About a month ago, we published Mellifera 12 which brought numerous features such as mini-reports on the observable page, custom fields, alert similarity or template selection during alert imports.
Great, palatable recipes, even if they are cooked by fine French chefs, need to be refined over time and may not be as savoury as intended when they are served in their early days. Quality takes time, although smokeware vendors would have you think otherwise.
Mellifera 12.1 (TheHive 2.12.1) has been released to fix a number of outstanding bugs:
- #249: renaming of users does not work
- #254: TheHive does not send the file’s name when communicating with Cortex
- #255: merging an alert into an existing case does not merge the alert description into the case’s description
- #257: while TheHive does not let you add multiple attachments to a single task log, the UI makes you believe otherwise
- #259: fix an API inconsistency.
GET /api/case/task/:id/loghas been fixed.
And a new API call
POST /api/case/task/:taskId/log/_searchhas been added, which accepts a “query” in the request body to filter logs of the task.
- #268: cannot create an alert if the IOC field is set for a single alert’s attribute.
- #269: closing a case with an open task does not dismiss it from ‘My Tasks’.
This new minor release adds the following enhancements:
- #267: fix warnings in the DEB package.
- #272: in alert preview, similar cases are shown regardless of their status. Merged or deleted ones should not appear in that list.
How About the Test VM?
The test VM has not been updated yet. It still contains Mellifera 12 (TheHive 2.12.0). We will update it in September, probably when Mellifera 13 is released. That version will bring the ability to export cases as MISP events.
Download & Get Down to Work
If you have an existing installation of TheHive, please follow the migration guide.
If you are performing a fresh installation, read the installation guide corresponding to your needs and enjoy. Please note that you can install TheHive using an RPM or DEB package, use Docker, install it from a binary or build it from sources.
Something does not work as expected? You have troubles installing or upgrading? No worries, please join our user forum, contact us on Gitter, or send us an email at email@example.com. We are here to help.