ASIM Parser Development Automation: GitHub Copilot Skills for Accelerated Detection Engineering

GitHub Copilot agent skills now automate the complete ASIM parser creation workflow, reducing parser development time from days to hours for security engineers. Read More →

ASIM AssetEntity Schema: Three New Fields Added in v1.0.0 Release

ASIM AssetEntity schema upgraded to v1.0.0 with three new fields for enhanced entity correlation and snapshot tracking. Read More →

ASIM Agent Event Schema: New Normalization Framework for Security Agent Monitoring

Microsoft Sentinel gains ASIM Agent Event schema for normalizing security agent events across all vendor platforms. Read More →

ASIM Authentication Schema: VMware vCenter Parser Enables Authentication Monitoring for On-Premises and Azure VMware Environments

New ASIM parser normalizes VMware vCenter authentication events from syslog streams to enable detection coverage across vSphere environments. Read More →

ASIM Schema: Enhanced EntitySource Coverage for Data Platform Assets

ASimTester validation schema adds Snowflake, Databricks, and Salesforce to AssetEntity EntitySource enumeration for broader data platform asset tracking. Read More →

Cisco IOS: New ASIM Authentication Parser for Network Device Login Monitoring

ASIM authentication parser for Cisco IOS enables normalized monitoring of login, logout, and failed authentication events from network infrastructure devices. Read More →

ASIM WebSession Parser: New Cisco Umbrella Proxy Log Coverage

New ASIM parser adds web session visibility for Cisco Umbrella proxy logs, normalizing HTTP/HTTPS traffic data to standard schema. Read More →

ASIM Data Tester Enhanced: New Type Validation for Asset Schema Fields

ASIM Data Tester adds DynamicType and ArrayValuesType validation columns to improve dynamic field type checking accuracy. Read More →

ASIM AuditEvent Parser: Azure SQL Security Audit Data Normalized for Detection

New ASIM parser enables normalized analysis of SQL security audit events from SQLSecurityAuditEvents and AzureDiagnostics tables. Read More →

ASIM Schema Standardization: Removing Unused User Role Fields Across Multiple Schemas

Cleanup of unused Actor/Target user role fields and alignment of empty parsers improves schema consistency but does not affect active detection capabilities. Read More →

ASIM Schema Cleanup: Removing Unused User Fields from Test Configuration

Maintenance cleanup removes unused optional user fields from ASIM test configuration with no impact on parser or detection functionality. Read More →

ASIM Asset Entity Schema: New Schema Foundation for Asset Management

Introduces complete ASIM Asset Entity schema with parsers, empty templates, and CI integration to enable asset-centric security monitoring. Read More →

ASIM FileEvent Parser: New AWS CloudTrail S3 Support Added

New FileEvent parser enables normalized S3 object activity monitoring from AWS CloudTrail logs across bucket operations and object lifecycle events. Read More →

ASIM Authentication Schema: NetworkCleartext SubType Added

ASIM Authentication schema expanded to include NetworkCleartext authentication subtype for cleartext password events. Read More →

ASIM Authentication Parser: Enhanced SSH Authentication Method Detection

SSH authentication parser now accurately identifies logon methods (password, PKI, PAM) and adds improved field mappings for better authentication visibility. Read More →

Azure Firewall ASIM Parsers: Enhanced Detection Coverage for Six New Log Types

New ASIM normalisation parsers added for six Azure Firewall log tables, expanding detection coverage for network sessions, DNS queries, and web traffic analysis. Read More →