Skip to content

SenseOn Platform: Dec 2025

Log sources have their own Custom log sources tab on the Integrations page, and Hunt Lab shows JSON fields in a tidy, collapsible view that makes log data much easier to read. Investigate now lists MITRE ATT&CK techniques for the whole case and for each observation, and shows the case status in the case overview. Observation notes, search results in Experience and setting badges on Device Configuration are all clearer to read.

What's new

  • Log Ingestion: your log sources move to a dedicated Custom log sources tab on the Integrations page, separate from your Data Connectors. If you don't use log ingestion yet, contact SenseOn to request access.
  • Hunt Lab: JSON fields in query results are shown in a formatted view that you can expand and collapse. Click a key or value to copy it.
  • Investigate: the case overview lists the MITRE ATT&CK techniques seen across the case, and selecting an observation lists its own techniques in the observation details. Each technique heading starts with its technique code.
  • Investigate: the case overview shows a badge with the case's current status.

What's improved

  • Hunt Lab: Tidy formats more query styles, including queries that start with placeholders followed by a WITH clause.
  • Investigate: observation notes keep their line breaks and highlight inline code, such as hostnames and commands, so they are easier to read.
  • Experience: when you search, the matching row is highlighted and the matching value is shown beside the entity's name, so you can see why a result matched.
  • Experience: the case details that open from an observation's Seen in case list have a cleaner layout, with the case score, flag and title aligned and a tooltip for long titles.
  • Case management panel: on narrow screens the panel takes up less room, and on phone-sized screens it opens full width with a back button.
  • Device Configuration: settings on each segment use clear badges. Settings that are off are shown in yellow, a dot marks settings changed from the default, and settings that aren't enabled for your organisation, such as Antimalware, are shown in grey with a padlock. Contact SenseOn to request access.
  • Data Connectors: the details window for each connection and log source shows its status in the same table as the rest of its details.
  • Data Connectors: if Entra ID User Containment isn't set up, the user details panel now says so, instead of reporting that no user was found.
  • Expandable sections: sections such as third-party device data, threat techniques and the response overview expand in the same way everywhere, and you can click the title to expand them.
  • Knowledge Graph: selecting a node is more reliable, even if your mouse moves slightly as you click.

This round-up covers SenseOn Platform 5.1 and 5.2.