Microsoft Entra ID: Account Creation/Deletion Detection Enhanced Against Timing Evasion

Critical improvements to AccountCreatedandDeletedinShortTimeframe rule extend detection window to 7 days and use immutable UserID correlation to prevent timing-based evasion techniques. Read More →

Vectra XDR Connector: Critical Exception Handling Bug Fixed

Exception handling bug in Vectra XDR data collector prevented proper error propagation during ingestion failures. Read More →

ASIM Authentication: New Parser for Cisco ISE Administrator Login Events

Added ASIM Authentication parser for Cisco ISE administrator authentication events, expanding centralized network device visibility. Read More →

Imperva Cloud WAF: Critical Fix for JSON Log Ingestion Failure

Imperva CCF connector now properly ingests WAF logs containing embedded JSON, preventing data loss during log processing. Read More →

Fortinet FortiGate ASIM Authentication Parsers: Schema Version Metadata Correction

Updates schema version metadata from 0.1.3 to 0.1.4 in FortiGate authentication parsers with no functional changes. Read More →

Microsoft Sentinel Training Lab: Comprehensive Hands-On Security Operations Environment Now Available

New deployment-ready training lab delivers 14 guided exercises with pre-recorded telemetry, detection rules, and automation workflows for practical Microsoft Sentinel skill development. Read More →

Threat Intelligence Domain-to-SecurityAlert Rule: Fixes Recursive Alert Loop with Self-Exclusion Filter

Threat Intelligence domain mapping rule updated to prevent infinite alert loops by excluding its own alerts from the source data. Read More →

Azure Security Benchmark: Updated Labels to Microsoft Cloud Security Benchmark

Replaced “Azure Security Benchmark” references with “Microsoft cloud security benchmark” across workbook labels and KQL queries. Read More →

Blacklens Logic App: Fixed Invalid secureData Configuration Breaking Deployment

Resolved deployment failure caused by invalid secureData configuration in Logic App Compose action. Read More →

Tenable VM: Vulnerability Data Checkpoint Field Update

Changed vulnerability export checkpoint field from last_found to indexed_at for customer enhancement. Read More →

ExtraHop RevealX: Azure Monitor Logs Ingestion API Replaces Legacy HTTP Data Collector

Added Log Ingestion API support with OAuth 2.0 authentication — modernizes data ingestion from legacy HTTP Data Collector API. Read More →

Abnormal Security: New CCF Push Connector Adds Multi-Table Email Security Event Routing

Added CCF Push connector with OAuth 2.0 authentication and dedicated tables for 9 event types — modern replacement for Azure Functions ingestion. Read More →

Cisco Umbrella ASIM Parser: Fixing Variable Scope Bug in IP Filter Logic

Moves critical IP filtering variables inside parser function to prevent incorrect filtering and potential data loss. Read More →

Palo Alto GlobalProtect: New ASIM Authentication Parser for VPN Monitoring

New ASIM parser normalizes GlobalProtect VPN authentication events from CommonSecurityLog table, enabling unified monitoring of gateway and portal authentication across Palo Alto PAN-OS deployments. Read More →

Trend Micro Vision One Connector: South Africa Region Support Added

Added South Africa (za) regional API endpoint support, expanding global deployment coverage for Trend Micro Vision One data ingestion. Read More →

Island Enterprise Browser V2 Connector: Documentation Clarity Improvements

Updated Island connector titles and descriptions to reduce confusion between legacy V1 and current V2 connectors. Read More →

Visa Threat Intelligence Solution: Package Artifacts Regenerated After Template Validation Failure

Template validation failure fixed through package regeneration for Visa Threat Intelligence solution v3.0.2. Read More →

Data Connector 64 KB Field Truncation: Silent Data Loss Risk Documented

Microsoft Sentinel now documents a critical platform limitation where individual fields exceeding 64 KB are silently truncated during ingestion, creating blind spots in large payload analysis. Read More →

ASIM Parser Validation: Critical Schemas Added to CI Pipeline

Four ASIM schemas missing from KQL validation pipeline now included, preventing unvalidated parser deployments. Read More →

Atlassian Confluence Audit: Critical DCR Fix Restores Data Ingestion After Stream Declaration Error

CCF connector repair resolves stream naming mismatch that prevented audit data ingestion in affected deployments. Read More →