What's New

While release notes provide a comprehensive view of our release updates, here is a preview of our most exciting features in ExtraHop 25.2.

New versioning format

Beginning with this release, ExtraHop is updating firmware version numbers to Year.Quarter.Maintenance.Revision (for example, 25.2.0.1687), where Year is a two-digit representation of the year and Quarter is a single-digit representation of the quarter that the firmware is released.

Detection Optimization Guide

A new in-product guide is now available to help you optimize detections by defining your environment, refining which detections you display, and distributing results for action or analysis. Access the guide at any time from the system settings menu.

Detection Log

You can now interact with the Detection Log in detection details to create tuning rules or view packets and records for individual log entries. You can also click IP addresses, usernames, device names, and properties in log entries to view additional information.

Notifications for Smart Investigations

You can now create a notification for recommended investigations, which sends an email when recommended investigations, also known as Smart Investigations, are created.

Enhanced Users page

The Users page now displays the number of detections in which the user was a participant and when the user was last observed on the network. In addition, you can now click a user row to view user properties in a side panel without leaving the table. The side panel also includes links that filter devices or detections by username.

Enhanced Devices page

From the Devices page, you can now click a device row to view and edit device properties in a side panel without leaving the table. The side panel can also include investigative links that navigate to pages for IP lookups, detections, activity maps, and records.

New Dashboard Home page

You can now display a new dashboards Home page that enables you to scan a list of the dashboards in each collection that you own or that were shared with you.

Packetstore lookback metrics on the System Health dashboard

You can now view packetstore metrics on the System Health dashboard if a packetstore is connected to the selected sensor. New charts have been added that display metrics about the estimated lookback, throughput, packet activity, and interface frames and drops.

Enhanced CrowdStrike Falcon integration (RevealX 360 only)

You can enable a new option for the CrowdStrike Falcon integration that imports and displays device properties from CrowdStrike Falcon. When viewing a CrowdStrike Falcon device in the ExtraHop system, certain CrowdStrike properties such as the last user, hostname, local and external IP addresses, and containment status are displayed in the device details. These CrowdStrike properties are also available as filters when searching for devices.

For Administrators

Webhook payload metrics on the System Usage dashboard
Administrators can now view metrics about webhook payloads sent to a target based on a detection notification rule. New charts have been added to the System Usage dashboard that display the number of webhook payloads sent, payloads that failed, and the event types associated with payloads.

For API Developers

Trigger API
You can now store metrics and access properties for BACnet and DNP3 traffic with new BACnet and DNP3 classes.
Last modified 2025-04-22