This topic describes the release history for Security Center and provides links to the relevant documentation.
August-December 2025
| Feature | Category | Description | Release date | References |
|---|---|---|---|---|
| Agentic SOC | Updated | Data import supports Azure. | 2025-12 | Import Azure log data |
| Vulnerability Management | New | Added automatic vulnerability remediation. | 2025-12 | View and handle vulnerabilities |
| Agentic SOC | Updated | Automatic response rules now support:
| 2025-12 | Automated response rules |
| Agentic SOC | New | Added the update owner feature for security event handling. | 2025-12 | Assess and handle Agentic SOC security incidents, Assess and handle CWPP security events |
| Agentic SOC | New | Data import supports Alibaba Cloud OSS. | 2025-11 | General data import process |
| Agentic SOC | Updated | Custom alerting rules support setting alert enrichment information. | 2025-11 | Rule management |
| Connect to Baidu Cloud Assets | New | Added support for Baidu Cloud. | 2025-11 | Onboard Baidu Cloud assets using an AccessKey |
| Agentless Detection | Updated | Agentless detection supports default scanning for new assets. | 2025-11 | Agentless detection, One-click onboarding policies and billing details for pay-as-you-go services |
| Malicious File Detection | New | Added the ability to handle malicious file detection results. | 2025-11 | Handle detection results |
| One-click Policy Activation | Updated | Added Log Management, anti-ransomware, and vulnerability remediation to one-click policy activation. | 2025-11 | One-click onboarding policies and billing details for pay-as-you-go services |
| Log Analysis and Log Management | Updated | Log Analysis and Log Management can be purchased and used together. | 2025-11 | Purchase Security Center, Migration guide for Log Analysis to Log Management |
| Overview | Unpublished | The previous version of the Overview page is unpublished. | 2025-11 | Assess and handle CWPP security events |
| Anti-ransomware | Updated | Anti-ransomware supports the pay-as-you-go billing method. | 2025-10 | Anti-ransomware service overview, Purchase Security Center, Activate and purchase the anti-ransomware service |
| Agentless Detection | New | Agentless detection supports scanning AWS host assets. | 2025-10 | Agentless detection |
| Cloud Security Posture Management (CSPM) | Updated | CSPM supports connecting to Volcengine assets. | 2025-09 | Onboard Volcengine assets using an AK, Add cloud assets for configuration checks |
| Agentic SOC | Updated | Watchlists support scheduled updates of trusted IP address sources for Alibaba Cloud products and services to global_white_list. | 2025-09 | Observation lists |
| Billing | Updated | For the pay-as-you-go plan, a basic service fee is added. The protection edition is changed to protection level. | 2025-09 | Purchase Security Center, Billing details, [Notice] Pay-as-you-go billing change |
| Agentic SOC | Updated | Custom alerting rules support setting alert entity mappings. | 2025-09 | Rule management |
| Detection and Response/Agentic SOC | Updated | Security event handling is available to Cloud Workload Protection Platform (CWPP) users. | 2025-09 | Assess and handle Agentic SOC security incidents |
| Agentic SOC | New | Added TaskContext, Threatbook, and Fortinet components to response orchestration. | 2025-08 | TaskContext, Threatbook, Third-party cloud OpenAPI component |
| Attack Analysis | Updated | Migrated to network defense alerts in Security Alerts. | 2025-08 | Manage alert information, [Notice] Changes to the Attack Analysis and Event Investigation menu |
| Agentic SOC | Updated | Product integration supports batch integration for Alibaba Cloud cloud-native products and automatic discovery of multi-account Logstore data sources. | 2025-08 | Multi-account management |
| Malicious File Detection | Updated | OSS file detection supports real-time incremental scanning in China regions. | 2025-08 | Malicious file detection |
July 2025
| Feature | Category | Description | Affected editions | Release date | References |
|---|---|---|---|---|---|
| Malicious File Detection | Updated | The maximum file size for single malicious file detection in Object Storage Service (OSS) is increased from 500 MB to 1 GB. | Editions with Malicious File Detection enabled | 2025-07-16 | Malicious file detection |
| Security Orchestration, Automation and Response (SOAR) | New | Added process components. | All editions | 2025-07-09 | Process component |
| Agentic SOC | Updated | Supports the upgrade assessment entry for Agentic SOC 2.0. | All editions | 2025-07-09 | [Notice] Agentic SOC upgrade, [Notice] Unpublish data sources of Agentic SOC 2.0 Process File Write Logs and Agentic SOC 1.0 File Read-Write Logs |
| Host and Container Security | Updated | Only the Ultimate Edition supports protection for Intelligent Computing LINGJUN assets, which can only be bound to the Ultimate Edition. | Anti-virus, Enterprise, and Advanced | 2025-07-03 | Manage host and container security quotas |
| Multi-cloud Asset Access | New | Supports integrating Google Cloud assets in global regions (excluding China). | All editions | 2025-07-02 | Onboard Google Cloud assets using a service account key |
June 2025
| Feature | Category | Description | Affected editions | Release date | References |
|---|---|---|---|---|---|
| Cloud Service Configuration Check | New | Supports configuration checks for Azure and AWS cloud-native AI services. | Editions with CSPM enabled | 2025-06-18 | Cloud service configuration check |
| AI Security Posture Management | Updated | Added the AI Asset card on the Overview page. | All editions | 2025-06-13 | AI security posture management |
| Malicious File Detection | Updated | Supports pay-as-you-go billing. | Editions with Malicious File Detection enabled | 2025-06-09 | Malicious file detection, Billing details |
| Application Protection | Updated | Supports pay-as-you-go billing. | Editions with application protection purchased | 2025-06-09 | Billing details |
| Serverless Asset Protection | Updated | Supports tiered billing. | Editions with serverless asset protection enabled (pay-as-you-go) | 2025-06-09 | Billing details |
May 2025
| Feature | Category | Description | Affected editions | Release date | References |
|---|---|---|---|---|---|
| Agentless Detection | Updated | Supports alert notifications. | Editions with agentless detection purchased (pay-as-you-go) | 2025-05-28 | Notification settings |
| Security Report | Updated |
| Advanced, Enterprise, and Ultimate | 2025-05-16 | Security reports |
| Log Analysis | Updated | Supports log delivery and storage for agentless detection alerts. | All editions | 2025-05-12 | Log types and field descriptions |
| Overview Page | Updated |
| All editions | 2025-05-08 | Overview (new) |
April 2025
| Feature | Category | Description | Affected editions | Release date | References |
|---|---|---|---|---|---|
| Anti-ransomware | Updated | Anti-ransomware policies for databases support selecting instances. | Editions with anti-ransomware enabled | 2025-04-29 | Manage anti-ransomware policies and agent |
| Cloud Security Posture Management (CSPM) | Updated | Cloud service configuration check supports custom check items. | Editions with CSPM purchased | 2025-04-25 | Set and run check policies |
| Multi-cloud Asset Access | New | Security Center supports adding Volcano Engine assets. | All editions | 2025-04-02 | Onboard a third-party asset to Security Center |
March 2025
| Feature | Category | Description | Affected editions | Release date | References |
|---|---|---|---|---|---|
| Baseline Check | Updated | Moved to Risk Governance > CSPM > Baseline Risks in the Security Center console. | Advanced, Enterprise, and Ultimate | 2025-03-31 | Baseline check |
| Asset Fingerprints | New | Asset fingerprints support collecting AI component information. | Enterprise and Ultimate | 2025-03-31 | Investigate asset fingerprints |
| Asset Exposure Analysis | New | Asset exposure analysis supports identifying AI service exposure on servers. | Enterprise and Ultimate | 2025-03-31 | Asset exposure analysis |
| Vulnerability Management | New | Vulnerability management supports detecting vulnerabilities in AI applications. | Enterprise and Ultimate | 2025-03-31 | View and handle vulnerabilities |
| Container Image Scan | New | Container image scan can tag images deployed by the Elastic Algorithm Service (EAS) of the Platform for AI (PAI) and detect plaintext sensitive information in AI API calls, such as Alibaba Cloud Model Studio API keys. | Editions with container image scan purchased | 2025-03-31 | View and handle detected image risks |
| Agentless Detection | New | Agentless detection supports identifying plaintext sensitive information in AI API calls, such as tokens of Alibaba Cloud PAI-EAS services. | Editions with agentless detection purchased (pay-as-you-go) | 2025-03-31 | Agentless detection |
| CSPM | Updated | Cloud service configuration check adds AI configuration management (AI-SPM) check items. | Editions with CSPM purchased or enabled | 2025-03-31 | Cloud service configuration check |
| CSPM | Updated | Cloud service configuration check adds Kubernetes Security Posture Management (KSPM) check items. | Editions with CSPM purchased or enabled | 2025-03-27 | Cloud service configuration check |
| Log Management | Discontinued | Security Center no longer supports delivering and storing network logs by using the log analysis feature or the log management feature of Agentic SOC. | Editions with log storage capacity for log analysis or Agentic SOC purchased | 2025-03-27 | [Notice] Updates on log analysis and Agentic SOC features |
| Defense Against Brute-force Attacks | Updated | Added configuration items for SQL Server brute-force attacks to reduce the risk of database intrusions. | Advanced, Enterprise, and Ultimate | 2025-03-14 | Defense against brute-force attacks |
| Host and Container Security | Updated | Supports pay-as-you-go billing, allowing you to bind different Security Center editions to your servers for a more flexible security solution. | All editions | 2025-03-14 | Purchase Security Center, Manage host and container security quotas |
| Terraform | Updated | Terraform documentation updated to support creating Agentic SOC modules. | All editions | 2025-03-06 | Activate Security Center by using Terraform |
February 2025
| Feature | Category | Description | Affected editions | Release date | References |
|---|---|---|---|---|---|
| Security Control | Discontinued | The security control feature is discontinued in Other Settings. | All editions | 2025-02-14 | Enable features on the Other Settings tab |
January 2025
| Feature | Category | Description | Affected editions | Release date | References |
|---|---|---|---|---|---|
| Multi-cloud Asset Access | Updated | Multi-cloud asset access supports configuring account names to differentiate assets from different accounts of the same third-party cloud provider. | All editions | 2025-01-12 | Onboard a third-party asset to Security Center |
| Agentic SOC | Updated | When assessing whether to adopt the recommended log policy for ActionTrail logs, Security Center considers whether you have purchased a paid edition (Anti-virus, Advanced, Enterprise, or Ultimate). Without a paid edition, ActionTrail logs are not automatically added, even with the recommended Agentic SOC log policy enabled. | Editions with Agentic SOC enabled | 2025-01-12 | Agentic SOC overview |
| Serverless Asset Protection | Updated | Supports protecting Alibaba Cloud Container Compute Service (ACS) assets. | Editions with serverless asset protection enabled (pay-as-you-go) | 2025-01-09 | Serverless security |
| Agent Status | Updated | The Security Center agent status now includes Agent Offline, Server Shutdown, and Agent Uninstalled. | All editions | 2025-01-07 | Install Client |
| Application Protection | Updated | Resource statistics support counting the number of PHP applications. | Editions with application protection quota purchased | 2025-01-07 | View applications added to application protection feature |
| Container Security | Updated | Supports protecting Intelligent Computing LINGJUN assets. | Ultimate | 2025-01-02 | Manage container assets |
December 2024
| Feature | Category | Description | Affected editions | Release date | References |
|---|---|---|---|---|---|
| Agentic SOC | Updated | When enabling Agentic SOC with pay-as-you-go billing, you can select the recommended log access policy. After selecting the recommended policy, the system automatically adds 14 types of logs from Alibaba Cloud Security Center, Web Application Firewall (WAF), Cloud Firewall, and ActionTrail. | Editions with Agentic SOC enabled | 2024-12-27 | Agentic SOC overview |
| Anti-ransomware | Updated | The regions supported by anti-ransomware for servers now include China (Ulanqab), China (Heyuan), and China (Guangzhou). | Editions with anti-ransomware enabled | 2024-12-20 | Overview of anti-ransomware |
| Agentless Detection | Updated | Agentless detection supports incremental detection forcustom images. | Editions with agentless detection enabled (pay-as-you-go) | 2024-12-20 | Agentless detection |
| Agentless Detection | Updated | Agentless detection supports handling malicious samples and sensitive files. | Editions with agentless detection enabled (pay-as-you-go) | 2024-12-20 | Agentless detection |
| Malicious File Detection | Updated | In OSS file detection, the size limit for a single file in a detection task is increased to 500 MB. | Editions with Malicious File Detection enabled | 2024-12-18 | Malicious file detection |
| Billing | Updated | Agentic SOC supports pay-as-you-go billing, enabling capabilities such as adding services, handling events, security alerting, and orchestration response. | All editions | 2024-12-13 | Billing details |
| Billing | Updated | Security Center instances can be switched from full protection mode to partial protection mode, allowing you to specify servers for protection and use more flexible billing and protection policies. | All paid editions | 2024-12-12 | [Notice] Full protection mode upgraded to partial protection mode |
| CSPM | Updated | Configuration assessment is renamed Cloud Security Posture Management (CSPM). | Editions with CSPM enabled | 2024-12-10 | CSPM overview |
| Application Protection | New | Protection for PHP applications is supported. | Editions with application protection quota purchased | 2024-12-06 | Overview of application protection |
| Baseline Check | Updated | Baseline check adds operational metrics. | Advanced, Enterprise, and Ultimate | 2024-12-03 | Baseline check |
November 2024
| Feature | Category | Description | Affected editions | Release date | References |
|---|---|---|---|---|---|
| Container Image Scan | Updated | Sensitive file information detected by the container image scan feature can be exported, including image versions and repository names. | Editions with container image scan enabled | 2024-11-21 | View and handle detected image risks |
| CI/CD Integration Settings | Updated | Documentation for Jenkins Freestyle and Pipeline projects is optimized to include detailed steps and screenshots for installing plugins and configuring image scans. | Ultimate | 2024-11-19 | Install the CI/CD plug-in for a Jenkins Freestyle project, Install the CI/CD plug-in for a Jenkins Pipeline project |
| Configuration Assessment | Updated | Added the attack path analysis feature, which scans and analyzes access paths between Alibaba Cloud services (such as a RAM role assigned to an ECS instance that controls OSS buckets) and provides visualized scan results. | Editions with configuration assessment enabled | 2024-11-19 | Use the attack path analysis feature |
| Agentic SOC | Updated | The recommended log access policy for Agentic SOC is adjusted to add 14 types of logs from Alibaba Cloud Security Center, WAF, Cloud Firewall, and ActionTrail. | Editions with Agentic SOC enabled | 2024-11-15 | Agentic SOC overview |
| Anti-ransomware | Updated | Anti-ransomware for databases supports viewing backup jobs. | Editions with anti-ransomware enabled | 2024-11-15 | Troubleshoot the issues causing the abnormal status of an anti-ransomware policy for a database and backup tasks |
| Anti-ransomware | Updated | Anti-ransomware supports backing up data of Rocky Linux systems. | Editions with anti-ransomware enabled | 2024-11-13 | Overview of anti-ransomware |
| Billing | Updated | Supports enabling Agentic SOC in the subscription billing method by using Terraform. | All editions | 2024-11-04 | Activate Security Center by using Terraform |
October 2024
| Feature | Category | Description | Affected editions | Release date | References |
|---|---|---|---|---|---|
| Container Microsegmentation | Updated | Container firewall is renamed container microsegmentation. | Ultimate | 2024-10-31 | Container microsegmentation |
| Container Image Scan | Updated | GitLab image repository can be scanned. | Ultimate | 2024-10-31 | Configure and perform image security scans |
| Container | Updated | GitLab image repository is added. | Ultimate | 2024-10-31 | Add image repositories to Security Center |
| Anti-ransomware | Updated | Added the option to exclude non-local mount paths in the anti-ransomware policy for servers. | Editions with anti-ransomware enabled | 2024-10-30 | Create an anti-ransomware policy and manage the anti-ransomware agent |
| Application Protection | Updated | Whitelist can be configured to limit access to Runtime Application Self-Protection (RASP). | Editions with application protection quota purchased | 2024-10-30 | Enable application protection |
| Agentic SOC | Updated | Alerts generated by Cloud Workload Protection Platform (CWPP) and Agentic SOC are merged onto one page. | All editions | 2024-10-24 | |
| Defense Against Brute-force Attacks | Updated | Security Center Advanced edition supports installing the alinet plug-in to improve protection effectiveness. You can also use the cloud dynamic defense model to strengthen the security system. | Advanced | 2024-10-24 | [Notice] Updated Defense Against Brute-force Attacks of Security Center |
| Application Protection | Updated | Manual access for containers is upgraded, and custom installation of RASP agent is supported. | Editions with application protection quota purchased | 2024-10-21 | Enable application protection |
| Core File Monitoring | Updated | Windows servers can be monitored. | Enterprise and Ultimate | 2024-10-16 | Use the core file monitoring feature |
| Proactive Defense for Containers | Updated | Added container image limits to activate rules for non-image program defense. | Ultimate | 2024-10-16 | Use the feature of proactive defense for containers |
| Log Analysis | Updated | Core file monitoring event logs are supported for delivery and storage. | Enterprise and Ultimate | 2024-10-15 | Log types and field descriptions |
| Anti-ransomware | Updated | Anti-ransomware for databases supports backing up data from MySQL 8.0. | Editions with anti-ransomware enabled | 2024-10-11 | Anti-ransomware service overview |
| Agentless Detection | Updated | Servers in the China (Chengdu) region are supported for agentless detection. | Editions with agentless detection enabled (pay-as-you-go) | 2024-10-09 | Agentless detection |
September 2024
| Feature | Category | Description | Affected editions | Release date | References |
|---|---|---|---|---|---|
| Serverless Asset Protection | Updated | Security assessment is supported across Serverless App Engine (SAE) products. | Editions with serverless asset protection enabled (pay-as-you-go) | 2024-09-30 | Serverless security |
| Asset Exposure Analysis | Updated | ApsaraDB RDS, Tair (Redis OSS-compatible), and ApsaraDB for MongoDB are added to supported asset types for detection. | Enterprise and Ultimate | 2024-09-27 | Asset exposure analysis |
| Agentic SOC | Updated | The attack timeline tab on the security event details page is optimized to include timeline cards with alerts and log evidence, as well as the source tracing diagram. This supports automated tracing of suspicious attack paths. The tracing diagram includes alerts, logs, vulnerabilities, baselines, assets, and entities, with options to view detailed information. | Editions with Agentic SOC enabled | 2024-09-24 | Security incident response |
| Agentic SOC | Updated | The public preview of the cold data storage solution for Agentic SOC log management is ended and the solution is unpublished. | Editions with Agentic SOC enabled | 2024-09-12 | [Notice] Public preview of the cold data storage feature of Agentic SOC ends and the feature is unpublished |
| Multi-cloud Configuration Management | Updated | The process for adding multi-cloud assets is optimized. When adding Azure assets, the SubscriptionId configuration is no longer required. | All editions | 2024-09-05 | Onboard a third-party asset to Security Center |
August 2024
| Feature | Category | Description | Affected editions | Release date | References |
|---|---|---|---|---|---|
| Agentic SOC | Updated | Added the aliyuncloudOpenAPI basic orchestration group. | Editions with Agentic SOC enabled | 2024-08-30 | SOAR |
| Agentic SOC | Updated | Logs from third-party cloud services such as Chaitin WAF and FortiGate Firewall can be added to Agentic SOC. | Editions with Agentic SOC enabled | 2024-08-20 | Ingest cloud product logs |
| Application Protection | Updated | Runtime circuit breaking feature is available. | Editions with application protection enabled | 2024-08-19 | Enable application protection |
| Configuration Assessment | Updated |
| Editions with configuration assessment enabled | 2024-08-19 | Billing details, CSPM overview |
| Application Protection | Updated | AI-powered analysis is available for attack alerts and in-memory webshell detection alerts, providing detailed explanations and reasoning. | Editions with application protection enabled | 2024-08-16 | Handle attack alerts |
| Configuration Assessment | Updated |
| All editions | 2024-08-02 | CSPM overview, Set and run check policies |
| Serverless Asset Protection | Updated |
| All editions | 2024-08-02 | Serverless security |
| Application Protection | Updated | A toggle for decompiling Java files is available on the details page of in-memory webshell detection alerts. | Editions with application protection enabled | 2024-08-01 | Use the in-memory webshell prevention feature |
| Log Analysis | Updated | V2.0 log dictionaries are released and the upgrade from V1.0 to V2.0 is available. | Editions with log analysis enabled | 2024-08-01 | [Notice] Log dictionaries are upgraded, Log types and field descriptions |
July 2024
| Feature | Category | Description | Affected editions | Release date | References |
|---|---|---|---|---|---|
| Malicious File Detection | Updated | Malicious File Detection can decrypt and check OSS objects encrypted with server-side encryption. | Editions with Malicious File Detection enabled | 2024-07-26 | Malicious file detection |
| Agentless Detection | Updated | Agentless detection enables the snapshot feature and the image check feature. | Editions with agentless detection enabled (pay-as-you-go) | 2024-07-08 | Agentless detection |
| Agentic SOC | Updated | SOAR playbook can be copied. | Editions with Agentic SOC enabled | 2024-07-03 | SOAR |
| Core File Monitoring | Updated | Added a best practice document for configuring the core file monitoring feature, including monitoring rule configurations and examples. | Enterprise and Ultimate | 2024-07-01 | Best practices for configuring the core file monitoring feature |
June 2024
| Feature | Category | Description | Affected editions | Release date | References |
|---|---|---|---|---|---|
| Malicious File Detection | Updated | API-based malicious file detection results are displayed in the at-risk files list in the Security Center console. | Editions with Malicious File Detection enabled | 2024-06-28 | Malicious file detection |
| Malicious File Detection | Updated | Malicious file detection logs can be delivered to the Logstore dedicated to Security Center. | Editions with Malicious File Detection enabled | 2024-06-28 | Malicious file detection logs |
| Malicious File Detection | Updated | DingTalk chatbots can be added to send notifications for real-time alerts on detected malicious files in a specified DingTalk group. | Editions with Malicious File Detection enabled | 2024-06-28 | DingTalk notifications |
| Vulnerability Management | Updated | Vulnerability management supports scanning servers that use SUSE and Kylin operating systems. | All editions | 2024-06-20 | Overview of vulnerability management |
| Application Protection | Updated |
| Editions with application protection quota purchased | 2024-06-19 | Overview of application protection |
| Agentic SOC | Updated | EdgeRoutine logs, access logs, and WAF logs of Dynamic Content Delivery Network (DCDN) can be added to Agentic SOC for threat detection, event handling, SOAR, and log storage. | Editions with Agentic SOC enabled | 2024-06-19 | Agentic SOC overview |
| Baseline Check | Updated | Debian 10, Debian 11, Debian 12, and TencentOS Server 3.1 are supported. | Advanced, Enterprise, and Ultimate | 2024-06-19 | Baseline check |
| Baseline Check | Updated | The maximum size of a weak password file that you can upload is increased to 40 KB. | Advanced, Enterprise, and Ultimate | 2024-06-07 | Baseline check |
| Installation of the Security Center Agent | Updated | Kylin V7 and Red Hat Enterprise Linux (RHEL) 9 are supported. | All editions | 2024-06-06 | Operating systems supported by the Security Center agent |
| Log Analysis | Updated | Agent event logs are supported for delivery and storage. | Editions with log analysis enabled | 2024-06-06 | Log types and log fields of the V1.0 log dictionaries |
May 2024
| Feature | Category | Description | Affected editions | Release date | References |
|---|---|---|---|---|---|
| Container Image Scan | Updated | Container image scan is supported for the China (Ulanqab) region. | Editions with container image scan enabled | 2024-05-31 | Overview of container image scan |
| Container | Updated | Risk detection results of a single image can be exported. | Ultimate | 2024-05-31 | Manage container assets |
| Purchase | Updated | When you purchase Security Center with the subscription billing method, the Protected Servers and Cores parameters can be specified based on your requirements. After purchase, you can manage the quotas. | Anti-virus, Advanced, Enterprise, and Ultimate | 2024-05-30 | Manage host and container security quotas |
| Alerts | Updated | The Suspicious process - Suspicious command alert is renamed Suspicious process - Suspicious probe command. | Anti-virus, Advanced, Enterprise, and Ultimate | 2024-05-22 | Overview of alerts |
| Application Protection | Updated | The attack alert details panel text is optimized. | Editions with application protection purchased | 2024-05-15 | Handle attack alerts |
| Malicious File Detection | Updated | The maximum file size for Malicious File Detection is increased from 20 MB to 100 MB. | Editions with Malicious File Detection purchased | 2024-05-14 | Malicious file detection |
| Configuration Assessment | Updated |
| Editions with configuration assessment purchased or enabled (pay-as-you-go) | 2024-05-11 | Overview of configuration assessment |
| Agentic SOC | Updated | The time picker and filter conditions on the Security Incident page are optimized. | Editions with Agentic SOC enabled | 2024-05-09 | Security incident response |
April 2024
| Feature | Category | Description | Affected editions | Release date | References |
|---|---|---|---|---|---|
| Agentic SOC | Updated |
| Editions with Agentic SOC enabled | 2024-04-26 | [Notice] Billing rules of Agentic SOC are changed |
| Application Protection | New | Added the in-memory webshell prevention feature to detect threats hidden in memory. | Editions with application protection enabled | 2024-04-17 | Use the in-memory webshell prevention feature |
| Configuration Assessment | Updated | Quick fixing is provided for more than 50 check items. | Editions with configuration assessment purchased or enabled (pay-as-you-go) | 2024-04-17 | Set and run check policies |
| Anti-ransomware (Bait Capture) | Updated | Linux servers are supported. | Advanced, Enterprise, and Ultimate | 2024-04-17 | Enable features on the Host Protection Settings tab |
| Baseline Check | Updated | The baseline type of Center for Internet Security (CIS) compliance is renamed internationally agreed best practices for security. | Advanced, Enterprise, and Ultimate | 2024-04-11 | Baseline check |
| Malicious File Detection | Updated | File packages can be decompressed for malicious file detection. | Editions with Malicious File Detection enabled | 2024-04-11 | Malicious file detection |
| Agentic SOC - Log Management | New |
| Editions with Agentic SOC enabled | 2024-04-02 | Manage logs |
| Configuration Assessment | Updated | In the Security Center console, accounts on the China site (aliyun.com) can perform RAM-related checks only on assets in China regions, and accounts on the international site (alibabacloud.com) can perform RAM-related checks only on assets in regions outside China. Historical scan results are retained in the regions of the assets. | Editions with configuration assessment purchased or enabled (pay-as-you-go) | 2024-04-01 | [Configuration assessment] RAM-related check items are supported only in the regions where Alibaba Cloud accounts are created |
March 2024
| Feature | Category | Description | Affected editions | Release date | References |
|---|---|---|---|---|---|
| Agentic SOC | Updated | The threat analysis feature is renamed Agentic SOC. | Editions with Agentic SOC enabled | 2024-03-29 | Agentic SOC overview |
| Container File Protection | Updated | A process whitelist and a file path whitelist can be configured when creating a rule for container file protection. | Ultimate | 2024-03-19 | Use the container file protection feature |
| Malicious File Detection | Updated | Adware, cracking programs, and private game servers can be detected. | Editions with Malicious File Detection enabled | 2024-03-01 | Malicious file detection |
February 2024
| Feature | Category | Description | Affected editions | Release date | References |
|---|---|---|---|---|---|
| Core File Monitoring | Updated | DingTalk chatbot alert notifications are supported for core file monitoring. | Enterprise and Ultimate | 2024-02-23 | Notification settings |
| Baseline Check | Updated | Custom weak password rules can be added to existing weak password rules. | Advanced, Enterprise, and Ultimate | 2024-02-22 | Baseline check |
| Application Protection | Updated |
| Editions with application protection enabled | 2024-02-22 | Enable application protection |
| Configuration Assessment | Updated | Pay-as-you-go billing method is supported. | All editions | 2024-02-19 | Overview of configuration assessment |
| Agentless Detection | Updated | Agentless detection is available for commercial use and is no longer free. If you enabled this feature free of charge, you can continue using it until the public preview ends on March 5, 2024. After that date, you must enable it with pay-as-you-go billing. | All editions | 2024-02-02 | Public preview of agentless detection ends |
January 2024
| Feature | Category | Description | Affected editions | Release date | References |
|---|---|---|---|---|---|
| Security Report | Updated | The Security Report page in the Security Center console is optimized. | Advanced, Enterprise, and Ultimate | 2024-01-31 | Security reports |
| Overview | Updated | The content of the security information module is optimized. | All editions | 2024-01-29 | Overview page (old version) |
| Risk Governance | Updated | The risk management module is renamed risk governance. | All editions | 2024-01-26 | None |
| Configuration Assessment | Updated | If you do not purchase a quota for configuration assessment, 25 check items are provided free of charge. | All editions | 2024-01-19 | Overview of configuration assessment |
| Vulnerability Management | Updated | The Show Only Exploitable Vulnerabilities feature is supported when you select Outside China as the asset region. | All editions | 2024-01-05 | View and handle vulnerabilities |
Earlier release notes
For release notes of Security Center earlier than 2024, see Release notes (before 2024).