This month's release focuses on two areas: making investigations more actionable and giving admins more control over access, authentication, and auditing.
Every investigation now ends with action
An alert should not end with more homework. It should leave your environment more secure than it was before.
Qevlar now closes every investigation with a short, prioritized list of actions: what to contain, what to harden, which detection rules to tune, and where more context is needed.
Every outcome comes with a move:
- Benign: tune to cut future noise.
- Malicious: contain and harden to stop recurrence.
- Inconclusive: add the missing context.
- Missing data: connect the log source Qevlar flags.
That's the loop, closed: better data and context for the next alert, and a safer environment over time.
Coming next: one-click containment actions available directly from this section.
Catch account compromise hiding in routine alerts
Credential attacks often look legitimate at first. To identify the anomaly, you need to know what is normal for that specific user. Most teams do not have time to do that on every alert.
Identity Hunt does it automatically whenever an investigation includes a user, across endpoint, email, cloud, and network alerts. It builds a behavioral baseline from ~30 days of authentication logs, detects suspicious activity, then returns a verdict and the reach of the compromise.
It uncovers password spraying, brute-force attempts, impossible travel, MFA fatigue, and account takeover.
Identity Hunt is already running on your investigations. No configuration is required.
Extract the IOCs that matter
Every closed Qevlar investigation can now feed your security stack with the indicators it proves malicious. The new IOC API returns malicious file hashes, URLs, domains, and public IPs, along with the evidence behind each verdict.
Send confirmed indicators to blocklists, SIEM or EDR watchlists, detection rules, and retrospective hunts. Now you can act on what your detections missed.
Use Qevlar IOCs in your security stack →
Strengthen platform governance
This release adds new controls to help you secure access to Qevlar, support compliance requirements, and improve visibility into user activity.
Add stronger authentication and session security
Qevlar now offers MFA and session policy settings that give you a strong second factor at sign-in, a 30-minute inactivity timeout, and 12-hour reauthentication. Together, these controls support NIST 800-63B AAL2 authentication requirements.
Qevlar can enable these settings for you today. Self-service controls are coming next.
Want them enabled? Reply to this email or contact your Customer Success Manager at Qevlar.
Session policy documentation →
Track user activity with Audit Logs
Know who changed what, and when.
Audit Logs capture key user activity across Qevlar, giving security teams a complete audit trail for troubleshooting, governance, and compliance.
For MSSPs: Assign profiles by analyst, or by entire team
By default, analysts can access all profiles or tenants. Now you can lock that down at two levels.
Per-Profile Access limits an individual analyst to the profiles they're assigned. Turn on enforcement for a profile, assign profiles in User Management, and each analyst sees only their scope.
Team Access does the same for groups. Create a team, give it a set of profiles, and add analysts. They inherit that access the moment they join, so you configure it once and reuse it instead of setting up each person by hand.
New connector and upgraded Integration center
- Qevlar can now autonomously investigate HarfangLab endpoint alerts. By connecting HarfangLab as a data source, Qevlar can also run queries and retrieve relevant evidence.
- Connecting new data sources is now faster and easier with the redesigned Integration Center. It automatically validates required permissions and immediately flags any that are missing. Check it out →