---
title: "What’s New in Infoblox Threat Defense"
canonical: "https://docs.infoblox.com/space/BloxOneThreatDefense/35369418/What%E2%80%99s%20New%20in%20Infoblox%20Threat%20Defense"
format: markdown
---
This topic includes new features and enhancements for Infoblox Threat Defense. You can view information about other enhancements and maintenance for Infoblox SaaS products and services in the *[Infoblox SaaS Release Notes](https://docs.infoblox.com/space/BloxOneCloud/35461931/Infoblox+SaaS+Release+Notes)*.

## **Infoblox Threat Defense – September 3, 2026**

##### **Dossier now provides an AI Summary that explains domain risk at a glance.**

Infoblox Dossier now includes an AI Summary that provides a concise overview of a queried domain’s risk. The summary combines key intelligence, including the domain’s risk classification, classification rationale, reputation changes over time, threat feeds, and associated threat actors. Security analysts can quickly understand why a domain is considered risky, prioritize investigations, and access Dossier for deeper analysis. For information, see *[Related Domains](https://docs.infoblox.com/space/BloxOneThreatDefense/272172700/Related+Domains)*.

##### **Infoblox Endpoint 2.6.1.3 Enhances Internal Domain Availability.**

Infoblox Endpoint 2.6.1.3 improves the resilience of internal domain access during Infoblox Endpoint client failover and its eight-hour protection mode. The release strengthens local cache handling to help preserve access to internal domains during system restarts, including situations with limited or delayed internet connectivity. This update is being rolled out to all customers to further enhance connectivity and reliability. For information, see *[Managing Endpoint](https://docs.infoblox.com/space/BloxOneThreatDefense/35374260/Managing+Endpoint)*.

## **Infoblox Threat Defense – September 2, 2026**

##### **Threat Actor Monitoring is now available in the Security Workspace and in the Comprehensive Security Report.**

The **Threat Actor Monitor** gives you visibility into all Infoblox-identified threat actors observed in your environment, highlighting key details such as summaries, indicators, occurrences, affected assets, and threat attempts to help you understand threat actor activity at a glance. The **Comprehensive Security Report** also includes a dedicated Threat Actors section that summarizes the total number of detected threat actors and provides details about the top 10, including their names, summaries, occurrences, and threat attempts. For more information, see *[Threat Actors Detailed View](https://docs.infoblox.com/space/BloxOneThreatDefense/2760278053/Threat+Actors+Detailed+View)* and *[Comprehensive Security Report](https://docs.infoblox.com/space/BloxOneThreatDefense/35406198/Comprehensive+Security+Report)*.

## **Infoblox Threat Defense – August 31, 2026**

##### **Infoblox now supports deploying NIOS-X servers on the Proxmox hypervisor.**

Users can now deploy NIOS-X servers on the Proxmox hypervisor using an Infoblox-provided image, which can be downloaded from the Infoblox Portal. For more information, see *[NIOS-X on Proxmox Hypervisor](https://docs.infoblox.com/space/BloxOneInfrastructure/2760146949/NIOS-X+on+Proxmox+Hypervisor)*.

##### **NIOS-X now supports IPv6 static route configuration.**

Users can now configure IPv6 static routes from the **Servers** > **IP Interface Settings** page in the Infoblox Portal. For more information, see *[Setting IP Interfaces](https://docs.infoblox.com/space/BloxOneInfrastructure/119996611/Setting+IP+Interfaces)*.

## **Infoblox Threat Defense – August 28, 2026**

##### **IQ for Threat Defense introduces expanded Insight and Investigation capabilities.**

IQ for Threat Defense has expanded its Insight capabilities with Actor Insights for unverified assets, Retrospective Insights, and Botnet Behavioral Insights based on observed SERVFAIL and NXDOMAIN activity. Additionally, Insights for Malware C2, Malware Download, and Phishing Traffic now provide richer threat context. The investigation workflow now includes a dedicated Actor tab with more detailed threat actor information, and an optional Charts tab within Analysis. You can also download Insight data in JSON format. KPI charts and widgets dynamically reflect applied filters, providing a more focused view of the data. For information, see *[IQ for Threat Defense](https://docs.infoblox.com/space/BloxOneThreatDefense/2448392230/Infoblox+IQ+for+Threat+Defense)*.

## **Infoblox Exposure Management – August 19, 2026**

##### **Exposure Management now includes automated detection triage.**

Automations let you create rules that act on detections without requiring an analyst to review and triage each one manually. When a detection matches the conditions you define, an automation can change its status, apply a tag, or add a note. You control when each automation runs by reviewing and activating it after configuration. Automations allow users to automate tickets in workspaces, providing tools for creating, editing, prioritizing, pausing, and deleting automations. They also use permissions to control who can manage automation rules. For information about how to get started and where to find additional resources, see *[Infoblox Exposure Management Automations](https://docs.infoblox.com/space/IEM/2712731664/EASM+Automations)*.

## **Infoblox Threat Defense – August 18, 2026**

##### **Infoblox Portal now requires periodic user profile validation.**

Infoblox Portal now requires periodic user profile validation. To help maintain accurate user information for compliance and role-based communications, the Infoblox Portal now prompts users to validate their profile before accessing the product. On their next login, users are asked to confirm or update their first name, last name, job title, country, and state or region. Once validated, users are prompted to reconfirm this information annually. The validation screen is required and cannot be skipped. New users are also required to provide this information at account creation.

**Profile Validation details**:

Infoblox Portal periodically prompts you to validate your profile information. When validation is due, a required screen appears at login and must be completed before you can access the product. You cannot skip or dismiss this screen. During validation, you are asked to confirm or update your first name, last name, job title, country, and state or region, and to confirm your marketing email preference. Once validated, the system schedules your next validation for one year later. New users are required to provide this information at account creation. For more information, see *[Setting User Preferences in Universal DDI](https://docs.infoblox.com/space/BloxOneDDI/186466676)* and *[Setting User Preferences in Threat Defense](https://docs.infoblox.com/space/BloxOneThreatDefense/35407811)*.

## **Infoblox Threat Defense – August 14, 2026**

##### **NIOS-X as a Service now displays additional health details for each VPN tunnel on the Access Location view.**

You can now view the status of each VPN tunnel at an access location. For connections, the tunnel details now also show the primary and secondary tunnel BGP status. For more information, see *[Access Location View](https://docs.infoblox.com/space/BloxOneDDI/2514190405/Access+Location+View)*.

##### **Infoblox now supports configuring an Anycast profile for NTP in NIOS-X as a Service deployments.**

You can now enable Anycast for the NTP capability when creating or modifying a NIOS-X as a Service deployment. When NTP Anycast is enabled, NTP requests from your remote sites are routed to the nearest healthy NTP instance, improving time synchronization reliability and performance across distributed locations. For information, see *[General Tab](https://docs.infoblox.com/space/BloxOneDDI/2540371983/General+Tab)*.

##### **Unified Asset Inventory page.**

Universal Asset Insights now provides a single unified Asset Inventory page, which combines previously separate managed assets and unmanaged assets into one inventory view. Asset categories, such as service, network, IoT, device, and compute, now appear in a left-hand navigation panel, with managed and unmanaged assets shown as top-level sections within each category rather than on separate pages. This gives you a single place to browse and filter all discovered assets. For more information, see *[Viewing Discovered Assets in Data Table](https://docs.infoblox.com/space/UniversalAssetInsights/1614217830/Viewing+Discovered+Assets+in+Data)*.

##### **Ask IQ in Asset Inventory.**

Universal Asset Insights now includes an Ask IQ option in the Asset Inventory, letting you query your asset data using natural language. Ask IQ opens the AI Assistant directly from the Asset Inventory page so that you can ask questions about your assets. Responses may include clickable chips that automatically apply the corresponding filter to the inventory table. For more information, see *[Viewing Discovered Assets in Data Table](https://docs.infoblox.com/space/UniversalAssetInsights/1614217830/Viewing+Discovered+Assets+in+Data)*.

##### **Asset Inventory now supports advanced mode search support for filtering on provider data.**

Asset Inventory advanced search now supports dot-notation queries across the full raw data collected from each provider, including fields not displayed in the inventory table. Search suggestions identify matching tables and columns up to three levels deep, allowing you to filter by nested attributes such as account, region, or attachment state fields. For more information, see *[Viewing Discovered Assets in Data Table](https://docs.infoblox.com/space/UniversalAssetInsights/1614217830/Viewing+Discovered+Assets+in+Data)*.

## **Infoblox Threat Defense – August 12, 2026**

##### **Infoblox introduces a revamped Endpoint UI and User Experience for Endpoint.**

The refreshed Endpoint workspace in Infoblox Portal introduces a more intuitive, monitor-driven experience for managing Infoblox Endpoints. New dashboards and widgets provide centralized visibility into endpoint health, protection status, compliance, software versions, operating systems, device locations, and Point of Presence (PoP) connections.

The update also introduces endpoint health statuses, status-change logs, trend reporting, and compliance statistics. These enhancements help administrators quickly identify unhealthy or noncompliant endpoints, investigate status changes, recognize broader trends, and prioritize remediation.

The refresh does not change how existing DNS or security policies are enforced and does not require endpoint agents to be reinstalled.

For information, see *[Managing Endpoint](https://docs.infoblox.com/space/BloxOneThreatDefense/35374260/Managing+Endpoint)*.

## **Infoblox Threat Defense – August 7, 2026**

##### **Infoblox now supports the NIOS-X v4.1.12 image.**

The NIOS-X v4.1.12 image introduces self-migration support for converting NIOS to NIOS-X on X6 hardware appliances directly from the Infoblox Portal. The image also upgrades containerd to 2.2.4 and Docker to 29.4.3, and includes kernel and other package security updates.

## **Infoblox Threat Defense – August 4, 2026**

##### **Infoblox now supports converting X6 hardware appliances from NIOS to NIOS‑X directly through the Infoblox Portal.**

You can convert eligible X6 hardware appliances running NIOS version 9.0.7 to NIOS‑X directly from the **Servers** page. The conversion runs as a background process and converts the NIOS server to a NIOS‑X server. For more information, see *[Converting X6 Hardware from NIOS to NIOS‑X](https://docs.infoblox.com/space/BloxOneInfrastructure/2142797855/Converting+NIOS+to+NIOS%E2%80%91X+on+X6+Hardware)*.

## **Infoblox Threat Defense – July 30, 2026**

##### **NIOS-X now supports Red Hat Enterprise Linux (RHEL) 9.8 for bare-metal installations.**

NIOS-X now supports RHEL 9.8 for bare-metal installations, expanding compatibility across the RHEL 9.x family. This enhancement ensures validated installation and stable operation on RHEL 9.8.

## **Infoblox Threat Defense – July 15, 2026**

##### **Infoblox has introduced the following feature enhancements that simplify indicator management, improve network documentation, and provide greater control over DNS query routing.**

**Custom TTL Expiration for Indicators:** Administrators can now assign a time-to-live value to individual indicators added to custom lists. The expiration can be configured as a duration, such as seven days, or as a specific date and time. When the TTL expires, Infoblox Threat Defense automatically removes the indicator from the custom list and propagates the change to the policy engine. Any blocking action associated with the expired indicator is removed without requiring manual cleanup. For information, see *[Configuring TTL for Indicators in Custom Lists](https://docs.infoblox.com/space/BloxOneThreatDefense/2602565752/Configuring+TTL+for+Indicators+in+Custom+Lists)*.

**Subnet Descriptions for External Networks:** Administrators can now add a description to each subnet included in an External Network list. Previously, subnet entries supported only a CIDR address. Each subnet can include a free-text description of up to 256 characters. Descriptions can identify the location, purpose, or devices associated with the subnet, such as Guest Wi-Fi, IoT Devices, or New York Branch Office. For information, see *[Configuring External Networks](https://docs.infoblox.com/space/BloxOneThreatDefense/35473665/Configuring+External+Networks)*.

## **Infoblox Threat Defense – July 14, 2026**

##### **Infoblox Endpoint version 2.6.1 for Windows and macOS.**

Infoblox Endpoint 2.6.1 is now available for Windows and macOS. This release introduces new functionality and stability and reliability improvements for both operating systems, and includes the following updates:

**Expanded client event data:** Infoblox Endpoint now reports additional client event information. This data supports new dashboard statistics and upcoming user experience and interface enhancements.

**Infoblox-hosted update downloads:** Infoblox Endpoint now retrieves client updates from an Infoblox-hosted domain instead of the previous Amazon S3 location. This change supports customers whose firewalls, web proxies, or security tools restrict downloads from non-Infoblox domains. Action required: If your organization restricts outbound downloads, update your allowlist to permit the new Infoblox download host. Failure to allow the host may prevent endpoints from receiving automatic upgrades. For additional information on the updated download URL formats, see *[Infoblox SaaS Release Notes](https://docs.infoblox.com/space/BloxOneCloud/35461931/Infoblox+SaaS+Release+Notes)*.

**Block Non-Trusted DNS (Early Access):** Infoblox Endpoint can now block DNS queries sent to DNS servers that are not trusted by the active endpoint policy. This feature helps prevent applications and users from bypassing approved DNS resolution paths. It is available to Early Access Program customers while EAP testing continues. Stability and reliability improvements: This release includes additional fixes and enhancements that improve endpoint stability and reliability on Windows and macOS.

For additional information, see *[Infoblox SaaS Release Notes](https://docs.infoblox.com/space/BloxOneCloud/35461931/Infoblox+SaaS+Release+Notes)* and *[Managing Endpoint](https://docs.infoblox.com/space/BloxOneThreatDefense/35374260/Managing+Endpoint)*.

## **Infoblox Threat Defense – June 30, 2026**

##### **Infoblox introduces URL-based indicator sources for Bring Your Own Feed.**

Infoblox Threat Defense now supports URL-based indicator sources for Bring Your Own Feed. Administrators can create a Custom RPZ and feed from a referenced URL, then configure scheduled updates so indicators are imported and refreshed automatically without manual list updates. This enhancement supports CSV and plain text sources, basic username and password authentication, and API-based imports. Administrators can view active data sources, related Custom RPZ or feed information, the last update time, and the number of imported indicators, and can manage, update, or deactivate the source as needed. For information, see *[Submitting TIDE Data](https://docs.infoblox.com/space/BloxOneThreatDefense/35468085/Submitting+TIDE+Data)*.

## **Infoblox Threat Defense – June 26, 2026**

##### **Infoblox announces the release of Infoblox IQ for Threat Defense.**

Infoblox IQ for Threat Defense is the first product experience available in Infoblox IQ. It is built to help security teams focus on the threats that matter most by automatically investigating DNS security signals, surfacing prioritized threats with user and device context, and adding agentic AI capabilities for conversational investigations and one-click remediation workflows. For SOC analysts and managers, this means faster investigation, less manual triage, and a clearer path from detection to action, while keeping analysts in control and maintaining a full audit trail throughout. For information, see *[Infoblox IQ for Threat Defense](https://docs.infoblox.com/space/BloxOneThreatDefense/2448392230/Infoblox+IQ+for+Threat+Defense)*.

## **Infoblox Threat Defense – June 16, 2026**

##### **DFP service logs for NIOS-X as a Service deployments are now displayed on the Service Logs page.**

This enhancement improves observability and operational efficiency, enabling faster diagnostics and better service monitoring. For more information, see *[Viewing Service Logs](https://docs.infoblox.com/space/BloxOneDDI/186466397/Viewing+Service+Logs)*.

## **Infoblox Threat Defense – June 04, 2026**

##### **Infoblox now supports deployment of NIOS‑X servers on Equinix Network Edge.**

You can now deploy NIOS‑X servers on Equinix Network Edge through the Equinix Customer Portal. This enables you to provision virtual appliances without requiring dedicated physical hardware, extending Infoblox Universal DDI services across on‑premises, hybrid, and multi‑cloud environments. For more information, see *[Equinix Network Edge](https://docs.infoblox.com/space/BloxOneInfrastructure/2459467779/Equinix+Network+Edge)*.

## **Infoblox Threat Defense – June 03, 2026**

##### **Infoblox now provides health notifications for service capabilities and tunnel connections for NIOS‑X as a Service deployments.**

Infoblox now monitors the health of service capabilities across availability zones as well as the status of associated IPsec tunnel connections for NIOS‑X as a Service deployments. When a capability or tunnel becomes partially unavailable, fully unavailable, or returns to normal, the system generates **Degraded**, **Error**, or **Healthy** notifications to indicate the current state. This enhancement helps users to identify and respond to capability or connectivity issues more quickly. For more information, see *[Health Notifications](https://docs.infoblox.com/space/BloxOneDDI/2455045062/Health+Notifications)*.

## **Infoblox Threat Defense – May 29, 2026**

##### **Splunk Data Connector Scale and Performance Updates.**

This release increases the scale and performance of Splunk data delivery for Data Connector deployments. Enhancements include OpenSSL 3 compatibility, refreshed base images, optimized event delivery monitoring, and fine-tuned Splunk Universal Forwarder configurations to improve overall operational efficiency and reliability. For information, see *[Deploying the Data Connector Solution](https://docs.infoblox.com/space/BloxOneCloud/35429862/Deploying+the+Data+Connector+Solution)* and *[Setting Up Splunk](https://docs.infoblox.com/space/BloxOneCloud/35430532/Setting+Up+Splunk)*.

## **Infoblox Threat Defense – May 28, 2026**

##### **The DNS Activity report now includes Application tagging fields that provide additional application context for domain activity directly in the Infoblox Portal.**

Infoblox has enhanced DNS Activity in the Infoblox Portal by adding Domain Application tagging fields to the DNS Activity view. Users can now display application-related domain details directly in the UI, including application category, application name, and application vendor. This update surfaces domain application data that is already available in backend systems, making it easier to review DNS activity with additional context during investigation and analysis. For information, see *[DNS Activity Report](https://docs.infoblox.com/space/BloxOneThreatDefense/35406117/DNS+Activity+Report)*.

## **Infoblox Threat Defense – May 11, 2026**

##### **Protect Your Brand, Executives, and Data with Digital Risk Protection Services (DRPS).**

Infoblox completed the acquisition of Axur, an external cybersecurity company based in Brazil, on May 5th, 2026. With this acquisition, Infoblox now offers Digital Risk Protection Services (DRPS), part of Infoblox Exposure Management, a solution that extends preemptive security beyond the network perimeter. You can now disrupt phishing sites, brand and executive impersonation, and fraudulent apps with automated takedowns. In addition, you can monitor data leakage across the deep and dark web. For information about how to get started and where to find additional resources, see *[Infoblox Cloud Release Notes](https://docs.infoblox.com/space/BloxOneCloud/35461931/Infoblox+Cloud+Release+Notes)*.

## **Infoblox Threat Defense – May 6, 2026**

##### **Infoblox introduces searching by Infoblox Threat Actor name directly in Dossier.**

Dossier now provides security analysts with a more direct way to research threat actors by supporting searches by actor name. This enhancement improves investigation workflows by helping analysts locate relevant actor intelligence without first searching for a related domain name. With this update, Dossier users can enter a threat actor name in the search field to retrieve matching intelligence. For more information, see *[Dossier Threat Actor](https://docs.infoblox.com/space/BloxOneThreatDefense/230394862/Threat+Actor)*.

## **Infoblox Threat Defense – May 5, 2026**

##### **Reporting Token Usage Allocation Update.**

Infoblox recently resolved an issue related to Reporting Token allocation. This update improves usage accuracy for customers with Reporting Tokens who export high-volume log data through Cloud Data Connector, S3 Log Export, or Universal DDI Reports. Customers exporting over 1 million logs per day may notice that usage data will be backfilled to accurately reflect activity that was previously under-counted. This correction affects reporting visibility only and helps ensure that Reporting Token utilization reflects actual log export volume.

## **Infoblox Threat Defense – April 28, 2026**

##### **Upcoming: Infoblox Portal has a redesigned navigation structure that will be available starting May 4th, 2026.**

Infoblox Portal will introduce a redesigned menu structure focused on improving usability. The new layout offers more intuitive navigation, clearer organization, and streamlined workflows to help users find what they need more efficiently. For more information, see *[Mapping between Legacy and New Navigation](https://docs.infoblox.com/space/BloxOneCloud/2345041926/Mapping+between+Legacy+and+New+Navigation)*.

## **Infoblox Threat Defense – April 21, 2026**

##### **Infoblox now supports viewing additional service logs for NIOS‑X as a Service deployments and introduces service log filtering for service deployments.**

Service logs for **NTP**, **Anycast**, **DTC**, and **Tunnel (IPSec)** services are now available on the **Service Logs** page for NIOS-X as a Service deployments. In addition, the **Service Logs** page includes a new **Universal Service** filter that allows you to select one or more NIOS-X as a Service deployments and display only the service events associated with those deployments. This enhancement improves operational insight by enabling deployment-based filtering of service logs, helping administrators perform faster diagnostics and more effective monitoring across supported services. For more information, see *[Viewing Service Logs](https://docs.infoblox.com/space/BloxOneDDI/186466397/Viewing+Service+Logs)*.

##### **Infoblox now supports configuring NTP in an Anycast configuration for NIOS‑X.**

Users can configure **NTP** as a service type in an Anycast configuration, enabling NTP requests to be routed through a single Anycast IP address. When NTP is enabled, the Anycast service continuously monitors NTP health and automatically directs requests to the nearest healthy NTP instance, improving reliability and performance. For information on how to configure NTP in an Anycast configuration, see *[Creating Anycast Configuration](https://docs.infoblox.com/space/BloxOneDDI/186648729/Creating+Anycast+Configuration)*.

## **Infoblox Threat Defense – April 2, 2026**

##### **Microsoft Active Directory User Attribution is now available in Infoblox Threat Defense.**

Infoblox Threat Defense now supports Microsoft Active Directory User Attribution, giving security teams user-level visibility into DNS activity and security events without changing the DNS path or requiring a captive portal.

By passively correlating on-premises Active Directory sign-in and sign-out data with client IP addresses and devices in the Infoblox cloud, Threat Defense and SOC Insights can identify the user behind suspicious DNS activity, including activity from shared systems. This improves attribution, the speed of investigations, and reduces the need to manually review separate AD logs and endpoint tools. For information, see *[Configuring Security Policies](https://docs.infoblox.com/space/BloxOneThreatDefense/35371559/Configuring+Security+Policies)*.

## **Infoblox Threat Defense – March 27, 2026**

##### **Infoblox Threat Defense introduces advanced query language filtering and user history for Security Monitors.**

This release includes advanced query language filtering for Security Monitors, enabling more precise and flexible filtering using a simple, structured syntax. A new query builder makes it easier to create and apply these filters within the Security Monitor Workspace.

Also included in this release is the ability to view user history directly within the Security Monitor Workspace, allowing you to review user activity without leaving your investigation workflow.

For more information, see *[Viewing Security Workspace](https://docs.infoblox.com/space/BloxOneCloud/1588592724/Viewing+Security+Workspace)*.

## **Infoblox Threat Defense – March 06, 2026**

##### **Infoblox Threat Defense updates the default global security policy and precedence for new deployments.**

Infoblox Threat Defense updates the default global security policy and precedence for **new deployments** by changing the default action for the following three Threat Insight detections from Log to Block: **Threat Insight – DGA**, **Threat Insight – Data Exfiltration**, and **Threat Insight – DNS Messenger**. The rule order in the default global security policy is also updated to position these Threat Insight block rules after Infoblox Medium Risk and before Infoblox Low Risk and Infoblox Information. For more information, see *[Default Global Policy Feed Configuration Recommendation](https://docs.infoblox.com/space/BloxOneThreatDefense/624918912/Default+Global+Policy+Feed+Configuration+Recommendation)*.

## **Infoblox Threat Defense – March 04, 2026**

##### **Infoblox X6 hardware now supports running NIOS-X on TE‑906 and TE‑1506 appliances.**

For more information, see *[Converting NIOS to NIOS‑X on X6 Hardware](https://docs.infoblox.com/space/BloxOneInfrastructure/2142797855/Converting+NIOS+to+NIOS%E2%80%91X+on+X6+Hardware)*.

## **Infoblox Threat Defense – February 24, 2026**

##### **Infoblox supports the deployment of NIOS-X servers on Oracle Cloud Infrastructure (OCI).**

Users can now deploy NIOS-X servers on Oracle Cloud Infrastructure (OCI) using the Infoblox-provided OCI package, which can be downloaded from the Infoblox Portal. For more information, see *[Oracle Cloud Infrastructure (OCI) Deployment](https://docs.infoblox.com/space/BloxOneInfrastructure/2129920010/Oracle+Cloud+Infrastructure+(OCI)+Deployment)*.

## **Infoblox Threat Defense – February 23, 2026**

##### **NIOS‑X v4.0.0 now supports Ubuntu 24.04.**

This release is built on Ubuntu 24.04, providing compatibility with the latest OS features and security enhancements. It supports both fresh deployments on new appliances and upgrades from existing v3.x appliances, including restoration of host configuration. For more information, see *[Dell Physical Servers Deployment](https://docs.infoblox.com/space/BloxOneInfrastructure/204538971/Dell+Physical+Servers+Deployment)*.

## **Infoblox Threat Defense – February 20, 2026**

##### **Infoblox has released new Threat Breakdown Content in Security Reports.**

The **Comprehensive Security Report** and **Executive Summary Report** now include a new Threat Breakdown section. This section provides key summary metrics, such as protection before impact, unique threat domains, and suspicious and malicious domains, offering an overview of key findings on threat domains within your environment. To download the unified report, go to **Monitor** > **Reports** > **Security** > **Summary Report** and click **Download**. For more information, see *[Security Reports](https://docs.infoblox.com/space/BloxOneCloud/1787265026/Security+Reports)* and *[Summary Reports](https://docs.infoblox.com/space/BloxOneThreatDefense/35375414/Summary+Reports)*.

## **Infoblox Threat Defense – February 18, 2026**

##### **Infoblox has released Endpoint version 1.0.14 for Android and Endpoint version 2.0.13 for iOS.**

This release enhances Endpoint protection status reporting and includes minor feature improvements. For information, see *[Managing Endpoint](https://docs.infoblox.com/space/BloxOneThreatDefense/35374260/Managing+Endpoint)*.

## **Infoblox Threat Defense – February 6, 2026**

##### **Infoblox now provides the ability to apply software updates immediately from the Servers page.**

The **Servers** page includes a new **Apply software updates now** option. This option allows you to install the latest software updates for applications running on a selected NIOS-X server immediately. It provides faster and more flexible update management. For more information, see *[Scheduling Software Updates for Servers](https://docs.infoblox.com/space/BloxOneInfrastructure/184583758/Scheduling+Software+Updates+for+Servers)*.

##### **NIOS-X supports chained software update scheduling across server groups.**

NIOS-X now supports chaining multiple software update schedules (for example, lab, stage, and production) to run in a defined sequence with configurable delays. This capability enables controlled and efficient updates. For more information, see *[Scheduling Software Updates for Servers](https://docs.infoblox.com/space/BloxOneInfrastructure/184583758/Scheduling+Software+Updates+for+Servers)*.

## **Infoblox Threat Defense – January 21, 2026**

##### **NIOS-X now supports IPv4 static route configuration.**

Users can now configure IPv4 static routes from the **Servers** > **IP Interface Settings** page in the Infoblox Portal. For more information, see *[Setting IP Interfaces](https://docs.infoblox.com/space/BloxOneInfrastructure/119996611/Setting+IP+Interfaces)*.

## **Infoblox Threat Defense – January 14, 2026**

##### **NIOS-X supports sequential software updates.**

By default, NIOS-X applies software updates to one server at a time during a software update, ensuring each update completes successfully before proceeding to the next server. This applies to all update types, including scheduled updates. If preferred, users can disable sequential updates for an update window or restore sequential behavior for future software updates. For information, see *[Scheduling Software Updates for Servers](https://docs.infoblox.com/space/BloxOneInfrastructure/184583758/Scheduling+Software+Updates+for+Servers)*.

##### **Data Connector introduces Splunk CIM alignment for DHCP events and performance enhancements.**

Data Connector now aligns DHCP lease events with Splunk CIM Network Session standards, mapping operations to CIM-compliant actions while preserving Infoblox-specific details for advanced analytics. This release also delivers major scalability and efficiency improvements for high-volume collections from Infoblox Cloud sources through optimized CPU and memory usage, as well as batch processing. For information, see *[Data Connector](https://docs.infoblox.com/space/BloxOneCloud/35428954/Data+Connector)* and *[Setting Up Splunk](https://docs.infoblox.com/space/BloxOneCloud/35398013/Setting+Up+Splunk+Cloud)*.

## **Infoblox Threat Defense – January 13, 2026**

##### **Infoblox Threat Defense has added 16 new applications, expanding application filtering coverage within the VPNs & Proxies category.**

This update enhances policy enforcement for proxy and VPN services commonly used to obscure user identity or bypass network controls. For information, see *[Creating Application Filters](https://docs.infoblox.com/space/BloxOneThreatDefense/56656233/Creating+Application+Filters)*. For a list of the newly added applications, see *[Infoblox Cloud Release Notes](https://docs.infoblox.com/space/BloxOneCloud/35461931/Infoblox+Cloud+Release+Notes)*.

## **Infoblox Threat Defense – January 9, 2026**

##### **Infoblox Threat Defense certificate update for the Redirect Block page.**

The Infoblox SSL Root Certificate for the Infoblox Default Redirect Block page will be updated on January 9, 2026. Please install the latest certificate in your browsers by January 24, 2026, to prevent redirect errors when the Block Policy is enforced. For information on how to install the certificate, see *[Installing Infoblox Root Certificate for Bypass Code](https://docs.infoblox.com/space/BloxOneThreatDefense/35404482/Installing+Infoblox+Root+Certificate+for+Bypass+Code)*.

## **Infoblox Threat Defense – December 16, 2025**

##### **Infoblox Labs lets customers discover, enable, and try early-access product capabilities before they are generally available.**

For more information, see *[Infoblox Labs](https://docs.infoblox.com/space/BloxOneCloud/1904607249/Infoblox+Labs)*.

## **Infoblox Threat Defense – December 1, 2025**

##### **Infoblox Endpoint version 2.6.0 for Linux introduces enhancements that improve overall manageability, reliability, and deployment flexibility across endpoint environments.**

This release includes updates such as customer-defined fallback and customer-defined internal resolvers. These updates improve operational efficiency, strengthen security resilience, and streamline endpoint management workflows. For information, see *[Managing Endpoint](https://docs.infoblox.com/space/BloxOneThreatDefense/35374260/Managing+Endpoint)*. For a list of enhancements and resolved issues addressed in this release, see *[Infoblox Cloud Release Notes](https://docs.infoblox.com/space/BloxOneCloud/35461931/Infoblox+Cloud+Release+Notes)*.

## **Infoblox Threat Defense – November 21, 2025**

##### **Infoblox Endpoint version 2.6.0 for Windows Clients introduces enhancements that improve overall manageability, reliability, and deployment flexibility across endpoint environments.**

This release includes updates such as customer-defined fallback and customer-defined internal resolvers, IP management, and offline protection improvements. These updates improve operational efficiency, strengthen security resilience, and streamline endpoint management workflows. For information, see *[Managing Endpoint](https://docs.infoblox.com/space/BloxOneThreatDefense/35374260/Managing+Endpoint)*. For a list of enhancements and resolved issues addressed in this release, see *[Infoblox Cloud Release Notes](https://docs.infoblox.com/space/BloxOneCloud/35461931/Infoblox+Cloud+Release+Notes)*.

## **Infoblox Threat Defense – November 20, 2025**

##### **Infoblox introduces scheduled reporting for workspaces.**

With the appropriate reporting entitlements, users can now create on-demand or scheduled reports across Network, Security, and Asset workspaces in the Infoblox Portal. Select one or more workspaces and customize content with detailed drilldowns and data insights. Recipients receive automatic notifications when reports are ready. Manage and update schedules anytime through the centralized Scheduled Reports console. For more information, see *[Scheduling Reports](https://docs.infoblox.com/space/BloxOneDDI/1821048843/Scheduling+Reports)*.

## **Infoblox Threat Defense – November 19, 2025**

##### **Infoblox is releasing an Early Access version of Insights, referred to as “Insights – Early Access.”**

This Early Access release offers a new, streamlined workflow, making it easier to analyze and prioritize incidents in your environment. It provides richer context, clearer threat attribution, and recommended actions so that SOC teams can understand each insight and respond with confidence. Your existing Insights, including any SIEM/API integrations and notifications, will remain unchanged and functioning as they are. Insights – Early Access runs alongside the current SOC Insights and is intended to gather feedback on the new workflow and granular insights. General Availability of the updated Insights is planned for early 2026, at which point your existing Insights and configuration will be seamlessly migrated to the new experience. For information, see *[Insights - Early Access](https://docs.infoblox.com/space/BloxOneThreatDefense/1793392673/Insights+-+Early+Access)*.

## **Infoblox Threat Defense – November 4, 2025**

##### **Infoblox Endpoint version 2.6.0 for macOS introduces enhancements that improve overall manageability, reliability, and deployment flexibility across endpoint environments.**

This release includes updates such as customer-defined fallback and customer-defined internal resolvers, IP management, and offline protection improvements. These updates improve operational efficiency, strengthen security resilience, and streamline endpoint management workflows. For information, see *[Managing Endpoint](https://docs.infoblox.com/space/BloxOneThreatDefense/35374260/Managing+Endpoint)*.

## **Infoblox Threat Defense – October 30, 2025**

##### **NIOS-X now supports Large (L) and Extra Large (XL) virtual server sizes, enabling greater scalability and performance for high-demand environments.**

NIOS-X now supports the configuration of virtual servers with Large (L) and Extra Large (XL) sizes. This enhancement supports deployment in environments with heavy network traffic and increased scalability requirements. For information, see *[Minimum System Requirements for NIOS-X Servers](https://docs.infoblox.com/space/BloxOneInfrastructure/873758806/Minimum+System+Requirements+for+NIOS-X+Servers)*.

## **Infoblox Threat Defense – October 17, 2025**

##### **Infoblox introduces enhancements to the Bandwidth Savings Monitor and Threat Defense Security Reports.**

This update replaces the Bandwidth Savings pie chart with a donut chart for improved readability and data clarity. It also expands the Comprehensive Security and Executive Summary reports to include additional metrics and enhanced visualization for First to Detect, Predictive Intelligence, and Lookalike Domain Monitoring. For information see *[Viewing Security Workspace](https://docs.infoblox.com/space/BloxOneCloud/1588592724/Viewing+Security+Workspace)* and *[Summary Reports](https://docs.infoblox.com/space/BloxOneThreatDefense/35375414/Summary+Reports)*.

## **Infoblox Threat Defense – October 8, 2025**

##### **Infoblox Introduces Data Connector HA/DR for Enhanced Cloud Ecosystem Continuity.**

Cloud Data Connector now supports high availability (HA) through pairing. If the primary fails, the secondary automatically takes over, and cloud sources seamlessly redirect data flows to maintain continuity.

This ensures a reliable data path, allowing Security Operations to receive timely alerts and enabling the SOC to respond quickly—thus improving Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR). With automated failover, customers no longer need to manually resolve cloud data flow issues and can focus on deriving value from dependable security use cases. For information, see Setting Up a High Flow (HA) Fallback Configuration. *[Setting Up a High Flow (HA) Fallback Configuration](https://docs.infoblox.com/space/BloxOneCloud/1638891602/Setting+Up+a+High+Flow+(HA)+Fallback+Configuration)*.

##### **Ecosystem Integration Test Event is now available to validate connectivity and response on the receiving side.**

Ecosystem Integrations that use automation scripts can be difficult to validate, often needing to wait until the correct event is produced. Now customers can send a test event for these ecosystem automation integrations to not only validate connectivity but validate the response on the receiving side. This greatly simplifies troubleshooting and validation.

## **Infoblox Threat Defense – September 27, 2025**

##### **Infoblox Threat Defense introduces Detect Mode, enabling organizations to assess the value of Protective DNS without making disruptive infrastructure changes.**

Threat Defense Detect Mode lets organizations validate Protective DNS value without disruptive infrastructure changes. Instead of redirecting queries to the cloud, Detect Mode forwards DNS query and response logs to the Threat Defense service for full threat detection. Security teams gain visibility into threats and can forward findings to SOC tools such as SIEM or SOAR for investigation and response. Available on all supported Infoblox NIOS versions, Detect Mode enables IT and Network Architects to evaluate Threat Defense benefits in a transparent, non-intrusive way. For more information, see *[Infoblox Threat Defense Detection Mode](https://docs.infoblox.com/space/BloxOneThreatDefense/1638924360/Infoblox+Threat+Defense+Detection+Mode)*.

##### **Infoblox has deployed version 3.0.9 of the DNS Forwarding Proxy (DFP) service for CNIOS hosts, delivering enhanced connectivity and resiliency.**

The DFP service upgrade (v3.0.9) for all CNIOS hosts delivers critical enhancements aimed at strengthening system connectivity and overall resiliency.

## **Infoblox Threat Defense – September 15, 2025**

##### **Training and education materials are now available to all Infoblox users through Launchpad.**

This platform offers unlimited access to learning resources, hands-on labs, and product updates across the entire Infoblox suite. To get started, navigate to **Guidance** > **Launchpad** in the Infoblox Portal.

## **Infoblox Threat Defense – September 12, 2025**

##### **Threat Defense introduces enhancements to the redirect page.**

Organizations can customize redirect messages explaining why access to a website is blocked. The redirect page can include the following information when applicable: Blocked Domain/IP Address, Threat Information, Policy Name, Security Feed, Custom List Name, Filter Name, Domain Category, and Application Name. For more information, see *[Redirect Page](https://docs.infoblox.com/space/BloxOneThreatDefense/1673297931/Redirect+Page)*.

##### **Infoblox introduces the configuration of Anycast DNS on NIOS-X servers in Microsoft Azure deployments.**

Configuring Anycast DNS on NIOS-X servers in Azure could improve performance by routing users to the nearest DNS server, reducing latency and speeding up resolution times. Anycast provides built-in load distribution, simplifies client configuration with a single IP address, and supports scalability and global performance, making your DNS infrastructure more resilient, efficient, and user-friendly.

## **Infoblox Threat Defense – September 2, 2025**

##### **Infoblox Threat Defense introduces Detect Mode, enabling organizations to assess the value of Protective DNS without making disruptive infrastructure changes.**

Detect Mode allows organizations to validate the value of Protective DNS without requiring disruptive infrastructure changes. Instead of redirecting DNS queries to the cloud, Detect Mode forwards DNS query and response logs to the Threat Defense service for comprehensive threat detection. Security teams gain visibility into threats and can forward findings to SOC tools such as SIEM or SOAR for investigation and response. Available on all supported Infoblox NIOS versions, Detect Mode enables IT and network architects to evaluate Threat Defense benefits in a transparent and non-intrusive way. Detect Mode is available only for currently supported NIOS versions. For information, see *[Infoblox Threat Defense Detection Mode](https://docs.infoblox.com/space/BloxOneThreatDefense/1638924360)*.

## **Infoblox Threat Defense – August 21, 2025**

##### **NIOS-X supports sequential configuration updates.**

NIOS-X now allows DNS/DHCP/DFP configuration updates to be applied sequentially, even when using scheduled updates. Configuration updates are performed one NIOS-X server at a time, progressing to the next server only after the configuration on the current server has been updated successfully.

## **Infoblox Threat Defense – August 8, 2025**

##### **Infoblox Threat Defense introduces Retrospective Detection in SOC Insights.**

Retrospective Detection in SOC Insights identifies whether any newly classified malicious domains were retrospectively accessed within a customer’s environment during the 30 days prior to their classification as threats. This insight helps SOC teams assess historical exposure and monitor affected assets to determine appropriate follow-up actions. For information, see *[SOC Insights](https://docs.infoblox.com/space/BloxOneThreatDefense/501514252/SOC+Insights)*.

## **Infoblox Threat Defense – August 4, 2025**

##### **Infoblox Threat Defense introduces a new Security Workspace emphasizing Enhanced Threat and Asset Intelligence monitoring.**

Infoblox Threat Defense has launched a new Security Workspace, designed to give security teams a more comprehensive, real-time view into DNS-based threats and asset intelligence. With an emphasis on visibility, interactivity, and actionable data, this enhanced dashboard streamlines threat detection and response while helping organizations better understand the security posture of their network assets.

**Threats**: The Threats view within the Security Workspace empowers analysts to monitor and respond to DNS-based threats in real time. Summary monitors and drill-down capabilities provide a clear breakdown of blocked and allowed threats, threat class, severity level, and geographic distribution. Users can quickly filter and group threat data to reveal patterns, uncover predictive intelligence, and access key performance indicators such as bandwidth savings and first-to-detect metrics. The interactive visualizations and contextual detail allow for fast identification of emerging attack vectors, enabling security teams to act decisively, and with confidence.

**Assets**: The Assets view enhances visibility into devices and systems impacted by, or exposed to, DNS threats. With categorized views of verified and unverified assets, risk levels, and associated security events, users can assess asset vulnerability and prioritize response based on criticality. Mini monitors and detailed tables help identify at-risk endpoints, track policy violations, and surface high-value targets. Filters and grouping functions add further clarity, supporting more informed risk management decisions.

For information, see *[The Security Workspace](https://docs.infoblox.com/space/BloxOneCloud/1588592724/The+Security+Workspace)*.

##### **Infoblox introduces the new Risk Posture monitor, designed to offer actionable tips for enhancing your organization’s security posture. This monitor replaces the deprecated SOC Insights Configuration information page.**

The Risk Posture feature evaluates your organization’s configuration across a three-tier scale: **Average**, **Good**, and **Optimal**. Clicking on the posture gauge or the associated risk count directs users to the Risk Posture information page, where detailed insights into configuration checks are available.

Additionally, the page provides recommended steps for remediation, helping organizations progress toward an optimal configuration status. For information, see *[Managing the Configuration Lifecycle](https://docs.infoblox.com/space/BloxOneThreatDefense/1088455433/Managing+the+Configuration+Lifecycle)*.

## **Infoblox Threat Defense – July 29, 2025**

##### **Infoblox Endpoint version 2.5.0 introduces tamper protection for Windows.**

This release includes enhanced hardening measures designed to prevent common tampering attempts, such as disabling services, terminating processes, or deleting configuration files. For information, see *[Managing Endpoint](https://docs.infoblox.com/space/BloxOneThreatDefense/35374260/Managing+Endpoint)* and *[Endpoint Tamper Protection](https://docs.infoblox.com/space/BloxOneThreatDefense/1613135922/Endpoint+Tamper+Protection)*.

## **Infoblox Threat Defense – July 18, 2025**

##### **Infoblox Endpoint enhances protection visibility by updating the endpoint “status” column.**

The Infoblox Endpoint status column has been revised to better reflect the current protection state of endpoints. The former values of “Active,” “Inactive,” and “Disabled” have been replaced with the following, more descriptive labels: Protected: The device **is secured** by Infoblox.

**Unprotected**: The device **is not secured** by Infoblox.

**Protected - OnPrem**: The on-premises device **is secured** using corporate network DNS.

**Unprotected - OnPrem**: The on-premises device **is not secured** using corporate network DNS.

**Unknown**: The device status is currently unknown. The protection state cannot currently be verified.

**Disabled**: The device has been disabled. Protection has been intentionally turned off.

For information, see *[Managing Endpoint](https://docs.infoblox.com/space/BloxOneThreatDefense/35374260/Managing+Endpoint)* and *[Viewing Endpoint Devices](https://docs.infoblox.com/space/BloxOneThreatDefense/35470720/Viewing+Endpoint+Devices)*.

## **Infoblox Threat Defense – July 17, 2025**

##### **For accounts with the SANDBOX entitlement, the Infoblox Portal now includes a hierarchical tree menu that enables users to easily locate and access subtenants.**

Subtenants are now organized under their corresponding primary tenants, allowing for clearer identification and streamlined navigation. For more information, see *[Viewing Subtenants](https://docs.infoblox.com/space/BloxOneInfrastructure/327778336/Viewing+Subtenants)*.

## **Infoblox Threat Defense – July 14, 2025**

##### **CrowdStrike EDR is now available for Infoblox Ecosystem.**

Infoblox has added Ecosystem support with a new integration between Infoblox Threat Defense, SOC Insights and CrowdStrike. This capability enables detected threats—such as DNS-based data exfiltration, command-and-control attempts and domain-generated algorithm (DGA) activity—to be automatically sent from Infoblox to CrowdStrike. Once received, CrowdStrike can instantly quarantine the affected endpoint, stopping threats at both the network and device level.

##### **Infoblox has added Ecosystem support with a new integration between Infoblox Threat Defense, SOC Insights, and CrowdStrike.**

This capability enables detected threats—such as DNS-based data exfiltration, command-and-control attempts and domain-generated algorithm (DGA) activity—to be automatically sent from Infoblox to CrowdStrike. Once received, CrowdStrike can instantly quarantine the affected endpoint, stopping threats at both the network and device level.

## **Infoblox Threat Defense – June 27, 2025**

##### **Infoblox adds a new Point of Presence (PoP) in Hong Kong.**

Infoblox is expanding its global infrastructure with the addition of a new Point of Presence (PoP) in the AWS ap-east-1 region (Hong Kong). This enhancement improves performance and resiliency for regional DNS security services. This PoP is available only via regional IP addresses or manual DFP and Endpoint Group settings.

The Anycast IP addresses for the new PoP are 52.119.41.65 and 103.80.6.65. For more information, see see *[Forwarding DNS Traffic to Infoblox Platform](https://docs.infoblox.com/space/BloxOneThreatDefense/35408116/Forwarding+DNS+Traffic+to+Infoblox+Platform)*.

## **Infoblox Threat Defense – June 26, 2025**

##### **Enhanced Platform Notifications: Type and Subtype**

Stay informed with our updated platform notifications. With streamlined categorization and filtering by type and subtype, users can easily find actionable notifications specific to their products and interests, making it easier to distinguish critical updates from general notifications.

##### **Terminology Update: “Sandboxes” are renamed to “Subtenants”**

In the Infoblox Portal, “Sandboxes” have been renamed to “Subtenants” to better align with industry-standard terminology. This change does not impact existing functionality, and no action is required from users. The use of Subtenants remains subject to the existing *[Sandbox terms and conditions](https://www.infoblox.com/company/legal/bloxone-sandbox-supplemental-terms-and-conditions/)*.

## **Infoblox Threat Defense – June 11, 2025**

##### **The Infoblox Portal now supports infinite scrolling for table views on the Servers and Protocol Services pages.**

This enhancement replaces the previous paginated table view with an infinite scrolling interface, allowing users to continuously load more data as they scroll. Infinite scrolling is now the default behavior for these pages. Additionally, the total number of objects is displayed at the bottom of the page for reference.

## **Infoblox Threat Defense – June 3, 2025**

##### **Infoblox Endpoint announces the support for Chrome Manifest V3.**

Infoblox Endpoint for Chrome receives a major upgrade to support Chrome Manifest V3. The existing Chrome Manifest V2 application and extension will be deprecated by the end of May 2025. To maintain protection for Chrome devices, install the new extension before the end of May. For information, see *[ChromeBook DOH Enrollment (MV3 ChromeOS)](https://docs.infoblox.com/space/BloxOneThreatDefense/1227128856/ChromeBook+DOH+Enrollment+(MV3+ChromeOS))*.

## **Infoblox Threat Defense – May 22, 2025**

##### **Data Connector now supports high-availability and failover destinations natively within Data Connector for HTTP and Syslog.**

Organizations can now configure two destinations in HA/failover mode for HTTP and syslog destinations such as SIEMs. When the primary destination becomes unreachable, Data Connector automatically detects and reroutes traffic to the secondary destination. HA/failover for destinations ensures minimal data loss by removing manual reconfiguration of redundant destinations for fast and automated recovery when failure is encountered.

For more information, see *[Configuring Destinations](https://docs.infoblox.com/space/BloxOneCloud/35430092/Configuring+Destinations)*.

## **Infoblox Threat Defense – May 2, 2025**

##### **Infoblox adds a new Point of Presence (PoP) in Hyderabad, India.**

Infoblox is expanding its global infrastructure with the addition of a new Point of Presence (PoP) in the AWS ap-south-2 region (Hyderabad, India). This enhancement improves performance and resiliency for regional DNS security services.

- The Regional Anycast IP addresses for the new PoP are 52.119.41.64 and 103.80.6.64.
- The CNAME ap-south-2-geo.threatdefense.infoblox.com resolves to 52.119.41.64.

For more information, see *[Forwarding DNS Traffic to Infoblox Platform](https://docs.infoblox.com/space/BloxOneThreatDefense/35408116/Forwarding+DNS+Traffic+to+Infoblox+Platform)*.

## **Infoblox Threat Defense – April 28, 2025**

#### **Infoblox Threat Defense SOC Insights now supports exclusion of network for Insight generation.**

A new Exclusions section in SOC Insights Settings configuration allows users to exclude traffic for Insight generation (e.g., guest network). The excluded traffic is configured using DFPs and/or Network subnets using CIDR notation. This reduces noise and helps highlight the most relevant insights. For more information, see *[SOC Open Insights - Threats View](https://docs.infoblox.com/space/BloxOneThreatDefense/497811915/Open+Insights+-+Threats+View)*.

##### **Infoblox Threat Defense SOC Insights now supports enforcement action filtering with two options: Blocked and Allowed.**

This feature allows SOC Insights to prioritize allowed (unblocked) events by using the Enforcement Action filtering. The default filter setting is “Allowed,” ensuring that permitted activity is prioritized in the analysis. For more information, see *[SOC Open Insights - Threats View](https://docs.infoblox.com/space/BloxOneThreatDefense/497811915/Open+Insights+-+Threats+View)*.

## **Infoblox Threat Defense – April 24, 2025**

##### **The Discovery service in the Infoblox Portal now supports Full Network Ping Sweep for on-premises environments.**

The Discovery service in the Infoblox Portal now supports a Full Network Ping Sweep capability designed specifically for on-premises environments. This feature scans the entire IP ranges using ICMP Echo Requests (“ping” requests) and identifies which IP addresses respond, indicating active devices. Unlike targeted or Smart Ping Sweeps, this method performs an exhaustive scan of all addresses within the defined on-premises network segment. It enables administrators to quickly identify which on-premises IPs are live and reachable, helping support asset discovery, inventory validation, and local network troubleshooting. For more information, see *[Viewing the Network Workspace](https://docs.infoblox.com/space/BloxOneInfrastructure/606339272/Creating+Discovery+-+Discovery+Settings)*.

##### **Universal Asset Insights now supports exporting asset inventory data.**

Asset inventory data can now be exported to a CSV file. Users can export a single, multiple, or the entire asset inventory data all at once. The export process also provides an option to customize the attributes before exporting. For more information, see *[Exporting Asset Inventory](https://docs.infoblox.com/space/BloxOneDDI/1381565981/Exporting+Assets)*.

##### **Universal Asset Insights now supports permanently deleting IPAM data and assets for cloud providers.**

When deleting a network discovery configuration for cloud providers, users can choose to permanently delete IPAM data, asset inventory data, or both. Once the IPAM data and assets are deleted, they cannot be recovered from the Recycle Bin. For more information, see *[Deleting a Network Discovery Configuration](https://docs.infoblox.com/space/BloxOneDDI/512229416/Deleting+a+network+discovery+configuration)*.

## **Infoblox Threat Defense – April 2, 2025**

##### **The Infoblox Portal navigation now displays features accessible through product upgrades.**

Customers can easily see the features available to their account with a product upgrade via the **Configure** and **Monitor** lifecycle navigation.

##### **Infoblox Portal has enhanced the handling of expired subscriptions.**

Infoblox has updated the license entitlement dashboards to remove subscriptions that are over 60 days past expiration.

##### **Infoblox Portal introduces the Education Launchpad.**

Infoblox introduces a **Product Learning** link for the new Infoblox Education Launchpad, located under the **Guidance** navigation of the Infoblox Portal. The Launchpad provides self-led training, hands-on labs, and a list of upcoming training events.

## **Infoblox Threat Defense – March 24, 2025**

##### **Infoblox Data Connector now supports multiple traffic flows of the same destination type (syslog and HTTP) to a single destination host.**

Infoblox Cloud Data Connector can now create multiple traffic flows of the same destination type (syslog and HTTP) to the same destination host. In the past customers who needed to send two syslog or HTTP streams to the same destination host had to combine the streams which could create issues if different filters needed to be applied. This became an issue with NIOS and Universal DDI each wanting to send their own syslog stream to a SIEM. For more information, see *[Configuring Traffic Flows](https://docs.infoblox.com/space/BloxOneCloud/35397475/Configuring+Traffic+Flows)*.

## **Infoblox Threat Defense – March 21, 2025**

##### **Infoblox Ecosystem integration update notifications will now be provided to configured users in the Infoblox Portal.**

Infoblox Ecosystem customers who are using a supported ecosystem integration will now receive integration version update notifications through the Infoblox Portal. This targeted approach ensures that customers who benefit the most from these updates are informed. Users of supported integrations will automatically receive the notifications when new versions are posted on from the Ecosystem Portal. For information, see see *[Infoblox Platform Notifications](https://docs.infoblox.com/space/BloxOneCloud/1196590637/Viewing+the+Network+Workspace)*.

##### **Infoblox Threat Defense introduces two new Network Workspace monitors, providing real-time visualization and insight.**

DHCP Range Utilization: The DHCP Range Utilization summary monitor provides a quick view of DHCP range usage, helping users assess resources and project future needs. This summary monitor helps admins avoid running out of IP addresses, thereby enabling proactive management. For more information, see *[Viewing the Network Workspace](https://docs.infoblox.com/space/BloxOneCloud/1196590637/Viewing+the+Network+Workspace)*.

Subnet Utilization: The Subnet Utilization summary monitor helps users optimize IP address usage by highlighting heavily utilized subnets and enabling efficient resource reallocation for better network management. It enhances network efficiency, scalability, and security while enabling proactive capacity planning and compliance. For more information, see *[Viewing the Network Workspace](https://docs.infoblox.com/space/BloxOneCloud/1196590637/Viewing+the+Network+Workspace)*.

##### **Infoblox Threat Defense now supports assigning a NIOS-managed host to a NIOS-managed subnet or range via the Infoblox Portal.**

Infoblox Threat Defense now supports assigning a Grid Master, Grid Master Candidate, or Standalone appliance to a NIOS-managed subnet or range via the Infoblox Portal. This assignment can be performed without logging into the NIOS interface. For more information, see *[Assigning a NIOS Host from the Infoblox Portal](https://docs.infoblox.com/space/BloxOneDDI/1293516805/Assigning+a+NIOS+Host+from+the+Infoblox+Portal)*.

##### **Infoblox now supports NIOS-X server deployments in the following environments:**

- Nutanix AHV Hypervisor
- VMware ESXi version 8.0.3
- Red Hat OpenShift

## **Infoblox Threat Defense – March 7, 2025**

##### **Infoblox has released Infoblox Endpoint for Ubuntu 24.04.**

The Endpoint for Ubuntu 24.04 release includes enhancements and bug fixes for Ubuntu 22.04. Please note that Infoblox Endpoint for Ubuntu 20.04 is being discontinued. For information, see *[Managing Endpoint](https://docs.infoblox.com/space/BloxOneThreatDefense/35374260/Managing+Endpoint)*.

## **Infoblox Threat Defense – February 28, 2025**

##### **Infoblox Threat Defense introduces an enhanced license dashboard with utilization metrics and trending.**

The new Threat Defense Licensing Dashboard offers an in-depth overview of Threat Defense entitlements and utilization. It is designed to provide insights into trends associated with key licensing metrics, including Queries per User, Dossier™ Queries, and Ecosystem Events. For more information, see *[Viewing License Entitlements](https://docs.infoblox.com/space/BloxOneCloud/35397411/Viewing+License+Entitlements)*.

## **Infoblox Threat Defense – February 20, 2025**

##### **Infoblox Threat Defense introduces enhancements to the Executive Summary Report and Comprehensive Security Report.**

These enhancements provide more comprehensive, actionable information and improved usability to support security teams in making informed decisions. Key enhancements include the following: A streamlined layout with a redesigned single-view summary presenting overall security statistics at a glance; improved highlighting of key traffic items that emphasizes critical customer traffic across all modules of Threat Defense; and dynamic DNS traffic anomaly detection of traffic patterns utilizing mean deviation analysis to highlight irregularities over the report period.

The enhanced Executive Summary and Comprehensive Security Reports are available to Threat Defense Business Cloud and Advanced licensed users. For information, see *[Summary Reports](https://docs.infoblox.com/space/BloxOneThreatDefense/35375414/Summary+Reports)*.

## **Infoblox Threat Defense – February 13, 2025**

##### **Infoblox Threat Defense introduces the Industry Vertical Analysis feature, allowing organizations to benchmark their security posture against peers within the same industry.**

Infoblox Threat Defense introduces the Industry Vertical Analysis feature, allowing organizations to benchmark their security posture against peers within the same industry. This new feature analyzes DNS traffic and security events across key categories, including:

- **Malicious Threats**
- **Risky Threats**
- **Threat Insights**
- **Threat Actors**
- **Zero Day Detection**

By comparing your security stance with industry peers and all Infoblox customers, this feature provides actionable insights to fine tune security policies and enhance your overall threat defense strategy. The analysis is based on the industry registered to your Infoblox account and presents data from three perspectives:

- **Customer-Specific** – Your organization’s unique security metrics
- **Peers from the Same Industry Vertical** – Comparative insights within your sector
- **All Customers** – Broader trends across all Infoblox users

This feature is available to Business Cloud and Advanced licensed users. To access the report, navigate to **Monitor** > **Reports** > **Security** > **Industry Vertical Analysis**.

For more information, see *[Industry Vertical Analysis](https://docs.infoblox.com/space/BloxOneThreatDefense/1184923677/Industry+Vertical+Analysis)*.

## **Infoblox Threat Defense – January 31, 2025**

##### **Infoblox Threat Defense application filtering now includes two new generative AI chatbots: DeepSeek and Qwen.**

You can track the usage of these newly added chatbots by navigating to (**Monitor** > **Reports** > **Security** > **Application Discovery**) under the **Applications - Generative AI category.**

Using application filters, you can assign an application a status of Approved or Unapproved based on whether Application Discovery indicates it is safe or unsafe. An application’s status can be revised and updated at any time.

For information, see *[Creating Application Filters](https://docs.infoblox.com/space/BloxOneThreatDefense/56656233/Creating+Application+Filters)*.

## **Infoblox Threat Defense – January 24, 2025**

##### **Infoblox Endpoint has released an updated version of its endpoint app for Android devices, now available on the Google Play Store.**

The latest update addresses minor issues when used with Android 14 devices. For information, see *[Managing Mobile Endpoint](https://docs.infoblox.com/space/BloxOneThreatDefense/35470955/Managing+Mobile+Endpoints)*.

## **Infoblox Threat Defense – January 24, 2025**

##### **Infoblox Endpoint has released an updated version of its endpoint app for Android devices, now available on the Google Play Store.**

The latest update addresses minor issues when used with Android 14 devices. For information, see *[Managing Mobile Endpoint](https://docs.infoblox.com/space/BloxOneThreatDefense/35470955/Managing+Mobile+Endpoints)*.

## **Infoblox Threat Defense – January 13, 2025**

##### **Infoblox introduces an event selection field option for SOC Insights logs exported to Data Connector.**

This update features a new traffic flow widget in Data Connector, enabling users to select SOC Insights fields for HTTP destinations in non-DNS logs. For information, see Creating Traffic Flows and Log Source Configuration Export Options.

For more information, see *[Creating Traffic Flows](https://docs.infoblox.com/space/BloxOneCloud/35367017/Creating+Traffic+Flows)* and *[Log Source Configuration Export Options](https://docs.infoblox.com/space/BloxOneCloud/774964692/Log+Source+Configuration+Export+Options)*.

## **Infoblox Threat Defense – January 8, 2025**

##### **Infoblox has planned a deployment for additional security mechanisms on Thursday, January 23 at 6 PM PST to protect the Infoblox Portal.**

Infoblox is deploying additional security mechanisms to protect the Infoblox Portal. During the deployment update on Thursday, January 23rd at 6 PM PST, the Infoblox Portal will remain available, and core services are unlikely to be impacted.

## **Infoblox Threat Defense – December 11, 2024**

##### **Infoblox now provides a new configuration landing page showing data for key services based on entitlement.**

When users log on to the Infoblox Portal, the configuration landing page displays data for key services based on license entitlements.

##### **The Infoblox Portal now displays the “What’s New” content in a new modal dialog.**

This new dialog can be hidden by selecting the “Do not show me again” checkbox.

## **Infoblox Threat Defense – December 10, 2024**

##### **Infoblox bare-metal deployment now supports Red Hat version 9.5.**

For more information, see *[Bare-Metal Deployment](https://docs.infoblox.com/space/BloxOneInfrastructure/204538556)*.

## **Infoblox Threat Defense – November 25, 2024**

##### **Infoblox Threat Defense introduces a feedback loop for Threat Intelligence (TI) Detectors.**

This feature enables users to activate, deactivate, and remove TI domains from their custom lists. For information, see *[Custom Lists](https://docs.infoblox.com/space/BloxOneThreatDefense/35473695/Custom+Lists)*.

##### **Infoblox Threat Defense adds Unicode support for custom lists and internal domain lists.**

This enhancement allows users to input domains using Unicode characters in both custom lists and internal domain lists. For information, see *[Creating Custom Lists](https://docs.infoblox.com/space/BloxOneThreatDefense/35469424/Creating+Custom+Lists)* and *[Creating an Internal Domain](https://docs.infoblox.com/space/BloxOneThreatDefense/35375088/Creating+an+Internal+Domain)*.

## **Infoblox Threat Defense – November 22, 2024**

##### **Infoblox Threat Defense enhances the Application Discovery feature to improve the detection and blocking of generative AI applications.**

Infoblox is excited to announce significant enhancements to our Application Discovery feature within Threat Defense Advanced, now with improved capabilities to detect and block applications used for generative AI. Recognizing the high risk of data loss associated with unmanaged generative AI, these updates are designed to provide organizations with additional protection. The new functionality distinguishes between consumer and enterprise versions of select generative AI applications, allowing for approved use while blocking unmanaged consumer versions. This update helps you leverage the benefits of generative AI securely and efficiently.

These enhancements underscore Infoblox’s commitment to continuous innovation and delivering increased value to our customers. By integrating these advanced detection and blocking capabilities, organizations can mitigate the risks associated with shadow IT and data exfiltration, ensuring compliance and enhancing overall security posture. Customers will benefit from improved visibility and control over application usage, empowering them to make informed decisions and maintain a secure, compliant environment. You can find these detections in the Infoblox Platform (**Monitor** > **Reports** > **Security** > **Application Discovery**), under the Applications - Generative AI category. This category was previously named AI Chatbots. For information, see *[Creating Application Filters](https://docs.infoblox.com/space/BloxOneThreatDefense/56656233/Creating+Application+Filters)*.

## **Infoblox Threat Defense – November 14, 2024**

##### **Infoblox Endpoint version 2.4.20 is now available for Windows and macOS.**

This update introduces support for macOS Sequoia 15.0.1 and above, along with stability improvements and fixes for minor issues on both Windows and macOS. Customers planning to upgrade their macOS to version 15 should follow these steps:

- Test the upgrade on a small number of Mac computers first, rather than upgrading all machines at once.:Test the upgrade on a small number of Mac computers first, rather than upgrading all machines at once.
- For Macs with Infoblox Endpoints, upgrade a few computers initially, monitor for any issues, and only proceed with upgrading the remaining devices if no problems are detected.

For more information about Infoblox Endpoint, see *[Managing Endpoint](https://docs.infoblox.com/space/BloxOneThreatDefense/35374260/Managing+Endpoint)*.

## **Infoblox Threat Defense – November 8, 2024**

##### **Infoblox Dossier now treats DNS lame delegation as a vulnerability.**

Lame delegation occurs when one or more delegated nameservers fail to provide authoritative DNS information. When a lame delegation is detected on the queried domain, Dossier highlights this vulnerability along with the level at which this was detected, allowing customers to take appropriate action on the affected domain and nameserver.

For information, see *[Dossier Summary Report](https://docs.infoblox.com/space/BloxOneThreatDefense/271975496/Summary)*.

## **Infoblox Threat Defense – October 21, 2024**

##### **Infoblox now allows users to change the default password for the Device UI when configuring NIOS-X physical servers. This can be done through the Infoblox Portal, Device UI, or Debug CLI.**

When deploying NIOS-X servers, Infoblox initially uses a default username and password for accessing the Device UI. Users can now change this default password via the Infoblox Portal, Device UI, or Debug CLI. Once changed, the new password will be synchronized across the console and Device UI, allowing for SSH and HTTPS access.

## **Infoblox Threat Defense – October 18, 2024**

##### **Infoblox Dossier now features streamlined false-positive reporting.**

The Infoblox Dossier feedback functionality has been updated to direct critical and blocking issues to the Support Portal for ticket creation and to the Infoblox support team for assistance with Service-Level Agreement (SLA) compliance. This functionality allows users to submit feedback on the following indicators: False Positive, False Negative, and Content Categorization.

For information, see *[Dossier Threat Research Feedback](https://docs.infoblox.com/space/BloxOneThreatDefense/230493737/Dossier+Threat+Research+Feedback)*.

## **Infoblox Threat Defense – September 24, 2024**

##### **Data Connector introduces HTTP Destination support for Microsoft Sentinel.**

This enhancement facilitates the setup of Microsoft Sentinel as a destination in the Infoblox Platform. For more information, see *[Data Connector](https://docs.infoblox.com/space/BloxOneThreatDefense/35472014/Data+Connector)*.

## **New Infoblox Portal – September 05, 2024**

##### Infoblox is pleased to announce a significant update to the Infoblox Portal featuring a modern UX refresh designed to enhance your experience and productivity. (UI updates will be available for the EU Region users in October).

[Watch the video guide to the new Infoblox Portal.](https://docs.infoblox.com/space/BloxOneDDI/847085580/Video)

This update introduces:

**Optimized Navigation Experience**: Our redesigned interface offers more intuitive and seamless navigation, allowing you to find what you need faster and more efficiently through the following enhancements.

- **Bespoke Lifecycles**:
  - **Monitoring lifecycle**: This lifecycle focuses on providing business visibility through custom asset, security, and networking monitor Workspaces. These workspaces are tailored to deliver real-time insights and visualizations, helping you keep a close eye on critical metrics and system health**.**
  - **Configuration lifecycle**: Optimized to configure and deliver network services efficiently, this lifecycle follows best practices to ensure smooth and effective network management. It simplifies complex configurations, making deploying and managing network services easier.
- **Improved Navigation Flows**: Core task focus areas such as Security, Network, and Administration are now more logically grouped. This logical grouping streamlines your workflow, making accessing the tools and information you need easier without unnecessary clicks or searches.
- **Industry-Standard Layouts**: User Profile options, Account selection, and Notifications have been redesigned to align with industry standards. This redesign enhances usability and consistency across the portal, providing a familiar and user-friendly experience.

**Enhanced Server and Service Deployment Management Workflows:**

- **Universal DDI Offering**: Introducing NIOS-X As-a-Service, a fully managed deployment solution that enables network protocol service delivery without the need for infrastructure investments. This new deployment type simplifies the process of delivering network services, allowing you to focus on your core business activities.
- **Dedicated Servers Section:** Users of traditional services will now find virtual and physical hosts under a dedicated Servers section. This section includes our next-generation NIOS-X servers (formerly BloxOne) and our industry-leading NIOS solution, providing a comprehensive view of your deployment infrastructure.
- **Manage NIOS with Universal DDI**: Single pane of glass management of NIOS Grids and Members directly within the Infoblox Portal

**Increased Visibility to Critical Metrics**:

Stay informed on key performance indicators with our new dashboards and KPIs, designed to provide clear and actionable insights:

- **Custom Workspaces**: Workspaces for Assets, Security, and Networking feature custom-designed monitors crafted by our industry experts. These monitors deliver out-of-the-box real-time visualizations of critical metric summaries, allowing users to quickly assess the health of their networking and security environment. With these insights, you can take immediate action without waiting for reports or updates.
- **Business KPI Ribbon**: A new Business KPI ribbon provides line-of-sight visibility into critical success metrics. This feature allows users to quickly understand the positive impact of the Infoblox market-leading DDI solution in securing critical business assets, providing 24x7 highly scalable network services, and offering centralized management across both cloud and on-premises deployments.

**Provide Tailored User Access with Access Views**

Access Views enables users to set custom fine-grained access rules for specified users or groups and associated DDI resources.

##### **Infoblox Endpoint releases version 2.4.16 for Windows and macOS**

This release addresses an issue with statically assigned DNS servers on network interfaces. For more information about Infoblox Endpoint, see *[Managing Endpoint](https://docs.infoblox.com/space/BloxOneThreatDefense/35374260/Managing+Endpoint)*.

## **BloxOne Threat Defense – August 29, 2024**

##### **Data Connector introduces BloxOne Cloud-to-Cloud SIEMs, emphasizing fully managed services with seamless integrations with third-party SaaS services.**

Key enhancements in this release:

- Facilitates the setup of a Syslog destination in BloxOne Cloud.
- Facilitates the setup of automations in BloxOne Cloud.
- Facilitates the setup of an HTTP Destination in BloxOne Cloud.

For more information, see *[Data Connector](https://docs.infoblox.com/space/BloxOneThreatDefense/35472014/Data+Connector)* and *[Infoblox Ecosystem](https://docs.infoblox.com/space/BloxOneThreatDefense/778240004/Ecosystem+Portal)*.

##### **Infoblox Ecosystem now offers support for automation integrations running in BloxOne Cloud, enabling the automation of Cloud-to-Cloud workflows.**

Users have the ability to configure automated workflows, with service instance options specifically for setting up cloud-to-cloud flows. For more information, see *[Data Connector](https://docs.infoblox.com/space/BloxOneThreatDefense/35472014/Data+Connector)* and *[Infoblox Ecosystem](https://docs.infoblox.com/space/BloxOneThreatDefense/778240004/Ecosystem+Portal)*.

## **BloxOne Threat Defense – August 19, 2024**

##### **To enhance Threat Defense services, Infoblox has launched a new second-level infobloxtd.com domain along with additional IP addresses, 103.80.6.120 and 52.119.41.120.**

Infoblox strongly recommends that all customers update their network configuration to enable access to the new IP addresses, the second-level domain, and all its subdomains. Infoblox plans to launch services utilizing these IP addresses and hostnames under infobloxtd.com by mid-September 2024.

##### **Data Connector introduces additional event field options for Atlas Notification settings.**

This update introduces a refined traffic flow widget in the Cloud Services Portal that allows users to choose subtypes and event fields seamlessly. For information, see *[Creating Traffic Flows](https://docs.infoblox.com/space/BloxOneDDI/186649073)*.

## **BloxOne Threat Defense – August 14, 2024**

##### **Data Connector introduces additional event field options for Audit Log settings.**

This update introduces a refined traffic flow widget in the Cloud Services Portal that allows users to choose subtypes and event fields seamlessly. For information, see *[Creating Traffic Flows](https://docs.infoblox.com/space/BloxOneDDI/186649073)*.

## **BloxOne Threat Defense – August 5, 2024**

##### **Infoblox launches the Infoblox Ecosystem Program.**

This program includes a self-service portal, offering certified, out-of-the-box integrations with leading technology providers. The program is powered by Automations, an event-driven automation framework designed to streamline integration development. These integrations have undergone rigorous testing and validation to ensure compatibility and support by Infoblox. The program aims to help NetOps and SecOps teams automate workflows, enhance security, and improve collaboration across on-premises, hybrid, and multi-cloud environments. For information, see *[Ecosystem Portal](https://docs.infoblox.com/space/BloxOneThreatDefense/778240004/Ecosystem+Portal)*.

## **BloxOne Threat Defense – August 2, 2024**

##### **Data Connector now supports sending logs to an HTTP destination in Splunk CIM data format.**

When configuring a Data Connector traffic flow, you now have the option to choose Splunk CIM as the log message format when you configure HTTP as the destination. For information, see *[Setting Up HTTP](https://docs.infoblox.com/space/BloxOneThreatDefense/774635635)*.

##### **BloxOne Threat Defense releases BloxOne Mobile Endpoint for iOS without VPN dependency.**

To improve compatibility with VPN solutions, including on-demand VPN, BloxOne Mobile Endpoint for iOS will be able to use the iOS native DNS proxy framework to intercept all DNS traffic. Requirements: iOS/iPadOS 14.x and later, deployment by an MDM.For more information about BloxOne Mobile Endpoint, see *[Managing BloxOne Mobile Endpoint](https://docs.infoblox.com/space/BloxOneThreatDefense/35470955/Managing+Mobile+Endpoint)*.

## **BloxOne Threat Defense – August 1, 2024**

##### **Infoblox introduces event selection field options for BloxOne Threat Defense DNS Query/Response log, BloxOne Threat Defense Policy Hits log, BloxOne DDI DNS Query/Response log, and Service Logs exported by Data Connector.**

This update introduces a refined traffic flow widget in the Cloud Services Portal that allows users to choose subtypes and event fields seamlessly. For information, see *[Creating Traffic Flows](https://docs.infoblox.com/space/BloxOneThreatDefense/35438194)* and *[Event Field Logs](https://docs.infoblox.com/space/BloxOneThreatDefense/770048012)*.

## **BloxOne Threat Defense – July 26, 2024**

##### **BloxOne Endpoint releases version 1.0.9 for Linux Ubuntu 22**

This release includes stability improvements. For more information about BloxOne Endpoint, see *[Managing Endpoint](https://docs.infoblox.com/space/BloxOneThreatDefense/35374260)*.

## **BloxOne Threat Defense – July 24, 2024**

##### **To enhance security, the host API keys have been deprecated. However, users can still access the BloxOne APIs using the service API keys.**

For information about service API keys, see *[Configuring Service API Keys](https://docs.infoblox.com/space/BloxOneThreatDefense/35407860)*.

## **BloxOne Threat Defense – July 23, 2024**

##### **BloxOne Endpoint releases version 2.4.10 for Windows and macOS.**

This release includes stability improvements and resolves minor issues. For more information about BloxOne Endpoint, see *[Managing Endpoint](https://docs.infoblox.com/space/BloxOneThreatDefense/35374260)*.

## **BloxOne Threat Defense – July 12, 2024**

##### **BloxOne introduces tagging enhancements that restrict tag values displayed during tag addition, application, and filtering to those currently assigned to objects. Additionally, predefined tag values can now be defined through restricted tags, instead of freeform tags. To explicitly add values to a freeform tag, convert the tag to a restricted tag first.**

      For more information, see *[Managing Tags](https://docs.infoblox.com/space/BloxOneThreatDefense/35407270)*.

## **BloxOne Threat Defense – June 21, 2024**

##### **BloxOne enhances the performance and usability of Global Search on the Cloud Services Portal, making it easier and faster for users to find what they need.**

Global search includes the following enhancements:

- Users can now start a search by pressing the **Enter** key after entering key words.
- Quick results will display the top three relevant results.
- Users will see two groups of results: one for **Exact Matches** and the other for **Related Results**.
- Exact match results will appear within a second.
- Related results will be visible within a few seconds.

## **BloxOne Threat Defense – May 27, 2024**

##### **BloxOne Endpoint releases version 2.4.9 for Windows and MacOS.**

This release includes stability improvements and resolves minor issues. For information, see *[Managing Endpoint](https://docs.infoblox.com/space/BloxOneThreatDefense/35374260)*.

## **BloxOne Threat Defense – May 9, 2024**

##### **BloxOne Threat Defense introduces a new RPZ feed structure that provides simplicity and user-friendly feed names.**

BloxOne Threat Defense for NIOS now includes a new RPZ feed structure that provides simplicity, along with user friendly names, allowing users to set the correct policies and address the growing number of available RPZs over time. With the new structure, customers can configure their policy action correctly per their risk posture and have an “at a glance” understanding of how their network is protected. This requires removing the prior configured RPZ feeds and updating them to the consolidated new RPZs. The old RPZs will be supported until December 2024, giving time for transition to the new RPZ. The old RPZs will be deprecated after December 2024. Beyond the current RPZ updates for OnPrem, the feeds on the cloud will also be updated to reflect the same feed structure around July 2024.

Configuration Guide: *[https://docs.infoblox.com/space/BloxOneThreatDefense/622493764/Feed+Revamp+for+NIOS](https://docs.infoblox.com/space/BloxOneThreatDefense/622493764/Feed+Revamp+for+NIOS)*.

The following NIOS RPZ feeds are available based on your subscription level.  

| Feed Name | Essentials | Business On-Prem | Advanced |
| --- | --- | --- | --- |
| **Infoblox Base** | ### ✔ | ### ✔ | ### ✔ |
| **Infoblox Base IP** | NA | ### ✔ | ### ✔ |
| **Infoblox High Risk** | NA | NA | ### ✔ |
| **Infoblox Medium Risk** | NA | NA | ### ✔ |
| **Infoblox Low Risk** | NA | NA | ### ✔ |
| **Infoblox Informational** | NA | ### ✔ | ### ✔ |

## **BloxOne Threat Defense – May 1, 2024**

##### **The default time filter in BloxOne Threat Defense reports has been updated from one hour to 24 hours.**

The default time filter change applies to the following reports: DNS Activity, Security Activity, Summary Reports, Application Discovery, and Web Content Discovery. A one hour reporting option is still available, but it is no longer the default. The default time filter setting benefits our customers by improving the performance of the rendering reports.

## **BloxOne Threat Defense – April 30, 2024**

##### **BloxOne Threat Defense introduces Infoblox Threat Intel research with supporting documentation on threat actor naming conventions.**

Threat intelligence research encompasses current analyses, alerts, advisories, and various reports compiled by the Infoblox Threat Intel team. This page highlights the threat actors discovered in your network. For each threat actor, the page also displays how early Infoblox discovered it in your network. Accompanying this information is detailed documentation that outlines the team’s specific naming conventions serving as a valuable reference source for users. For information, see *[Threat Intel](https://docs.infoblox.com/space/BloxOneThreatDefense/611745916)* and *[Infoblox Threat Actor Naming Conventions](https://docs.infoblox.com/space/BloxOneThreatDefense/610861663)*.

## **BloxOne Threat Defense – April 29, 2024**

##### **Infoblox is introducing a new, real-time streaming detection called “Zero Day DNS.”**

Threat Insight – Zero Day DNS (Zero Day DNS) detects new domains observed in customer traffic to protect them from any possible targeted or spear phishing attacks. It follows a low-regret model and blocks the domain for a short >TTL of 48 hours. The domain will be released after 48 hours, by which time other security systems in place should have enough information about this new domain to protect per policy. The default recommended action for this TI-List is Block - No Redirect. The intent of this detection is to provide very near real-time protection on new domains (can detect and block within 1-2 minutes of usage). Often when new domains are not mission-critical and following a low-regret model, it’s best to have this protection in place. If for any reason the detected domains are known, verified, and needed for use, they can be added to the Default Allow list to bypass the detection. For information, see *[Zero Day DNS Configuration](https://docs.infoblox.com/space/BloxOneThreatDefense/610861135)*

##### **BloxOne Threat Defense introduces external networks verification.**

This feature allows BloxOne Threat Defense Business Cloud and Advanced customers to conveniently claim all their existing external networks, ensuring exclusive registration rights for subnets, and assuring no one else can register them in the database. This enhanced external network management capability permits the addition of large subnets (up to /8 for IPv4 and /32 for IPv6) with Infoblox’s verification. Smaller subnets (ranging from /30 to /32 for IPv4 and from /56 to /128 for IPv6) can be added without verification. For information, see Configuring External Networks. For information, see *[Configuring External Networks](https://docs.infoblox.com/space/BloxOneThreatDefense/35473665/Configuring+External+Networks)*.

##### **Infoblox announces the phase-out of the “Allow with Log” action support for content category filtering.**

This change will affect only newly created policies and policy rules, ensuring that existing security policies remain unaffected. Customers can continue to modify and apply their current policies as usual without any adjustments to already provisioned rules. However, it will not be possible to establish new rules or policies incorporating the allow-log action for content categories moving forward. For information, see *[Creating Category Filters](https://docs.infoblox.com/space/BloxOneThreatDefense/56656287/Creating+Category+Filters)*.

##### **BloxOne Threat Defense introduces agentless implementation over DoH.**

With this update, BloxOne Threat Defense can now terminate DoH connections and associate custom DoH FQDNs with specific customer policies. This allows customers to securely redirect their DNS traffic to the BloxOne Threat Defense cloud without a client and integrate our solution with third-party solutions. For information, see *[Configuring Security Policies](https://docs.infoblox.com/space/BloxOneThreatDefense/35371559/Configuring+Security+Policies)*.

##### **BloxOne Threat Defense has updated its policy framework to address potential DNS rebinding attacks.**

This update addresses attacks like DNS rebinding attacks where attackers use a malicious DNS server for reconnaissance when attempting to connect to internal services. By setting a low TTL, attackers cause the DNS record to expire quickly, leading to frequent queries that switch to internal network IP addresses. This allows them to bypass security measures, enabling harmful actions or data extraction. For information, see Configuring Security Policies. For information, see *[Configuring Security Policies](https://docs.infoblox.com/space/BloxOneThreatDefense/35371559/Configuring+Security+Policies)*.

##### **BloxOne Endpoint has released several bug fixes for Linux Ubuntu 22.**

These updates include correcting the MAC address during the login process and avoid any vulnerability of Stack canary protection, among other updates. For information, see *[Linux Client Application Deployment](https://docs.infoblox.com/space/BloxOneThreatDefense/297666539)*.

## **BloxOne Threat Defense – April 12, 2024**

##### **BloxOne consolidates notifications for host-related events, optimizing efficiency and improving system performance.**

When configuring BloxOne notifications, you can now choose **Host Status Infra** to receive important events related to the supported host metrics. The former **Host State** option will no longer be available. This enhancement helps improve system performance and reduce the number of notifications you will receive. For information, see *[Configuring Notification Delivery](https://docs.infoblox.com/space/BloxOneThreatDefense/35407896)*.

## **BloxOne Threat Defense – April 11, 2024**

##### **This release of the BloxOne Data Connector includes a few enhancements: relocation of the Data Connector tab from the Manage tab to the Integrations tab on the Cloud Services Portal, a new traffic flow configuration wizard, and the ability to add tags.**

In addition to the relocation of the **Data Connector** tab from the **Manage** tab to the **Integrations** tab, other enhancements include the release of a new traffic flow configuration wizard to improve workflow efficiency and the capability to add tags to traffic flows, sources, destinations, and ETL configurations. For information, see [*Data Connector*](https://docs.infoblox.com/space/BloxOneThreatDefense/35472014/Data+Connector).

## **BloxOne Threat Defense – April 5, 2024**

##### **BloxOne introduces enhancements that streamline account management across multiple organizations.**

The enhancements are particularly beneficial for administrators managing multiple organizations or sandboxes, simplifying the process of accessing and controlling subsidiary organizational accounts. The enhancements also overhaul the Cloud Services Portal’s current account-switching feature by introducing an improved account selection menu that can handle hundreds of organizational accounts and includes a search and filter function for better organizational account management.

Additional enhancements include the following:

- Administrators managing multiple organizations can set a default account, which is automatically accessed upon the initial connection to the Cloud Services Portal after authentication.
- Administrators are able to specify favorite organizations, which are prominently displayed at the top of the account selection window/menu for quick and easy access.

For additional information, see *[Managing BloxOne Accounts](https://docs.infoblox.com/space/BloxOneThreatDefense/573114374)*.

## **BloxOne Threat Defense – April 4, 2024**

##### **Infoblox Data Connector supports forwarding of BloxOne DHCP lease logs to a NIOS reporting destination.**

Infoblox Data Connector now allows you to forward BloxOne DHCP lease logs to NIOS reporting, streamlining network administration workflows and enhancing efficiency. For more information, see *[Configuring Traffic Flows.](https://docs.infoblox.com/space/BloxOneThreatDefense/35375761)*

## **BloxOne Threat Defense – March 14, 2024**

##### **BloxOne Endpoint supports deferred deployment scheduling options.**

A new deferred deployment schedule option for BloxOne Endpoint for Windows, MacOS, and Linux is available, allowing endpoint upgrades to be postponed by the endpoint group. Deployment can be deferred for up to four weeks, with the option to select deployment *day of week and time,* independent of the release date. BloxOne Endpoint for iOS and Android will request and validate a user’s email during manual installation when an MDM service is not used for the deployment. This simplifies and improves user notification, compromised device tracking, access restrictions (by listing trusted domains), and general consumption. For information, see *[Scheduling Endpoint Group Updates](https://docs.infoblox.com/space/BloxOneThreatDefense/35374562)*.

##### **BloxOne Mobile Endpoint validation of user email ID during manual installation (no MDM feature).**

BloxOne Moblie Endpoint adds validation of the user’s email during manual installation when an MDM service is not used for the deployment. This simplifies and improves user notification, compromised device tracking, access restrictions (by listing trusted domains), and general consumption. For information, see *[Deployment of MDM-less Mobile Endpoint (no MDM feature)](https://docs.infoblox.com/space/BloxOneThreatDefense/429293681)*.

## **BloxOne Threat Defense – March 8, 2024**

##### **Added DNS Point of Presence - U.S. (Ohio).**

Infoblox adds PoP for DNS resolution in the U.S. (Ohio) to speed resolution, improve resiliency, and provide local resolution for organizations in that region.

## **BloxOne Threat Defense – February 23, 2024**

##### **AWS S3 RPZ log export now includes three additional fields: “key,” “sld,” and “extra.”**

RPZ logs exported to AWS S3 and the object storage service will be updated to include additional fields: “key,” “sld,” and an “extra” field to provide additional metadata such as username, client region and country, endpoint group, response, etc. This RPZ log export enhancement uses a different output path on the customers’ S3 bucket ( / rpz_enriched / year=xxxx / month=xx / day=xx /hour=xx ). For information, see *[Log File Format](https://docs.infoblox.com/space/BloxOneThreatDefense/35376649)*.

## **BloxOne Threat Defense – February 16, 2024**

##### **SOC Insights for BloxOne® Threat Defense enhances SOC efficiency by utilizing AI-driven analytics to effectively reduce alert fatigue and security gaps while also decreasing Mean Time to Respond (MTTR).**

By distilling vast numbers of alerts into crucial insights, analysts can prioritize and address critical issues more efficiently and effectively. SOC Insights further empowers analysts with instant access to relevant network, event, and DNS intelligence, allowing for speedy, informed decision-making and accelerated incident response and threat mitigation. SOC Insights is offered as an optional feature for both BloxOne Threat Defense Advanced and BloxOne Threat Defense for BloxOne Business Cloud customers. Additionally, Configuration Insights is automatically integrated into all existing BloxOne Threat Defense Business Cloud and Advanced user accounts, offering guidance on optimal detection settings and adherence to best practices.

Customers interested in exploring this feature can reach out to the sales team to request a trial. For information, see *[SOC Insights.](https://docs.infoblox.com/space/BloxOneThreatDefense/501514252)*.

## **BloxOne Threat Defense – February 1, 2024**

##### **BloxOne Endpoint for Windows support for Join Tokens**

The latest update to the BloxOne Endpoint for Windows, version 2.4.6, introduces a new authentication method using join tokens. This enhancement significantly boosts security by enabling users to control endpoint access to the Cloud Service Portal through the use of rotating tokens. Rotating join tokens help prevent unauthorized access if an install package is leaked, for example. The server side of the authentication process is designed to be backward compatible, ensuring a smooth migration. Additionally, the same join token can be utilized across endpoint deployments for Mac, Linux, iOS, and Android. For information, see *[Configuring Join Tokens for Endpoint](https://docs.infoblox.com/space/BloxOneThreatDefense/401933130)*.

##### **BloxOne Endpoint for Mac support for Join Tokens**

The latest update to the BloxOne Endpoint for Mac, version 2.4.6, introduces a new authentication method using join tokens. This enhancement significantly boosts security by enabling users to control endpoint access to the Cloud Service Portal through the use of rotating tokens. Rotating join tokens help prevent unauthorized access if an install package is leaked, for example. The server side of the authentication process is designed to be backward compatible, ensuring a smooth migration. Additionally, the same join token can be utilized across endpoint deployments for Windows, Linux, iOS, and Android. For information, see *[Configuring Join Tokens for Endpoint](https://docs.infoblox.com/space/BloxOneThreatDefense/401933130)*.

## **BloxOne Threat Defense – January 29, 2024**

##### **The Cloud Services Portal now provides enhanced viewing and export options for service logs from the Data Connector.**

- Logs from the Data Connector are now accessible for both viewing and downloading through the Cloud Services Portal.
- The Data Connector has the capability to export service logs to all supported destinations, including integration with SIEM (Security Information and Event Management) systems.

For information, see *[BloxOne Notifications](https://infoblox-docs.atlassian.net/wiki/pages/createpage.action?spaceKey%3DBloxOneCloud%26title%3DBloxOne%20Notifications)* and *[Configuring Traffic Flows](https://docs.infoblox.com/space/BloxOneCloud/35397475)*.

## **BloxOne Threat Defense – January 17, 2024**

##### **BloxOne introduces the redesign of the Dossier summary and timeline page.**

The updated design now presents timeline events in a clear chronological order, using a vertical format for easier reference. Additionally, the redesign includes detailed event information linked to each timeline occurrence, streamlining the process of tracking and managing events within your organization. This enhancement aims to improve the user experience and facilitate more efficient detection, monitoring, and managing of reported threat indicators.

For information about Dossier, see *[The Dossier Threat Indicator Report](https://docs.infoblox.com/space/BloxOneThreatDefense/230493467)*.

## **BloxOne Threat Defense –  January 16, 2024**

##### **BloxOne supports host deployment using generation 2 virtual machines on Hyper-V/Azure.**

BloxOne now supports generation 2 VMs when you deploy BloxOne hosts in Microsoft Azure. For more information, see *[Microsoft Azure Deployment](https://docs.infoblox.com/space/BloxOneInfrastructure/204800676)*.

##### **BloxOne supports adding host tags associated with the Cloud Services Portal during BloxOne host deployments.**

When you deploy a BloxOne host, you can add a host tag to the “userdata” file to associate the host with the Cloud Services Portal. For more information, see *[YML and JSON Templates](https://docs.infoblox.com/space/BloxOneThreatDefense/35408412)*.

##### **BloxOne supports firmware updates on Dell VEP-1425, Dell VEP-1485, and Infoblox B1-212 hardware appliances.**

To upgrade the firmware on Dell VEP-1425, Dell VEP-1485, and Infoblox B1-212 appliances, you can now download firmware upgrades and apply a firmware upgrade script via the debug CLI or a USB flash drive. For more information, see *[Updating Firmware on Hardware Appliances](https://docs.infoblox.com/space/BloxOneInfrastructure/453017617)*.

##### **BloxOne host deployment on Google Cloud Portal (GCP) now supports IPv6.**

      For information, see *[Google Cloud Portal (GCP) Deployment.](https://docs.infoblox.com/space/BloxOneInfrastructure/350027851)*.

## **BloxOne Threat Defense –  January 5, 2024**

##### **BloxOne Endpoint for Linux support for Join Tokens**

The latest update to the BloxOne Endpoint for Linux, version 1.0.7, introduces a new authentication method using join tokens. This enhancement significantly boosts security by enabling users to control endpoint access to the Cloud Service Portal through the use of rotating tokens. Rotating join tokens help prevent unauthorized access if an install package is leaked, for example. The server side of the authentication process is designed to be backward compatible, ensuring a smooth migration. Additionally, the same join token can be utilized across endpoint deployments for Linux, iOS, and Android. For information, see *[Configuring Join Tokens for Endpoint](https://docs.infoblox.com/space/BloxOneThreatDefense/401933130)*

## **BloxOne Threat Defense – December 4, 2023**

##### **BloxOne Mobile Endpoint for Android will receive a MDM-less deployment option.**

BloxOne Mobile Endpoint for Android will receive a MDM-less deployment option. MDM-less deployment will allow better support for BYOD and other non-managed corporate devices. Users can now install BloxOne Endpoint from the [Google Play store](https://play.google.com/store/apps/details?id=com.infoblox.bloxone.mobile.endpoint&hl=en_US) and enable it by scanning a provided QR code to protect their devices. QR codes are generated based on unique join tokens, which are easy to retire and rotate. Due to significant changes in the authentication process it is recommended to deploy the application in a lab environment first to ensure it is properly understood and implemented,  and then schedule upgrades in stages. For information, see *[Managing Endpoint Groups](https://docs.infoblox.com/space/BloxOneThreatDefense/35470955)* and *[Managing BloxOne Mobile Endpoint](https://docs.infoblox.com/space/BloxOneThreatDefense/35470955)*.

## **BloxOne Threat Defense – December 1, 2023**

##### **BloxOne now displays all host types for hardware platforms on the Cloud Services Portal.**

The **Infrastructure** > **Host** page of the Cloud Services Portal now displays **B1-212** as the host type for Dell VEP appliances that are purchased from Infoblox. In addition, the “**B105**” hardware type is replaced by “**B1-105**.”

##### **BloxOne allows you to add new services directly on the Infrastructure > Host page.**

You can now add services to a specific host on the **Infrastructure** > **Host** page without navigating to the **Services** page.

## **BloxOne Threat Defense – November 20, 2023**

##### **BloxOne Endpoint for Windows version 2.4.3 is updated to provide a better experience with user group-based policies that do not require re-authentication on the agent. This release of BloxOne Endpoint for Windows and for MacOS version 2.4.3 also contains bug fixes.**

For information, see *[Managing Endpoint Groups](https://docs.infoblox.com/space/BloxOneThreatDefense/35470955)*.

## **BloxOne Threat Defense – November 15, 2023**

##### **BloxOne Mobile Endpoint for iOS will receive a MDM-less deployment option.**

MDM-less deployment will allow better support for BYOD and other non-managed corporate devices. Users can now install BloxOne Endpoint from the Apple App store and enable it by scanning a provided QR code to protect their devices. QR codes are generated based on unique join tokens, which are easy to retire and rotate. Due to significant changes in the authentication process it is recommended to deploy the application in a lab environment first to ensure it is properly understood and implemented, and then schedule upgrades in stages. For information, see *[Managing Endpoint Groups](https://docs.infoblox.com/space/BloxOneThreatDefense/35470955)* and *[Managing BloxOne Mobile Endpoint](https://docs.infoblox.com/space/BloxOneThreatDefense/35470955)*.

## **BloxOne Threat Defense – November 4, 2023**

##### **BloxOne Endpoint version 1.0.6  supports Ubuntu 20.x and RedHat 8.x distributions, in addition to Ubuntu 22.x.**

For information, see *[Linux Client Application Deployment](https://docs.infoblox.com/space/BloxOneThreatDefense/297666539)*.  

## **BloxOne Threat Defense – November 2, 2023**

##### **BloxOne introduces usability enhancements to global search and local search on the Cloud Services Portal.**

The global search and local search enhancements include the following:

- Global search input functionality updates
- Local search bar and filter updates
- New page header design and icon size and placement updates

For information, see  *[Using Global Search](https://docs.infoblox.com/space/BloxOneThreatDefense/35439577)* and *[Using Local Search](https://docs.infoblox.com/space/BloxOneThreatDefense/376307828)*.

## **BloxOne Threat Defense – October 20, 2023**

##### **BloxOne introduces a new table view to the Hosts, Services, Monitoring, Locations, and Templates tabs on the Manage > Infrastructure page of the Cloud Services Portal.**

In addition to the card and map views, you now have the flexibility to view and manage the data of hosts, services, monitoring, locations, and templates in a table format on the BloxOne **Infrastructure** page.

##### **BloxOne introduces a new table view to the Audit Logs, Service Logs, and Security Logs tabs on the Administration > Logs page of the Cloud Services Portal.**

In addition to the card view, you now have the flexibility to view and manage the data of audit logs, service logs, and security logs in a table format on the BloxOne **Logs** page.

## **BloxOne Threat Defense – October 6, 2023**

##### **BloxOne Threat Defense enhances full audit logging by adding details of Create, Update, and Delete (CUD) operations.**

Enhanced audit logging track changes in security policies, custom lists, application/category filters, BloxOne Endpoint/BloxOne Endpoint group settings, and more. For more information, see *[Viewing Audit logs](https://docs.infoblox.com/space/BloxOneCloud/35430270)*.

##### **BloxOne lookalike domain management includes suggested domains for monitoring.**

A maximum of 25 suggested lookalike domains can be added to a custom lookalike watch list for monitoring.  For more information, see *[Viewing Custom Watched Domains](https://docs.infoblox.com/space/BloxOneThreatDefense/139756688)*and *[Adding Suggested Lookalike Domains](https://docs.infoblox.com/space/BloxOneThreatDefense/360284570)*.

## **BloxOne Threat Defense – October 5, 2023**

##### **Infoblox BloxOne bare-metal deployment now supports Red Hat versions 7.9, 8.7, 8.8, 9.1, and 9.2.**

For more information, see *[Bare-Metal Deployment.](https://docs.infoblox.com/space/BloxOneInfrastructure/204538556)*.

## **BloxOne Threat Defense – September 27, 2023**

##### **Infoblox supports the deployment of BloxOne hosts in Google Cloud Platform.**

You can now deploy BloxOne hosts on Google Cloud Platform using Infoblox-provided GCP package you download from the Cloud Services Portal.  For more information, see *[Google Cloud Portal (GCP) Deployment](https://docs.infoblox.com/space/BloxOneInfrastructure/350027851)*.

##### **Infoblox supports the deployment of BloxOne hosts on Containerd Environments.**

You can now deploy BloxOne hosts on Containerd environments  using Infoblox-provided BloxOne Install packages you download from the Cloud Services Portal. For more information, see *[Bare-Metal Deployment.](https://docs.infoblox.com/space/BloxOneInfrastructure/204538556)*.

##### **Infoblox TIDE introduces new sizing guidelines for Custom RPZ feeds.**

Infoblox TIDE introduces new sizing guidelines for Custom RPZ feeds. Newly created custom RPZs are limited to a maximum of 6 million records. This limit includes all available feeds, such as Infoblox-curated data, Infoblox’s third-party data, and any uploaded data you provide. A new sizing indicator displays the number of records contained within a custom RPZ feed. Custom RPZ feeds created prior to the introduction of the new sizing guidelines will not be impacted by the new sizing guidelines, although no new records can be added. For information, see Sizing Guidelines for Custom RPZ Feeds.

For information, see *[Sizing Guidelines for Custom RPZ Feeds](https://docs.infoblox.com/space/BloxOneThreatDefense/351830160)*.

## **BloxOne Threat Defense – September 26, 2023**

##### **BloxOne enhances the Log Export feature to include additional metadata in the BloxOne Threat Defense DNS response logs.**

DNS response logs are exported in parquet format. Exported parquet-files include the following additional columns: ‘key’, ‘sld’ and column ‘extra’ get additional fields: ‘sld’, ‘pname’, ‘pdisplay_name’, ‘domain_applications’, ‘qname_norm’, ‘client_country’, ‘client_continent’, ‘event_date’, ‘response_continent’, ‘response_region’, ‘response_country’, ‘application’, ‘egress_ip’, ‘device_name’, ‘device_ip’, ‘domain_categories’, ‘network’, ‘record_type’, ‘query_type’, ‘response’, ‘user_name’, ‘endpointgroups’. If you have any questions about the enhancement, please contact your account team or open a support ticket.

For information, see *[Exporting Logs](https://docs.infoblox.com/space/BloxOneCloud/35365902)*.

## **BloxOne Threat Defense – September 1, 2023**

##### **You can now set up BloxOne sandboxes as test environments.**

If your business requires a separate BloxOne test environment, you can purchase a BloxOne sandbox and set it up for testing purposes. For more information, see *[Managing Sandboxes](https://docs.infoblox.com/space/BloxOneInfrastructure/327778306)*.