Alert

Attic Release Notes 2026.9.0

Attic MDR with IVON is available as a Sentinel add-on, reporting and usage are now in the portal, and app-based onboarding has become the default choice. In addition, sixteen new checks, two new detection rules and six automated remediations from alerts have been added.

New: Attic MDR with IVON

Attic MDR is now available as a Sentinel add-on. Incoming Sentinel and Defender alerts pass through a triage pipeline that classifies them, and IVON, our agentic investigation layer, writes the analysis that ends up in your ticket. Every outcome of the pipeline is a check, so findings arrive in the portal alongside your configuration checks and detection rules.

  • Layer 1 classifies alerts, layer 2 puts everything without a safe automatic answer in front of an analyst, and every outcome has its own check with an explanation for the customer.
  • The MDR consent step in onboarding activates IVON for a tenant. The step is optional and does not block the scheduling of checks.
  • Operators steer the pipeline through configurations: LLM provider and consent, Defender licence level, writeback, investigation budget and lifecycle status.

If you switch IVON on for a tenant, the old Sentinel alert processing for that tenant is switched off automatically. IVON takes over those alerts, so an alert is not processed twice.

New: Reporting and usage in the portal

Until now, reports could only be requested from IVON. They are now in the portal itself, both in the renewed partner portal and in the customer portal. You open a report in the browser or download it as a PDF, and you no longer have to forward anything for it.

Every report is attached to the incident it comes from. From an incident you reach the matching report and the other way round, so that when a customer asks a question you do not have to work out which report belonged to which incident.

The dashboard also shows per tenant how much incident handling has been used from the contracted capacity. You therefore see where usage is building up as you go, instead of only afterwards.

If you want to process the reports in your own tooling, you can do so through two new APIs for the IVON integration: one for reports and one for Sentinel.

Changed: app-based onboarding is the default

For a new onboarding, app-based is now set as the default. Onboarding through your GDAP relationship remains available as a choice. Nothing changes for existing tenants.

New: Automated remediations from alerts

Detection rules can now propose a containment action on the alert itself. Six new remediations join the existing account and mail rule actions, for revoking sessions, isolating endpoints and cleaning up persistence.

Added

Improved

Fixed

  • CHK-1176: RogueAppsDetected raised an incorrect ticket in every tenant after the external rogue apps feed was moved. The URL has been corrected, and a built-in list takes over when the feed is unreachable or unusable, instead of the check reporting a clean result without having scanned anything
  • Detection rule panels showed text from an alert that had already been resolved, most clearly with the log stoppage rules, which reported at the same time that there were no problems and that no logs were coming in. Forty rule descriptions now follow the current alert status
  • CHK-1003: got stuck on mailboxes that had never been configured, missed audit actions because of a substring comparison, and the fix stopped at the first mailbox that refused a change instead of continuing with the rest of the tenant
  • CHK-1049: mailboxes that were on the whitelist under a different alias were not recognised
  • RULE-1131, RULE-1140, RULE-1141 and RULE-1142: role assignments were divided incorrectly across the PIM and non-PIM rules, which caused some assignments to be reported twice
  • RULE-1162: Owner added to Subscription now reports only owners at subscription level, instead of every role assignment within the subscription
  • FIX-9001: mail rule targets are read in more robustly and the verification now reports the actual result
  • FIX-1420 ran into a timeout in production because redirect discovery failed on PowerShell 7 and all traffic went to an endpoint that hangs

Stay informed

Receive security alerts and practical tips straight to your inbox.

Always free — never spam