Skip to main content

Seculyze 4.0.0 Release Notes

Automated monthly reporting in your own branding, incident precedent lookup, and hands-free alert rule updates.

Overview

Seculyze 4.0.0 removes the manual work from monthly reporting. Branded security reports are generated and delivered on the schedule you set, using your own template if you have one. Analysts also get precedent on every incident, and Calibrate can now apply published alert rule updates on its own.



Detailed Description

Three things drive this release. Monthly reporting is now automated end-to-end: data gathering, commentary, branding, and delivery. Incident triage gains precedence, showing how the same detection was closed before and how strongly the cases actually match. And Calibrate can keep detection rules current without a click per rule.


Release Highlights

📄 Automated Monthly Reporting — Scheduled, branded security reports using your own template

🔍 Similar Incidents — See how the same detection was closed before, ranked by real overlap

⚙️ Alert Rule Auto-Update — Optional automatic application of published detection updates


Changes

🏗️ Added Functionality — All Customers

Monthly Reporting

  • Introduced automated monthly security reports, delivered on the day of the month you choose

  • Added a designed 20-slide default report: executive summary, incident trends, MITRE coverage, threat landscape, Secure Score, risky users, devices, and log source budget

  • Added custom template upload — your own PowerPoint deck replaces the standard design

  • Added company name and logo branding on the cover slide and every footer

  • Added slide exclusion by slide number

  • Added Microsoft Secure Score: current score, movement over the period, and open improvement actions

  • Added the top five Secure Score improvement actions, ranked by value for effort

  • Added device count and user/device change counts from Defender

  • Added a threat landscape briefing from security news feeds, with references

  • Added AI-written slide commentary, generated so the narrative matches the figures

  • Added on-demand report generation and a sample deck preview

  • Added delivery by email or ITSM channel, via a one-time download link

  • Added a permission pre-flight check with a link to the setup guide

Incidents

  • Added the Similar Incidents panel: past incidents from the same detection, with closure verdict, entity overlap, shared threat intel and match strength

  • Added row expansion showing the entities two incidents share

  • Added comments and Sentinel live status to the incident sidebar

  • Edit on an incident row now opens the incident directly in edit mode

Calibrate

  • Added Alert Rule Auto-Update: an optional setting that applies published template updates during the hourly calibrate run

  • Auto-applied updates produce the same changelog entry as a manual update

🏗️ Added Functionality — Multi Tenancy

  • Added a save confirmation naming the client count, since each config is written to that client's own tenant

  • Multi Tenancy can now manage their shared report template without first selecting a client

  • Channel selection now skips clients that cannot use it and names them

  • Added a per-client permission check, flagging clients that still need consent

  • Moved the Clients filter into the Client column as a header filter on incidents

  • Added auto-update rollout across clients, with per-client results

📊 Improved Features

  • Only connected ITSM integrations now appear in ticket creation, notification channels, Automated Reporting, and threshold pickers

  • Moved the client registry to the bottom of the navigation

  • Descending sort on Action now surfaces partially enabled tuning rules first

  • Custom tags are now prefilled in the noise reduction modal when already set

  • Threat intel now reads high/medium/low severity across summaries and graphs

  • The six-month incident trend now ends on the month being reported on

  • Added a confirmation before reverting to the default report template

  • Improved parsing of specific alert types and entities

🛠️ Bug Fixes — All Customers

  • Fixed MITRE filter pagination and close-all pagination

  • Fixed a manually generated report covering a different period than the scheduled one

  • Fixed truncated numbers in the executive summary

  • Fixed a fully spent log source budget showing a dash instead of 0

🛠️ Bug Fixes — Multi Tenancy

  • Fixed alert sorting returning a scrambled page when orphaned incidents were included

  • Fixed alert severity sorting alphabetically instead of by severity rank

  • Fixed sorting alerts by owner having no effect

  • Fixed client registry name sorting, and pagination repeating or skipping clients

  • Fixed the Clients filter chip appearing when nothing was filtered

  • Fixed the client delivery table stopping at 100 clients

  • Fixed switching client showing the previous client's template status

Did this answer your question?