Serie v6.0.x
v6.0.0 (2026-09-01)
Sensor
New Anomaly Detection Engine: Anomaly detection now runs on a new machine learning engine in place of the previous z-score based approach, still trained per device on its own traffic history. This should surface behavioral deviations more accurately than before.
New Anomaly Rules: Added detection for combined behavior anomalies, off-hours device activity, and sudden protocol mix shifts on a device.
Breaking: Rule IP Allow/Deny Parameters: Removed the
allowedSourceIPsandallowedDestinationIPsrule parameters. Use a scope expression to allow or restrict IPs instead.
On-Prem Console
Model Status on the Resource Page: You can now see a device’s anomaly-detection model status directly on its resource detail page, and refresh a model on demand instead of waiting for the next scheduled run.
Unified Severity Across Rules and Controls: Rules and compliance controls now share one severity scale, shown consistently across alerts, findings, and the UI, making it easier to compare risk across both.
Remediation Guidance: Findings and threat-detection alerts now include suggested remediation steps, so you know what to do next without leaving the alert.
New Controls: Added a control that flags PLCs stuck in STOP state, and a control that tracks Siemens devices approaching end of life through their successor model. Cancelled-device detection for Siemens hardware now also recognizes two additional device states.
Clearer Findings and Vulnerability Trends: Reworked the findings and vulnerabilities evolution charts to show trends grouped by snapshot and stacked by severity, making it easier to see what’s driving a change over time.
Network Conversations View: Added a view for browsing network conversations between devices, with pagination and the ability to select a custom date range when looking at traffic history. Device pages now also show when a device was last seen in traffic.
Redesigned Sign-In Page: Refreshed the sign-in experience with an updated look.
Alert Groups Table Fix: Fixed an issue where an alert group’s occurrence count, age, or last-seen time could fail to display.
More Reliable IP Reputation Enrichment: Fixed an issue where a failed IP reputation lookup could silently leave an alert without threat context instead of surfacing the error.
Agentic OTSPM
New Assistant Skills: Added assistant-guided workflows for detecting inventory drift, planning network zone segmentation under IEC 62443, reducing alert noise, reviewing a device timeline, checking policy consistency, and running a compliance gap analysis.
Rule Scope via Assistant: You can now view and update a rule’s scope through the assistant, and query network flows, countries, and inventory changes directly from it.