ThreatSync Release Notes

ThreatSync is a WatchGuard Cloud service that provides eXtended Detection and Response (XDR) technology for WatchGuard Network and Endpoint Security products. ThreatSync provides extended detection capabilities through the correlation of data from different WatchGuard security products that indicates the presence of threats.

For a full description of ThreatSync features and functionality, go to ThreatSync Help.

Release Information Date
Latest ThreatSync Update 1 May 2025
Release Notes Revision Date 1 May 2025

Latest Release

Release Date: 1 May 2025

New Features

Access Point ThreatSync Response Actions

You can now perform response actions on Wi-Fi threats detected by ThreatSync to block wireless client connections to malicious access points or trust known access points in your deployment. This feature requires access point firmware v2.7. For more information, go to About ThreatSync. [WIFI-7982]

New ThreatSync Incident Details UI (Beta)

This Beta enables you view and manage incidents in a new Incident Details UI in ThreatSync. The updated Incident Details page contains restructured information, support for multiple source events, and includes these sections:

  • Recommended Actions — Actions WatchGuard recommends you perform to respond to the incident.
  • Entities of Interest — Unique objects (IP addresses, URLs, files, endpoints, and other devices) related to the incident.
  • Signals — Raw events that ThreatSync combines to generate the incident. Click a signal in the list to view more information in the signal details pane.

To learn more or to report an issue, go to the ThreatSync Beta test community.

Resolved Issues

  • When you block an IP address in ThreatSync, and the address appears in the Items Blocked by ThreatSync list, Fireboxes now successfully block the IP address. [FBX-29518, XDR-5014]
  • Minor updates and bug fixes.

Previous Releases