Stellar Cyber 6.6.0s Release Notes

Software Release Date:
Release Note Updated:

The Stellar Cyber 6.6.0s release delivers the following updates to the Stellar Cyber Open XDR platform.

The release notes are organized into the following sections:

Highlights

Autonomous SOC / Auto Triage

  • AI Assistance: Added AI Assistance to every automatically triaged case so you can investigate cases and alerts in plain language, asking why a case received its verdict, clarifying alert details, and exploring follow-up hypotheses against the case data and Verdict Signal Check (VSC) context that Alert Auto Triage has already assembled. (Available for SaaS deployments through an add-on license. Available for on-premises deployments through the Early Access Program.)

  • Auto Triage Verdict Visibility: Auto Triage verdicts now appear as filterable columns in the Alert Table and Threat Hunting views. In addition, a response action panel was added to the Auto Triage alert page (including phishing email alerts) so analysts can see and act on triage outcomes without opening individual cases.

  • MCP Server: The Stellar Cyber MCP Server connects supported AI clients to the Stellar Cyber Platform through the Model Context Protocol (MCP). The MCP server lets AI clients retrieve case and alert data, review investigation context, perform tenant-aware operations, and update selected case fields. This capability helps teams extend AI-assisted investigations by giving approved clients structured access to operational security data and workflows.

System / Platform

  • Platform Health Monitoring in the System Action Center (Early Access Program): Centralized platform health monitoring alerts in the System Action Center for improved visibility and faster response to platform issues.

  • License Enforcement and Usage Notifications: Added API actions for license enforcement and usage notifications.

Detections/Machine Learning

  • Improved Login Anomaly Fidelity: Alert suppression for Impossible Travel Anomaly and User Login Location Anomaly is now customizable, Impossible Travel prioritizes records with usernames, and ASN enrichment fields were added to Impossible Travel Anomaly alerts.

  • Improved User Counting Accuracy: Improved the accuracy of license user counting by integrating external data sources for Microsoft Entra ID.

Integrations

Usability

  • Watchlists for All Alert Fields: Enabled Add to Watchlistfor all alert fields.

  • Selective Parser Port Activation: Parser ingestion ports can now be enabled on-demand and parsers added after 6.5.0 are inactive by default, reducing false alerts from unused listeners.

Actions Required

There are no actions required in this release.

Behavior Changes

Changes that affect the way users interact with the product or interpret results are listed below.

  • DATA-3412: The totalbytes field in the Fortinet FortiAnalyzer parser is now calculated as the sum of inbytes_total and outbytes_total, consistent with how other parsers calculate this field. Previously, the FortiAnalyzer parser calculated totalbytes as the sum of inbytes_delta and outbytes_delta, which significantly underreported session volume when delta values differed from totals. Dashboards, detections, or queries that rely on totalbytes from FortiAnalyzer data may return different values after this change.

  • AELDEV-71104: Built-in legacy parsers added in 6.5.0 and later releases are now inactive by default for new tenants and must be explicitly activated in Parser Studio before use. Previously added legacy parsers retain their existing active status and are not affected by this change. You can activate or deactivate any individual parser at any time from Parser Studio, and the configuration is applied to sensors on the next deployment.

  • AELDEV-64683: The Google Workspace log collector no longer maps the metadata.customerId field to user.id. The customerId value is a Google account identifier for the organization, not a user identifier, so this mapping was incorrect and caused confusion in alert context. Existing events already indexed with this normalization are not affected. Newly ingested Google Workspace events no longer populate user.id from this field.

Deprecated Features

The following feature is planned for deprecation in a future version.

Upcoming Deprecation: SentinelOne Deep Visibility API – The Deep Visibility content type in the SentinelOne connector will be migrated to Deep Visibility (SDL) in a future version due to a SentinelOne API being deprecated.

Autonomous SOC

Improvements

Detection/ML

Improvements

Stellar Cyber Platform

New Features

Improvements

Sensors

New Features

Improvements

Connectors

New Features

Improvements

Parsers

New Features

Improvements

Usability

New Features

Improvements

Early Access Program

If you're interested in testing out new features ahead of general availability, consider joining the Early Access Program (EAP) by contacting your Stellar Cyber Customer Success representative and telling them which EAP feature you want to test. Once you've agreed to the EAP terms and signed up, the EAP feature is unlocked for you.

The purpose of this program is to boost performance and reliability through real-world customer insights, giving you a hands-on role in shaping a Stellar Cyber feature. In return, you'll receive early access to upcoming releases and the chance to guide product development.

The following EAP features are in this release:

Exportable Dashboards — Report Integration

Exportable Dashboards lets you schedule dashboards created with the Dashboard Builder as recurring PDF reports. The schedule form includes a new Default PDF type that renders the dashboard as it appears in the Dashboard Builder, along with options to control table row counts, chart color palettes, and optional CSV exports. This capability lets you generate consistent, configurable reports from new dashboards while preserving the settings and PDF types used by existing scheduled reports.

Parser Studio

Parser Studio lets you create and manage custom log parsers for data ingestion by cloning existing parsers, testing parser behavior before deployment, and activating parsers for production use. This capability helps you accelerate onboarding of custom log sources while reducing parser development effort and improving validation before live ingestion.

XDR Connector Webhook Ingestion

This is a simple webhook framework that lets you post JSON data directly from any external system into Stellar Cyber, accelerating custom integrations and expanding your visibility across the entire security stack. The XDR Connector is in Public Preview in this release.

Customizable Case Correlation Strategies

This EAP feature introduces support for multiple case correlation strategies, allowing teams to evaluate and experiment with different approaches to grouping alerts into cases. Each strategy provides a distinct investigative perspective:

  • Attacker-Centric Correlation groups alerts by the source (attacker) host, making it easier to track adversary behavior across multiple targets.

  • Victim-Centric Correlation organizes alerts by the destination (victim) host, enabling focused protection and visibility on high-value assets.

  • Multi-Entity Correlation links alerts across interconnected hosts and actions to form a single case, offering a holistic view of extended or lateral attack campaigns.

This flexibility enables security teams to tailor investigations based on their operational priorities—whether that’s identifying persistently targeted endpoints, tracing threat actor movements, or capturing full-scale intrusion campaigns.

Alert for Suspicious OCI Tenant-to-Tenant Communication

This EAP feature introduces a new alert type that detects cross-tenancy communications in the Oracle Cloud Infrastructure (OCI). By analyzing tenantId fields in audit logs, the feature identifies requests that target resources in a different tenancy. This provides accurate visibility into potentially unauthorized cross-tenancy activity and strengthens oversight in OCI environments.

To join the Early Access Program and begin testing these features, contact your Stellar Cyber Customer Success representative.

Resolved Issues

The following issues have been resolved in this release.

Known Issues