New Features
Incident Status Workflow
Incident status workflows are now configurable under Application Settings > Incident Statuses. Administrators can define allowed next statuses for each incident status, ensuring analysts select only valid transitions during incident handling. The configuration is disabled by default and applies globally when enabled. An incident status cannot be deleted while it is used in the configured status workflow, either as a current status with allowed next statuses, or as an allowed next status for another current status.
Site Inheritance
The User Groups module in the new UI now supports site inheritance, allowing administrators to assign sites to a group so that every member inherits them automatically. Inherited sites appear grayed out in a member's Sites field in the Users module and cannot be removed there. Removing a user from the group removes that inherited access, while removing a site from the group removes it for all members. Sites assigned directly to a user remain unaffected and can still be removed individually.
Adaptive Tasking Module
An Adaptive Tasking module is now available in the new UI, under the Configuration > Automation section. It offers a dedicated page for centralized management of organizational rules and SOPs. Administrators can create, edit, delete, enable, disable, search, and sort them from one location without opening an incident and issuing in-chat slash commands.
READER NOTE
Access requires the Adaptive Tasking feature flag, Administrator permission, and the AllowAIChat site setting. Reach out to D3 Support for assistance.
Incidents Queue Briefing
An AI-generated briefing is now available at the top of the Incidents page in the new UI. Analysts can review inline KPIs or expand the briefing to view charts, metric breakdowns, and a ranked incident-priority list, reducing the need for manual severity counts, SLA reviews, and priority-list scanning. The briefing covers a fixed seven-day window.
Global List Data Source for Reporting Widgets
For both the new UI and classic view, Global List, alongside Artifact, Event and Incident, is now available as an additional data source in the Reporting Dashboard > Widgets module. Users can visualize Global List contents with any reporting-widget type.
SOP Skill Generation from Incident Data Through AI
SOPs can now be autonomously generated from incidents by AI. Morpheus reviews how an incident was handled, including the investigation, analyst decisions, and actions taken, then converts the workflow into a reusable SOP skill that analysts or Morpheus can run on similar incidents. Analysts can edit the generated SOP in place, scope it as Personal or Shared, and assign it to specific incident types and sites. Incident types and sites are prefilled from the current incident to reduce manual setup.
READER NOTE
Only administrators can create SOPs with the Shared scope.
Morpheus Adaptive Tasking Permission Control
Under Configuration > Adaptive Tasking > Permissions, administrators can set organization-wide defaults for the Read and Write action classes. Morpheus can run Always Allow commands but not Blocked commands, with optional site-specific overrides. Each setting applies to all integration and utility commands assigned to that action class. The Tool Classification section lists commands by integration, and shows how many commands fall under each action class.
Site-Level Morpheus AI Chat Access
Administrators can now enable or disable Morpheus AI chat for individual sites in the new UI. Disabling the feature hides the chat panel across all incidents in that site without affecting other sites. By default, Morpheus AI chat is disabled for new sites. Existing sites retain their current access after the upgrade.
AI Chart Widget
The AI Chart widget is now available in the Reporting Dashboard > Widgets module in both the new UI and classic view. Users can describe the required analysis in natural language, and AI will analyze the queried data and generate a chart with supporting details, reducing manual chart configuration. A Regenerate button is available for refreshing the chart with the latest data.
READER NOTE
Access requires the Feature.ReportingAI.Enabled key. Contact D3 Support for assistance.
Enhancements
New Look for Exported Incident PDF
D3 users can now export polished, branded incident reports as multi-page PDFs from the new UI and classic view. Users can select which sections the export includes. Exports use live incident data, site-specific branding, and Morpheus AI-aligned verdict and confidence values.
Event Details View
The event details popover is now available in the new UI from an event's quick-view panel. Users can open it by clicking the View Full Details button. The popover consolidates key event context across dedicated tabs, including event fields and MITRE ATT&CK tactics and techniques in Overview, relationship mapping in Artifact Behavior, related events and incidents in Event/Incident Correlation, raw event data in Event Log, and automated verdict details in APD Disposition. Users can resize the popover by dragging its lower-right corner to the desired dimensions.
AI Query Generation for Reporting Widgets
The AI Build Query button is now available when creating or editing queries in the Reporting Dashboard > Widgets module across the new UI and classic view. Users can describe the required data in natural language, and AI will generate the corresponding query, reducing the need to configure filter conditions manually.
READER NOTE
Access requires the Feature.ReportingAI.Enabled key and deployment of the D3 AI microservices and supporting services. Contact D3 Support for assistance.
Incidents View Bar and More Views
The Incidents page in the new UI now includes a four-pill view bar above the incident table for Assigned to me, Unassigned, New <24h, and All. System and custom views have been moved to the More views dropdown, located to the right of the view bar. Unassigned incidents created within the last 24 hours are marked with an amber left-side indicator, reducing the need to scan the date column.
Incident Workspace Events Page
The incident workspace Events page is now available in the new UI, eliminating the need to use the classic view to review an incident's events. Analysts can review correlated events for the selected incident, examine MITRE ATT&CK tactic and technique coverage in the Event Matrix, and visualize geo-located artifacts in the Map View. The Events page replaces the embedded event tab previously shown in the incident workspace.
UI Modernization
Data Ingestion Configuration Module
The Data Ingestion module has been updated with a native Morpheus UI. An AI-assisted chat experience has also been added to guide ingestion configuration through natural language.
Schedules Configuration Module
The Schedules module has been updated to align with the modern D3 interface, and support automatic schedule-list refresh.
Connection Configuration
The integration connection configuration experience has been redesigned in both the Integrations and Connections modules. Users can now create connections through a guided flow that starts with a searchable integration picker, followed by general settings and account credentials.
Global List Module
The Global List module has been updated to align with the modern D3 interface. Batch JSON uploads and improved loading behavior have also been implemented.
Webhook Credentials Mapping
Third-party systems that support only username-and-password authentication can now connect to D3 webhooks by using existing D3 API keys or JWTs.
Bulk Incident Field Editing
Bulk incident-field editing is now available on the Incidents dashboard in the new UI. Analysts can select multiple incidents and update up to 11 fields at once via the Edit Fields drawer. The drawer displays only fields the user has permission to edit. After clicking the Review changes button, a partial-result message appears when one or more incidents cannot be updated and provides the reason for each failure.
Utility Commands
Updated Commands
The following utility commands were updated in this release.
|
Commands |
Changes |
|
Create Site |
The Create Site utility command in the classic view now supports syncing configuration to a newly created site. Administrators, or users with the Access Privileged Commands permission, can publish all live master incident playbooks and share all active master global lists while creating the site, removing the need to add each playbook and list by hand afterward. User syncing has been removed; new-site access is managed through roles. |
|
Generate AI Summary |
Generate AI Summary now reliably processes large, complex incidents by auto-condensing high-volume event and command data before analysis. Incidents that previously exceeded processing limits can now return complete summaries. |
Integrations
New Integrations
The following integrations were added in this release.
|
Integration Name |
Description |
|
Microsoft Defender for Identity |
Microsoft Defender for Identity (MDI) is a cloud-based identity threat detection and response service that monitors on-premises Active Directory and hybrid identities for compromise and lateral movement. It surfaces a unified view of identities across Active Directory, Entra ID, and Okta, and supports response actions on on-premises Active Directory accounts. |
|
FortiMail Workspace Security |
FortiMail Workspace Security, formerly Perception Point, is an email security service that detects and remediates malicious email, file, and URL threats across workspace collaboration channels. It scans content with multiple detection engines, exposes scan verdicts for ingestion, manages allow and block lists, and supports response actions such as changing a scan verdict and submitting files and URLs for analysis. |
|
Cribl Search |
Cribl Search is a vendor-hosted observability search platform that runs Kusto-style (KQL-based) queries across data ingested into Cribl Cloud - Cribl Lake datasets, Cribl Edge fleets, Amazon S3 sources, and other configured providers. It returns NDJSON event results suitable for downstream automation and analytics. |
Updated Integrations
The following integrations were updated in this release.
|
Integration Name |
Changes |
|
Microsoft Purview eDiscovery V2 |
New Commands
Deprecated Command
|
|
Cynet 360 AutoXDR |
New Commands
|
|
Splunk V2 |
This update enables searches and saved searches within a specified Splunk app rather than only the default Search app. It adds the App Context option to supported search commands and introduces the List Saved Searches command for discovering available saved searches. New Command
Enhanced Commands
|
|
Azure Sentinel |
Connection can support different Microsoft cloud environments: Commercial, GCC, GCC High, DoD |
|
Microsoft Defender for Endpoint |
|
|
Microsoft 365 Defender (Email & collaboration) |
Updated the ExchangeOnlineManagement PowerShell module to version 3.9.2. Deprecated Command
|
|
Perception Point |
Deprecated the integration. Use the FortiMail Workspace Security integration instead. |