edition | February 23, 2024 | Configure notification settings |
baseline check | Enhancement | The custom weak password feature now lets you append new weak passwords to an existing dictionary. | Advanced Edition, Enterprise Edition, Flagship Edition | February 22, 2024 | baseline risk checks |
application protection | Enhancement | Use protection policy groups for fine-grained control over detection types and modes (Standard, Loose, and Strict). On the Application Protection > Attack Alerts tab, an option to add items to the allowlist has been added. | Requires the application protection value-added service. | February 22, 2024 | Connect to application protection |
cloud platform configuration check | Enhancement | Pay-as-you-go billing is now supported. | All editions | February 19, 2024 | Overview of CSPM |
January 2024
Feature name | Change type | Description | Affected editions | Release date | Related documentation |
Security report | Enhancement | Optimized the security report page in the console. | Advanced Edition, Enterprise Edition, Ultimate Edition | 2024-01-31 | Security report |
Overview | Enhancement | Optimized the content in the Security Information module. | All editions | 2024-01-29 | Overview (old version) |
Risk governance | Enhancement | Renamed the risk management module to risk governance. | All editions | 2024-01-26 | None |
Cloud platform configuration check | Enhancement | Users without a quota for cloud platform configuration check can now use 25 check items for free. | All editions | 2024-01-19 | Cloud security posture management overview |
Release history
For Security Center feature releases before 2024, see Release notes (Before 2024).