Software Release Date: June 25, 2026
Release Note Updated: July 30, 2026
The Stellar Cyber 6.6.0s release delivers the following updates to the Stellar Cyber Open XDR platform.
Highlights
Autonomous SOC / Auto Triage
- AI Assistant (Early Access Program): Added AI Assistant to every automatically triaged case so you can investigate cases and alerts in plain language, asking why a case received its verdict, clarifying alert details, and exploring follow-up hypotheses against the case data and Verdict Signal Check (VSC) context that Auto Triage has already assembled.
- Auto Triage Verdict Visibility: Auto Triage verdicts now appear as filterable columns in the Alert Table and Threat Hunting views. In addition, a response action panel was added to the Auto Triage alert page (including phishing email alerts) so analysts can see and act on triage outcomes without opening individual cases.
System / Platform
- Platform Health Monitoring in the System Action Center (Early Access Program): Centralized platform health monitoring alerts in the System Action Center for improved visibility and faster response to platform issues.
- License Enforcement and Usage Notifications: Added API actions for license enforcement and usage notifications.
Detections/Machine Learning
- Improved Login Anomaly Fidelity: Alert suppression for Impossible Travel Anomaly and User Login Location Anomaly is now customizable, Impossible Travel prioritizes records with usernames, and ASN enrichment fields were added to Impossible Travel Anomaly alerts.
- Improved User Counting Accuracy: Improved the accuracy of license user counting by integrating external data sources for Microsoft Entra ID.
Integrations
- New Integrations: Added Liongard integration for cyber asset attack surface management, the Ironscales connector for incident ingestion, Idira (formerly CyberArk) Privilege Cloud for audit events, and response actions for Check Point Smart-1 Cloud Management.
Usability
- Watchlists for All Alert Fields: Enabled Add to Watchlist for all alert fields.
- Selective Parser Port Activation: Parser ingestion ports can now be enabled on-demand and parsers added after 6.5.0 are inactive by default, reducing false alerts from unused listeners.
Actions Required
There are no actions required in this release.
Behavior Changes - Changes that affect the way users interact with the product or interpret results are as listed:
- DATA-3412: The totalbytes field in the Fortinet FortiAnalyzer parser is now calculated as the sum of inbytes_total and outbytes_total, consistent with how other parsers calculate this field. Previously, the FortiAnalyzer parser calculated totalbytes as the sum of inbytes_delta and outbytes_delta, which significantly underreported session volume when delta values differed from totals. Dashboards, detections, or queries that rely on totalbytes from FortiAnalyzer data may return different values after this change.
- AELDEV-71104: Built-in legacy parsers added in 6.5.0 and later releases are now inactive by default for new tenants and must be explicitly activated in Parser Studio before use. Previously added legacy parsers retain their existing active status and are not affected by this change. You can activate or deactivate any individual parser at any time from Parser Studio, and the configuration is applied to sensors on the next deployment.
- AELDEV-64683: The Google Workspace log collector no longer maps the metadata.customerId field to user.id. The customerId value is a Google account identifier for the organization, not a user identifier, so this mapping was incorrect and caused confusion in alert context. Existing events already indexed with this normalization are not affected. Newly ingested Google Workspace events no longer populate user.id from this field.
Deprecated Features
The following feature is planned for deprecation in a future version.
Upcoming Deprecation: SentinelOne Deep Visibility API – The Deep Visibility content type in the SentinelOne connector will be migrated to Deep Visibility (SDL) in a future version due to a SentinelOne API being deprecated.
Autonomous SOC - Improvements
ASOC-142: Added Auto Triage verdict columns to the Alert Table and Threat Hunting views.
Detection/ML - Improvements
AELDEV-68980: Improved External/Internal Suspected SQL Injection alert types.
AELDEV-68304: Updated the User Login Location Anomaly to prioritize login records that include a username.
AELDEV-68301: Added ASN enrichment fields to Impossible Travel Anomaly.
AELDEV-67315: Added more alert integrations through Microsoft's Graph Security API.
AELDEV-61011: Improved user counting accuracy for Microsoft Entra ID environments.
AELDEV-59125: Added alert suppression options for Impossible Travel and User Login Location anomalies.
Stellar Cyber Platform - New Features
AELDEV-68802: Added detailed condition evaluation reasons for array comparisons.
AELDEV-66618: Enabled OpenAPI 3.1 specification generation for the Auto Triage API.
AELDEV-66617: Enabled OpenAPI 3.1 specification output for API documentation.
AELDEV-62965: Implemented API actions for license enforcement and usage notifications.
Stellar Cyber Platform - Improvements
AELDEV-69894: Updated the log collection agent on Modular Sensors to version 1.1.2.
AELDEV-69635: Updated timestamps in Last Scheduled Run and Last Manual Run to reflect actual execution times.
AELDEV-62593: Clarified system diagnostics availability in Report | Observability dashboards.
Sensors - New Features
AELDEV-71145: Added Fedora Linux 40 support for the Linux Server Sensor.
AELDEV-70754: Added Oracle Linux 10 support for the Linux Server Sensor.
Sensors - Improvements
AELDEV-68328: Updated the DPI protocol bundle to version 1.830.0-21 for enhanced traffic analysis.
AELDEV-64505: Upgraded Suricata to version 8.0.1 to address multiple vulnerabilities.
AELDEV-58588: Secured UDP socket communications in local services to prevent unauthorized access.
Connectors - New Features
AELDEV-71556: Introduced the Idira (formerly CyberArk) Privilege Cloud connector.
AELDEV-61583: Introduced the Check Point Smart-1 Cloud connector.
AELDEV-61569: Introduced the Liongard connector.
AELDEV-46279: Introduced the Ironscales connector.
Connectors - Improvements
AELDEV-69891: Huntress connector fix for mapping exception.
AELDEV-69470: Implemented mapping of azure_ad.ipAddress to src_ip in Service Principal Sign-in Logs.
AELDEV-69160: Mapped the Structured Azure Firewall Log content type to the Traffic index.
AELDEV-68502: Added a query_window_start field to Microsoft Office 365 connector events.
AELDEV-68427: The srcip field is now populated in Palo Alto Networks CORTEX XDR endpoint events.
AELDEV-66221: Enhanced the OCI connector to normalize Apache logs streamed via the OCI log stream.
AELDEV-65062: Upgraded OAuth library for the Sophos Central connector to support the Sophos API.
AELDEV-64683: Removed an incorrect user id mapping for Google Workspace events.
AELDEV-52408: Added API Token authentication for the Universal Webhook Responder.
Parsers - New Features
DATA-3472: Introduced a parser for ingesting Radware WAF logs.
DATA-3464: Introduced a parser for ingesting ManageEngine Endpoint Central logs.
DATA-3453: Introduced a parser for ingesting Safetica Data Loss Prevention logs.
DATA-3447: Introduced a parser for ingesting ONV Switch logs.
DATA-3445: Introduced a parser for ingesting Oracle Audit Trail logs.
DATA-3438: Introduced a parser for ingesting Forcepoint Web Security logs.
DATA-3431: Introduced a parser for ingesting Trend Micro Worry-Free Business Security Service logs.
DATA-3425: Introduced a parser for ingesting Avaya IP Office logs.
DATA-3409: Introduced a parser for ingesting Cowrie SSH/Telnet Honeypot logs.
DATA-3398: Introduced a parser for ingesting Kaspersky Secure Mail Gateway logs.
DATA-3373: Introduced a parser for ingesting Fudo Privileged Access Management logs.
DATA-3372: Introduced a parser for ingesting Ubika Web Application Firewall logs.
Parsers - Improvements
DATA-3494: Expanded ATH calculation support for the Fortinet FortiWeb parser.
DATA-3489: Updated the Microsoft IIS parser to support an extended log field set.
DATA-3463: Improved Citrix ADC login failure event parsing.
DATA-3456: Expanded A10 vThunder ADC parser support for additional syslog traffic log formats..
DATA-3451: Updated the Cisco ACI parser to support additional syslog header formats and event messages.
DATA-3449: Updated the Arbor Peakflow SP parser to support additional syslog header formats and event message patterns.
DATA-3439: Added Snort intrusion event log support to the KVH CommBox Edge Gateway parser.
DATA-3437: Moved fields from msg_data to the vendor field in the Fortinet FortiAnalyzer parser.
DATA-3427: Improved FortiWeb CEF field mapping in the Common Event Format (CEF) parser.
DATA-3420: Added RFC3164 syslog support to the Penta Security WAPPLES parser.
DATA-3413: Moved the bssid field to the vendor field for the Fortinet FortiGate parser.
DATA-3391: Updated the VMware ESXi parser to extract additional authentication event fields.
DATA-3371: Added BSD syslog format support for the Citrix ADC parser.
DATA-3365: Enhanced Efficient IP parser to prevent potential BufferOverflow issues.
DATA-3355: Added JSON-over-HTTP Kubernetes log support to the HTTP Google Kubernetes Engine parser.
DATA-3351: Added blocked-host threat log support to the Arbor Peakflow SP parser.
AELDEV-72115: Added a required field validation message for the Custom Namespace field in Parser Studio.
AELDEV-72105: Added Raw Log Capture support for modular parsers in Parser Studio.
AELDEV-71516: Removed the HTTP JSON parser from Parser Studio.
AELDEV-71104: Set new built-in parsers added in 6.5.0 and later to inactive by default.
AELDEV-70853: Updated the CLI command to show readable names for modular parser activity counters.
AELDEV-68064: Updated the Parser Studio UI to support enabling parser ports on demand.
AELDEV-67224: Added input and output record counters for modular parsers, reported through the CLI.
AELDEV-66922: Added automatic and manual timestamp normalization options in Parser Studio.
AELDEV-56360: Enabled selective parser port activation to reduce false alerts.
Usability - New Features
AELDEV-68843: Fixed an issue that caused manually triggered rules to be incorrectly marked as inactive failures.
AELDEV-68524: Added new platform health alerts to the System Action Center.
AELDEV-65225: Enabled Add to Watchlist for all alert fields.
AELDEV-64450: Added a filtered JSON attachment to ATH calculation rule alert notifications.
AELDEV-57363: Updated auto-triaged alert details with a redesigned view.
AELDEV-53674: Added a response action panel on the Auto Triage alert page.
Usability - Improvements
AELDEV-72095: Added new PDF export options to the Exported Dashboards schedule form.
AELDEV-72021: Updated the Dashboard Share dialog to use tenant and tenant group badges.
AELDEV-71898: Improved feedback for time series visualization widgets in dashboards when a data volume limit is reached.
AELDEV-67591: Updated the Case Detail page to preserve existing functionality in a redesigned experience.
AELDEV-67377: Added quick filters for enriched and non-enriched fields in alert details.
Early Access Program
If you're interested in testing out new features ahead of general availability, consider joining the Early Access Program (EAP) by contacting us at info@cspglobal.com as your Stellar Cyber Customer Success representative and tell us which EAP feature you want to test. Once you've agreed to the EAP terms and signed up, the EAP feature is unlocked for you.
The purpose of this program is to boost performance and reliability through real-world customer insights, giving you a hands-on role in shaping a Stellar Cyber feature. In return, you'll receive early access to upcoming releases and the chance to guide product development.
The following EAP features are in this release:
AI Assistant
AI Assistant is a natural-language investigation workbench built into every automatically triaged case. It converts your plain-language questions into answers grounded in the specific case data, alert details, and Verdict Signal Check (VSC) context that Auto Triage has already gathered. While the automated verdict tells you what Stellar Cyber concluded, AI Assistant explains why, and it supports follow-up questions in your own words, with no query syntax to learn. AI Assistant is included with every Auto Triage license at no additional cost and is available on SaaS deployments only.
Exportable Dashboards — Report Integration
Exportable Dashboards lets you schedule dashboards created with the Dashboard Builder as recurring PDF reports. The schedule form includes a new Default PDF type that renders the dashboard as it appears in the Dashboard Builder, along with options to control table row counts, chart color palettes, and optional CSV exports. This capability lets you generate consistent, configurable reports from new dashboards while preserving the settings and PDF types used by existing scheduled reports.
MCP Server
The Stellar Cyber MCP Server connects supported AI clients to the Stellar Cyber Platform through the Model Context Protocol (MCP). The MCP server lets AI clients retrieve case and alert data, review investigation context, perform tenant-aware operations, and update selected case fields. This capability helps teams extend AI-assisted investigations by giving approved clients structured access to operational security data and workflows.
Parser Studio
Parser Studio lets you create and manage custom log parsers for data ingestion by cloning existing parsers, testing parser behavior before deployment, and activating parsers for production use. This capability helps you accelerate onboarding of custom log sources while reducing parser development effort and improving validation before live ingestion.
XDR Connector Webhook Ingestion
This is a simple webhook framework that lets you post JSON data directly from any external system into Stellar Cyber, accelerating custom integrations and expanding your visibility across the entire security stack. The XDR Connector is in Public Preview in this release.
Customizable Case Correlation Strategies
This EAP feature introduces support for multiple case correlation strategies, allowing teams to evaluate and experiment with different approaches to grouping alerts into cases. Each strategy provides a distinct investigative perspective:
- Attacker-Centric Correlation groups alerts by the source (attacker) host, making it easier to track adversary behavior across multiple targets.
- Victim-Centric Correlation organizes alerts by the destination (victim) host, enabling focused protection and visibility on high-value assets.
- Multi-Entity Correlation links alerts across interconnected hosts and actions to form a single case, offering a holistic view of extended or lateral attack campaigns.
This flexibility enables security teams to tailor investigations based on their operational priorities—whether that’s identifying persistently targeted endpoints, tracing threat actor movements, or capturing full-scale intrusion campaigns.
Alert for Suspicious OCI Tenant-to-Tenant Communication
This EAP feature introduces a new alert type that detects cross-tenancy communications in the Oracle Cloud Infrastructure (OCI). By analyzing tenantId fields in audit logs, the feature identifies requests that target resources in a different tenancy. This provides accurate visibility into potentially unauthorized cross-tenancy activity and strengthens oversight in OCI environments.
To join the Early Access Program and begin testing these features, contact us at info@cspglobal.com as your Stellar Cyber Customer Success representative.
Resolved Issues
The following issues have been resolved in this release.
DATA-3313: Fixed an issue that caused the CEF parser to drop user agent information from Check Point logs.
DATA-3312: Resolved incorrect quote handling by the Netscaler parser.
AELDEV-70897: Resolved security vulnerabilities in the Stellar Cyber CLI that allowed privilege escalation.
AELDEV-70855: Fixed an issue that caused Windows Server Sensor uninstall tasks to remain stuck in progress.
AELDEV-70728: Fixed issues that left residual files and incorrect package status after uninstalling a Linux Server Sensor.
AELDEV-70629: Fixed an issue that caused sensor upgrades to stall indefinitely on Modular Sensors running Ubuntu 22.04.
AELDEV-70608: Fixed an issue that caused support sessions to close uncleanly when an elevated shell was open.
AELDEV-70360: Resolved a security vulnerability in the PackageKit component on Ubuntu 22.04 sensors.
AELDEV-70298: Fixed an issue that caused file inspection on Modular Sensors to stop capturing traffic.
AELDEV-70296: Fixed a missing CLI command for viewing the external syslog server on Modular Sensors.
AELDEV-70247: Fixed an issue that caused deleted InSync configurations to remain visible on the Alerts page.
AELDEV-70104: Fixed a file inspection issue with back-to-back NFSv3 transfers.
AELDEV-69759: Fixed a memory issue that caused repeated crashes on memory-constrained sensors.
AELDEV-69389: Corrected an issue that prevented typed tags from being applied in bulk case actions.
AELDEV-69116: Improved Modular Sensor stability and throughput under high traffic loads.
AELDEV-68933: Fixed an issue that caused the Cases API to stop responding when retrieving case data.
AELDEV-68926: Fixed a data placement issue for tenant indices created during high-volume onboarding.
AELDEV-64142: Removed malware upload commands from sensor types that do not support malware detection.
AELDEV-63142: Fixed runtime handling of new log filters in the connector for Azure Event Hub.
AELDEV-57819: Fixed an installation error on Amazon Linux 2023 that produced a spurious error message.
Known Issues
AELDEV-72543: Some migrated dashboards might require a manual layout adjustment after conversion to the new dashboard framework.
New features, updated ML algorithms, and enhanced configurations may change ingestion and detection patterns. We recommend the following to ensure a smooth upgrade:
- Upgrade sensors with the Sandbox and IDS features enabled before sensors with the only the Network Traffic feature enabled. Sensors with Network Traffic enabled send data to sensors with Sandbox and IDS enabled for additional processing.
- Upgrade sensors in batches instead of all at once.
-
For server sensors (agents):
- Upgrade a small set of sensors that cover non-critical assets.
- After 24 hours, ensure that your ingestion is as expected, then upgrade a larger set.
- After 24 hours, ensure that your ingestion is as expected, then upgrade the remaining server sensors.
Upgrading Sensors
Depending on the type of server sensor, you can upgrade your sensors directly to version 6.6.0 from these previous versions:
- Linux Server Sensors: 6.4.0 or 6.5.0
- Windows Server Sensors: 5.1.0 through 6.5.0
Upgrade the sensors to version 6.6.0 using the following process:
- Prepare for the upgrade.
- Upgrade the sensors.
- Verify the upgrade.
About Sensor Release Timing
Sensor upgrade packages release a few weeks after the corresponding DP release. Staggering the releases helps Stellar Cyber confirm whether any issues found after a DP upgrade come from the DP or the sensor and fix critical bugs before the new sensor is released.
If a sensor upgrade link in the docs doesn't resolve yet, the package simply isn't available yet — check back in a few weeks!
Prepare for the Upgrade
To prepare for the upgrade:
- Make sure the sensors are up and running
- Take note of the ingestion rate for the sensors to be upgraded in the Sensor Details page
- Make sure the system health indicators in the Sensor Details page all show green.
Upgrade the Sensors
New features, updated ML algorithms, and enhanced configurations may change ingestion and detection patterns. We recommend the following to ensure a smooth upgrade:
- Upgrade sensors with the Sandbox and IDS features enabled before sensors with the only the Network Traffic feature enabled. Sensors with Network Traffic enabled send data to sensors with Sandbox and IDS enabled for additional processing.
- Upgrade sensors in batches instead of all at once.
-
For server sensors (agents):
Upgrade a small set of sensors that cover non-critical assets.
After 24 hours, ensure that your ingestion is as expected, then upgrade a larger set.
After 24 hours, ensure that your ingestion is as expected, then upgrade the remaining server sensors.
CentOS 7.1 Prerequisite – Update curl to 7.29.0-59.el7_9.2 or Higher
Before upgrading any Linux Server Sensors running in CentOS 7.1, you must check your curl version and update it to 7.29.0-59.el7_9.2 or higher to use the strong encryption required by the Stellar Cyber Platform.
- Check your curl version as shown below:
yum list installed curl
\* Loaded plugins: fastestmirror Loading mirror speeds from cached hostfile Installed Packages curl.x86_64 7.29.0-19.el7
- If the listed version is lower than 7.29.0-59.el7_9.2 (as it is in the example above), use the following commands to update the curl package:
yum makecache
yum install curl
- If installation of the curl package fails, it is most likely because CentOS is trying to use a repo that has reached its end of life. Try updating the base URL and then reinstall curl. The following sed command makes the necessary changes for most environments to ensure that the updated curl package can be installed:
sudo sed -i.bak -e 's|^mirrorlist=|#mirrorlist=|' -e 's|^#baseurl=http://mirror.centos.org/centos/\$releasever|baseurl=http://archive.kernel.org/centos-vault/7.9.2009|' /etc/yum.repos.d/CentOS-Base.repo
To upgrade sensors:
You can upgrade a sensor to the most recent release from the two previous releases. This means that you can upgrade a sensor to the 6.6.0 release from any 6.4.x or 6.5.x release.
If you are upgrading a Windows Server Sensor, complete any pending updates for the host Windows machine before upgrading the Server Sensor.
- Select System | DATA SOURCE MANAGEMENT | Sensors | Sensors. | The Sensor List appears.
- Select Manage | Software Upgrade. | The Sensor Software Upgrade page appears.
- Choose the target software version.
- Choose the target sensors.
- Select Submit.
Verify the Upgrade
To verify that the upgrade was successful:
- Check the Software Version in the Sensor List.
- Check the Sensor Status LED in the Sensor List.
- Check the ingestion rate in the Sensor Details page for upgraded sensors and make sure it is as expected.