18.2

New Features

Incident Status Workflow

18.2RN Incident-Status-Workflow_New-UI (3).png

Incident status workflows are now configurable under Application Settings > Incident Statuses. Administrators can define allowed next statuses for each incident status, ensuring analysts select only valid transitions during incident handling. The configuration is disabled by default and applies globally when enabled. An incident status cannot be deleted while it is used in the configured status workflow, either as a current status with allowed next statuses, or as an allowed next status for another current status.

Example – Configuring the Incident Status Workflow Anchor

  1. Navigate to the Application Settings module, then select the Incident Statuses setting.

  2. Frame 9 (5).png

    Add a new "Demo Status" status.

    1. Frame 5 (2).png

      Click on the + New Status button.

    2. Enter "Demo Status" in the text input field.

    3. Select a preferred status indicator color.

    4. Click on the Save button.

  3. Add a workflow for both Open and Demo Status.

    1. Frame 6 (2).png

      Click on the Status Workflow tab.

    2. Click on the Restrict transitions toggle.

    3. Click on the + Add status button for the Open system status to add Closed, In Progress, On Hold and Demo Status as the allowed next statuses.

    4. Click on the + Add status button for the Demo Status custom status to add Closed as the allowed next status.

    5. Click on the Save button.

  4. Open an incident workspace for an incident in the Open status.

  5. Click on the Status dropdown menu, verify that the statuses set in step 3c are available in addition to current status, then click on the Demo Status option.

  6. Frame 7 (2).png

    Click on the Status dropdown menu, then verify that only the Closed status set in step 3d appears in addition to the current status.

    Frame 8 (2).png

Site Inheritance

Callout-Composite-Reference (3).png

The User Groups module in the new UI now supports site inheritance, allowing administrators to assign sites to a group so that every member inherits them automatically. Inherited sites appear grayed out in a member's Sites field in the Users module and cannot be removed there. Removing a user from the group removes that inherited access, while removing a site from the group removes it for all members. Sites assigned directly to a user remain unaffected and can still be removed individually.

Adaptive Tasking Module

18.2RN Adaptive-Tasking-Module_New-UI (1).png

An Adaptive Tasking module is now available in the new UI, under the Configuration > Automation section. It offers a dedicated page for centralized management of organizational rules and SOPs. Administrators can create, edit, delete, enable, disable, search, and sort them from one location without opening an incident and issuing in-chat slash commands.

READER NOTE

Access requires the Adaptive Tasking feature flag, Administrator permission, and the AllowAIChat site setting. Reach out to D3 Support for assistance.

Incidents Queue Briefing

Frame 26.png

An AI-generated briefing is now available at the top of the Incidents page in the new UI. Analysts can review inline KPIs or expand the briefing to view charts, metric breakdowns, and a ranked incident-priority list, reducing the need for manual severity counts, SLA reviews, and priority-list scanning. The briefing covers a fixed seven-day window.

Global List Data Source for Reporting Widgets

Frame 1 (3).png

For both the new UI and classic view, Global List, alongside Artifact, Event and Incident, is now available as an additional data source in the Reporting Dashboard > Widgets module. Users can visualize Global List contents with any reporting-widget type.

SOP Skill Generation from Incident Data Through AI

Frame 23 (2).png

SOPs can now be autonomously generated from incidents by AI. Morpheus reviews how an incident was handled, including the investigation, analyst decisions, and actions taken, then converts the workflow into a reusable SOP skill that analysts or Morpheus can run on similar incidents. Analysts can edit the generated SOP in place, scope it as Personal or Shared, and assign it to specific incident types and sites. Incident types and sites are prefilled from the current incident to reduce manual setup.

READER NOTE

Only administrators can create SOPs with the Shared scope.

Morpheus Adaptive Tasking Permission Control

Frame 17 (3).png

Under Configuration > Adaptive Tasking > Permissions, administrators can set organization-wide defaults for the Read and Write action classes. Morpheus can run Always Allow commands but not Blocked commands, with optional site-specific overrides. Each setting applies to all integration and utility commands assigned to that action class. The Tool Classification section lists commands by integration, and shows how many commands fall under each action class.

Site-Level Morpheus AI Chat Access

Frame 18 (4).png

Administrators can now enable or disable Morpheus AI chat for individual sites in the new UI. Disabling the feature hides the chat panel across all incidents in that site without affecting other sites. By default, Morpheus AI chat is disabled for new sites. Existing sites retain their current access after the upgrade.

Configuring Site-Level Morpheus AI Chat Access

  1. Navigate to the Global Settings > Organization Management > Sites module.

  2. Select a site to open its configuration drawer.

  3. Tick or untick the Allow Morpheus AI Chat checkbox.

  4. Click on the Save button.

AI Chart Widget

Frame 21 (2).png

The AI Chart widget is now available in the Reporting Dashboard > Widgets module in both the new UI and classic view. Users can describe the required analysis in natural language, and AI will analyze the queried data and generate a chart with supporting details, reducing manual chart configuration. A Regenerate button is available for refreshing the chart with the latest data.

READER NOTE

Access requires the Feature.ReportingAI.Enabled key. Contact D3 Support for assistance.

Enhancements

New Look for Exported Incident PDF

Frame 16 (3).png

D3 users can now export polished, branded incident reports as multi-page PDFs from the new UI and classic view. Users can select which sections the export includes. Exports use live incident data, site-specific branding, and Morpheus AI-aligned verdict and confidence values.

View Available Incident Report Sections

Rectangle (1).png

Event Details View

Frame 11 (3).png

The event details popover is now available in the new UI from an event's quick-view panel. Users can open it by clicking the View Full Details button. The popover consolidates key event context across dedicated tabs, including event fields and MITRE ATT&CK tactics and techniques in Overview, relationship mapping in Artifact Behavior, related events and incidents in Event/Incident Correlation, raw event data in Event Log, and automated verdict details in APD Disposition. Users can resize the popover by dragging its lower-right corner to the desired dimensions.

AI Query Generation for Reporting Widgets

Frame 19 (1).png

The AI Build Query button is now available when creating or editing queries in the Reporting Dashboard > Widgets module across the new UI and classic view. Users can describe the required data in natural language, and AI will generate the corresponding query, reducing the need to configure filter conditions manually.

READER NOTE

Access requires the Feature.ReportingAI.Enabled key and deployment of the D3 AI microservices and supporting services. Contact D3 Support for assistance.

Incidents View Bar and More Views

Frame 10 (3).png

The Incidents page in the new UI now includes a four-pill view bar above the incident table for Assigned to me, Unassigned, New <24h, and All. System and custom views have been moved to the More views dropdown, located to the right of the view bar. Unassigned incidents created within the last 24 hours are marked with an amber left-side indicator, reducing the need to scan the date column.

Incident Workspace Events Page

Frame 12 (2).png

The incident workspace Events page is now available in the new UI, eliminating the need to use the classic view to review an incident's events. Analysts can review correlated events for the selected incident, examine MITRE ATT&CK tactic and technique coverage in the Event Matrix, and visualize geo-located artifacts in the Map View. The Events page replaces the embedded event tab previously shown in the incident workspace.

UI Modernization

Data Ingestion Configuration Module

Frame 15 (1).png

The Data Ingestion module has been updated with a native Morpheus UI. An AI-assisted chat experience has also been added to guide ingestion configuration through natural language.

Schedules Configuration Module

Frame 14 (2).png

The Schedules module has been updated to align with the modern D3 interface, and support automatic schedule-list refresh.

Connection Configuration

Frame 22 (2).png

The integration connection configuration experience has been redesigned in both the Integrations and Connections modules. Users can now create connections through a guided flow that starts with a searchable integration picker, followed by general settings and account credentials.

View All Connection Configuration UI Changes

  • Guided configuration flow replaced the single, scrollable form.

  • Searchable integration picker was added as the first step.

  • Separate General Settings and Account Credentials steps were introduced.

  • Integration selection was locked after the integration was chosen.

  • General Settings grouping was added for the connection name, description, activation status, site selection, site cloning, agent selection, tenant-site sharing, and permissions.

  • Site-cloning dropdown was added beneath the Site field, replacing the Select Sites to Clone button.

  • Tenant Sites setting with supporting explanatory text replaced the Tenant toggle.

  • Proxy-agent dropdown replaced the Agent Name text field.

  • An About Agents information panel was added.

  • Access summary with an adjacent Configure action replaced the standalone Configure Permissions button.

  • The Account Credentials step was added for credential fields.

  • Separate Manual Input and Password Vault credential methods were introduced.

  • Enable recurring connection testing setting replaced Connection Health Check.

  • Dedicated connection-verification section was added.

  • Inline connection-test status was added within the credentials step.

  • Continue and Submit buttons replaced Save.

  • Back navigation was added between configuration steps.

Global List Module

Frame 25.png

The Global List module has been updated to align with the modern D3 interface. Batch JSON uploads and improved loading behavior have also been implemented.

Webhook Credentials Mapping

Third-party systems that support only username-and-password authentication can now connect to D3 webhooks by using existing D3 API keys or JWTs.

Connection Configuration

To configure the connection, retrieve the API key or JWT from the command's Webhook Authentication settings, enter d3key or d3jwt as the username, and enter the corresponding request header value as the password.

Bulk Incident Field Editing

Bulk-Field-Editing-Context — F3F5F7 (3).png
View Drawer

Bulk-Field-Editing-Drawer — F3F5F7 (2).png

Bulk incident-field editing is now available on the Incidents dashboard in the new UI. Analysts can select multiple incidents and update up to 11 fields at once via the Edit Fields drawer. The drawer displays only fields the user has permission to edit. After clicking the Review changes button, a partial-result message appears when one or more incidents cannot be updated and provides the reason for each failure.

Utility Commands

Updated Commands

The following utility commands were updated in this release.

Commands

Changes



Create Site

The Create Site utility command in the classic view now supports syncing configuration to a newly created site. Administrators, or users with the Access Privileged Commands permission, can publish all live master incident playbooks and share all active master global lists while creating the site, removing the need to add each playbook and list by hand afterward. User syncing has been removed; new-site access is managed through roles.


Generate AI Summary

Generate AI Summary now reliably processes large, complex incidents by auto-condensing high-volume event and command data before analysis. Incidents that previously exceeded processing limits can now return complete summaries.

Integrations

New Integrations

The following integrations were added in this release.

Integration Name

Description



Microsoft Defender for Identity

Microsoft Defender for Identity (MDI) is a cloud-based identity threat detection and response service that monitors on-premises Active Directory and hybrid identities for compromise and lateral movement. It surfaces a unified view of identities across Active Directory, Entra ID, and Okta, and supports response actions on on-premises Active Directory accounts.



FortiMail Workspace Security 

FortiMail Workspace Security, formerly Perception Point, is an email security service that detects and remediates malicious email, file, and URL threats across workspace collaboration channels. It scans content with multiple detection engines, exposes scan verdicts for ingestion, manages allow and block lists, and supports response actions such as changing a scan verdict and submitting files and URLs for analysis.



Cribl Search 

Cribl Search is a vendor-hosted observability search platform that runs Kusto-style (KQL-based) queries across data ingested into Cribl Cloud - Cribl Lake datasets, Cribl Edge fleets, Amazon S3 sources, and other configured providers. It returns NDJSON event results suitable for downstream automation and analytics. 

Updated Integrations

The following integrations were updated in this release.

Integration Name

Changes




Microsoft Purview eDiscovery V2

New Commands

  • List Case Operations 

  • List Case Searches 

  • Get Operation Status 

  • Initiate Purge Emails

Deprecated Command

  • PurgeEmails





Cynet 360 AutoXDR

New Commands

  • Fetch Event 

  • Get Host Details 

  • Unisolate Hosts

  • Isolate Hosts 

  • Quarantine Files 

  • Update Alert Status 

  • Get Network Sockets In Date Range 

  • Get File Info

  • Get Remediation Status

  • Block Network Traffic

  • Run Command on Host






Splunk V2

This update enables searches and saved searches within a specified Splunk app rather than only the default Search app. It adds the App Context option to supported search commands and introduces the List Saved Searches command for discovering available saved searches.

New Command

  • List Saved Searches

Enhanced Commands

  • Search

  • Start Search

  • Get Search Status

  • Get Search Result

Azure Sentinel

Connection can support different Microsoft cloud environments: Commercial, GCC, GCC High, DoD 

Microsoft Defender for Endpoint


Microsoft 365 Defender (Email & collaboration)

Updated the ExchangeOnlineManagement PowerShell module to version 3.9.2.

Deprecated Command

  • PreviewComplianceSearchResult

Perception Point 

Deprecated the integration. Use the FortiMail Workspace Security integration instead.