Every change to detections, cases, integrations and the night shift, written for the people who use them.
On call
Night pages now include a written hand-off
Every page an analyst takes overnight now ends with a short hand-off note on the case and in Slack.
Read the entry
Detections
OAuth consent phishing pack for Microsoft 365
Seven new detections for consent phishing, inbox rules and Graph API reads from new networks.
Read the entry
Detections
Test any detection against 30 days of logs
Run a rule against the last 30 days before you save it and see exactly what it would have caught.
Read the entry
Integrations
1Password Business events
1Password sign-in attempts and item usage are now a Wardell source.
Read the entry
Platform
Coverage export for SOC 2 evidence
Export the ATT&CK coverage map, case history and on-call log as one PDF for your auditor.
Read the entry
Platform
Case timelines load three times faster
Large cases with hundreds of events now open in under a second.
Read the entry
Send us one week of logs. We send back what we found.
Connect one source with a read-only key. Within 48 hours you get a written report of what Wardell would have caught. No contract, and you can disconnect at any time.