Auto-generated summaries of every merged PR in the Azure-Sentinel GitHub repo

New Citrix DaaS Connector: VDI Configuration Audit and Session Visibility Now Available in Microsoft Sentinel

A new CCF-based Data Connector ingests Citrix DaaS (Virtual Apps and Desktops) configuration audit logs and session activity into two custom tables, opening detection surface for VDI administrative abuse and anomalous session behaviour. Read More →

CrowdStrike Falcon Data Replicator Connectors: UI Title Disambiguation

The two CrowdStrike Falcon Data Replicator connectors have been renamed in the UI to clarify ownership of the underlying AWS S3 bucket – no ingestion logic, polling config, or detection content was changed. Read More →

CrowdStrike API Connector: Polling Timestamp Switch Closes Alert Ingestion Gap

The CrowdStrike API Data Connector was filtering alerts and EPP events by creation time rather than update time, causing any alert updated outside its original creation window to be silently dropped from ingestion. Read More →

Trend Micro Cloud App Security CCF Connector: Table Name Fix Restores Graph and Connectivity Status Accuracy

The CCF connector was referencing the bare table name TrendMicroCASV2 instead of the correct custom log table TrendMicroCASV2_CL, causing connector UI graph queries, connectivity checks, and data-type status indicators to silently fail for all deployments running v3.0.0-v3.1.1. Read More →

Palo Alto Cortex XDR: Three Severity-Tiered Analytic Rules and Unified Incidents Parser Added to CCF Solution

Detection coverage for Cortex XDR incidents, absent from the CCF-based solution since its launch, is restored with three new Analytic Rules (High/Medium/Low) and a parser that bridges both the CCF and legacy CortexXDR_Incidents_CL tables. Read More →

Salesforce Audit Logs Connector Promoted to GA — Verify ARM Template Syntax Before Deploying

The Salesforce Audit Logs CCF connector exits preview, but the PR introduces ARM concat expressions with syntactically invalid parameter references that may break deployment in affected workspaces. Read More →

Salesforce RTEM Connector: SOQL Queries Switched to FIELDS(STANDARD) to Respect Field-Level Security

The SalesforceRTEM CCF connector was querying Salesforce RTEM event stores with hardcoded field lists that ignored field-level security, meaning deployments with restricted Salesforce permissions received partial or failed responses; this update switches all 19 event type queries to FIELDS(STANDARD) and corrects a Username column case mismatch that caused null values in the DCR transform. Read More →

SAP BTP: New Detection for Custom Apps Silently Bypassing Audit Logging

A new Analytic Rule detects SAP BTP custom applications that only emit XSUAA login events but produce zero business audit logs, exposing a structural blind spot attackers can exploit for undetected operations. Read More →

NetApp Ransomware Resilience 3.1.0: Three New Containment and Recovery Playbooks for Storage Incidents

Three new Playbooks extend the NetApp Ransomware Resilience solution with user access containment (block/unblock) and volume restoration capabilities, enabling end-to-end automated incident response against ransomware targeting NetApp storage. Read More →

SAP LogServ: Four HANA Detections Were Querying the Wrong Table -- Now Fixed Plus ASIM DCR Routing Added

Four SAP HANA Analytic Rules were silently querying SAPLogServ_CL for HANA audit events now routed to Syslog via DCR meaning these detections returned zero results on post-DCR deployments until this fix. Read More →

QRadar Migration Tool: Hardened Error Handling Preserves CSV Delivery When Enrichment Fails

The QRadar migration collector (v0.4.2) downgrades several previously pipeline-aborting phases to non-critical, ensuring the minimum UCM CSV export survives enrichment failures that would previously have silently discarded all migration output. Read More →

VMware Workspace ONE CCF Connector Promoted to General Availability

The VMware Workspace ONE CCF data connector exits Public Preview and is now GA, making mobile endpoint compliance and unauthorized application visibility officially supported for production deployments. Read More →

Salesforce Service Cloud Connector: Missing SecureConnectionStart Field Added to DCR Schema and Transform

The Salesforce Service Cloud CCF data connector was missing the SECURE_CONNECTION_START field from the DCR stream schema and transformKql projection, meaning any Salesforce event log file records that included this TLS connection-state field had it silently dropped before ingestion into SalesforceServiceCloudV3_CL. Read More →

Check Point Email Security CCF Connector Graduates to GA

The Check Point Harmony Email & Collaboration CCF connector exits preview, making phishing, malware, DLP, and audit log ingestion into four custom tables officially supported for production deployments. Read More →

Microsoft Entra ID Assets Connector: EntraEligibleMembers Table Re-Enabled After Regional Deployment Gap

The EntraEligibleMembers (Preview) table is re-added to the Microsoft Entra ID Assets connector UI after being temporarily removed when backend ingestion was not yet available in all regions. Read More →

New PRODAFT USTA Solution: Infostealer-Sourced Compromised Credential Ingestion with Out-of-Box Detection

A new Microsoft Sentinel solution ingests PRODAFT USTA Account Takeover Prevention (ATP) compromised-credential tickets via CCF with ingestion-time password redaction, and ships two Analytic Rules, a hunting query, parser, workbook, and historical backfill playbook covering T1078 and T1555. Read More →

New Hunting Query: Teams Helpdesk-Theme Impersonation Detection via Known Suspicious Domains

A new hunting query surfaces Microsoft Teams external-sender impersonation attempts where the attacker UPN matches a curated list of known helpdesk-spoofing domains. Read More →

Tailscale Solution: Workbook Preview Images Registered for Standard and Premium Dashboards

Workbook preview thumbnails added for both Tailscale Standard and Premium workbooks, resolving missing preview image references in Content Hub. Read More →

Trend Micro Cloud App Security CCF Connector Exits Preview — Now Generally Available

The Trend Micro Cloud App Security CCF connector has been promoted to GA, making it the supported path for ingesting CAS security events into the TrendMicroCASV2_CL table via DCR/Log Ingestion API. Read More →

Threat Intelligence URL IoC Matching: Case-Sensitivity Bug Causing Silent Misses in AuditLogs Rule Fixed

The URLEntity_AuditLogs Analytic Rule was silently missing URL IoC matches because indicator values were uppercased before comparison against lowercased log URLs; this fix aligns both sides to lowercase. Read More →