SOC Prime CCF: Three New Detection Rules for Platform Security Events
SOC Prime solution adds Analytic Rules detecting platform administration events including tenant deletion and successful logins from malicious IPs. Read More →
SOC Prime solution adds Analytic Rules detecting platform administration events including tenant deletion and successful logins from malicious IPs. Read More →
New Citrix Analytics CCF solution provides push-based ingestion for SPA and CVAD security events via Azure Monitor Logs Ingestion API. Read More →
SAP Reader role permissions significantly reduced for agentless connector, implementing least-privilege access while maintaining monitoring capabilities. Read More →
Removed redundant configuration field from TheHive CCF connector to resolve ARM-TTK validation warnings and ensure clean deployment. Read More →
Azure Resource Graph connector updated table labels to align with Table Management naming conventions, ensuring consistent query references. Read More →
Two SAP solutions transitioned from preview to production-ready status, unlocking stable SAP audit and infrastructure log ingestion. Read More →
New ASIM parser normalizes VMware vCenter authentication events from syslog streams to enable detection coverage across vSphere environments. Read More →
Critical deployment fix for Cyren-SentinelOne connector that was failing ARM template validation in Content Hub, preventing threat intelligence data ingestion. Read More →
D3 Security migrates from Managed Application to Solution Template plan type, requiring new offer ID and deployment procedures. Read More →
ASimTester validation schema adds Snowflake, Databricks, and Salesforce to AssetEntity EntitySource enumeration for broader data platform asset tracking. Read More →
ASIM authentication parser for Cisco IOS enables normalized monitoring of login, logout, and failed authentication events from network infrastructure devices. Read More →
ASIM AssetEntity schema now enforces cloud platform enumeration and adds source traceability field. Read More →
UI graph charts for WAF and API Gateway data streams were broken in the connector interface since v3.0.0 launch. Read More →
New ASIM NetworkSession parser adds Check Point Smart Defense logs to normalized threat monitoring and detection coverage. Read More →
Fixed critical typo in Claroty threat detection rule where “Treat” was incorrectly used instead of “Threat” in both rule name and KQL logic. Read More →
New Netskope solution adds 10 detections for web transaction monitoring including impossible travel, excessive downloads, shadow IT detection, and data exfiltration patterns. Read More →
Proofpoint connectors now send user-agent headers with solution package version information for improved API request identification. Read More →
SAP deployment scripts now verify Docker image digest integrity to prevent container supply chain attacks during installation. Read More →
Trellix solution transitioned from preview to GA status, now production-ready for deployment. Read More →
Fixed missing connector information in deployment template and updated solution tier to Partner status. Read More →