What's New in Port0: Detector Studio, Deeper Fusion, Faster Answers

Smarter detections, better workflows, and more ways to accelerate your SOC.

A glowing network of connected app tiles

This release cycle had one theme: shortening the distance between a question and a defensible answer. Detector Studio gets new ways to build, Soc0 gets deeper evidence trails, and the fabric gets faster at answering questions you have not thought to ask yet.

Detector Studio: build from anything

Detector Studio now builds detectors from four starting points: the template library, a threat intelligence article, a MITRE ATT&CK technique, or a plain-language description. Paste a report about a new intrusion campaign and the studio drafts the detectors it implies, mapped to techniques, ready for replay against your history.

  • 5,000+ templates and collections, continuously refreshed from live threat research.
  • Article-to-detector: paste a write-up, get draft detectors with technique mappings and cited assumptions.
  • Plain-language building: describe the behavior; the studio writes the logic and shows its work.
  • Replay before release: every draft is tested against months of your real telemetry, with precision reported before anything can page a human.

Soc0: verdicts you can audit

Soc0's investigation reports now include a fully expandable evidence tree: every hop in the reasoning links to the raw events behind it. When Soc0 says a login was benign because the source has a two-year history with that account, the history is one click away. Trust in an AI analyst is built exactly here, in the audit trail.

The Legitimacy Score has also been recalibrated with feedback from millions of triage decisions. Score distributions are sharper at both ends, which means fewer cases in the ambiguous middle that need a human tiebreak.

An AI verdict is only as good as an analyst's ability to check it. Every hop now cites its evidence.

Network Security: fusion gets deeper

Network detections now correlate natively with identity and endpoint context in the investigation graph. A lateral-movement detection arrives with the account, the process, and the prior authentication chain already attached, so the network story and the host story are one story.

Sensorless coverage has expanded too: cloud flow logs and DNS telemetry can now drive the same behavioral detectors as sensor traffic, which means east-west visibility in environments where deploying taps was never going to happen.

Platform: query where the data lives

  • Federated query improvements: cross-source questions run up to 4x faster through predicate pushdown into source platforms.
  • New connectors: the integration catalog keeps growing; recent additions land in minutes with guided setup.
  • Coverage Map: the live map of sources, detectors, and gaps now flags unmonitored assets with suggested next steps.

See Port0 on your own data.

Bring your noisiest alert queue. Watch Soc0 investigate it live.

Book a Demo

Never Miss an Insight

Subscribe to get the latest posts delivered to your inbox.