SOC Prime CCF: Three New Detection Rules for Platform Security Events

SOC Prime solution adds Analytic Rules detecting platform administration events including tenant deletion and successful logins from malicious IPs. Read More →

Citrix Analytics: New CCF Push Connector Enables Security Analytics Visibility

New Citrix Analytics CCF solution provides push-based ingestion for SPA and CVAD security events via Azure Monitor Logs Ingestion API. Read More →

SAP Agentless Connector: Reduced Permission Model for Enhanced Security

SAP Reader role permissions significantly reduced for agentless connector, implementing least-privilege access while maintaining monitoring capabilities. Read More →

TheHive Connector: ARM Template Validation Fix

Removed redundant configuration field from TheHive CCF connector to resolve ARM-TTK validation warnings and ensure clean deployment. Read More →

Azure Resource Graph: Table Name Standardization for Query Consistency

Azure Resource Graph connector updated table labels to align with Table Management naming conventions, ensuring consistent query references. Read More →

SAP Solutions: Production-Ready Status After Preview Removal

Two SAP solutions transitioned from preview to production-ready status, unlocking stable SAP audit and infrastructure log ingestion. Read More →

ASIM Authentication Schema: VMware vCenter Parser Enables Authentication Monitoring for On-Premises and Azure VMware Environments

New ASIM parser normalizes VMware vCenter authentication events from syslog streams to enable detection coverage across vSphere environments. Read More →

Cyren-SentinelOne Connector: Restoring Threat Intelligence Deployment After ARM Template Failure

Critical deployment fix for Cyren-SentinelOne connector that was failing ARM template validation in Content Hub, preventing threat intelligence data ingestion. Read More →

D3 Smart SOAR: New Content Hub Solution Template Deployment Model

D3 Security migrates from Managed Application to Solution Template plan type, requiring new offer ID and deployment procedures. Read More →

ASIM Schema: Enhanced EntitySource Coverage for Data Platform Assets

ASimTester validation schema adds Snowflake, Databricks, and Salesforce to AssetEntity EntitySource enumeration for broader data platform asset tracking. Read More →

Cisco IOS: New ASIM Authentication Parser for Network Device Login Monitoring

ASIM authentication parser for Cisco IOS enables normalized monitoring of login, logout, and failed authentication events from network infrastructure devices. Read More →

ASIM AssetEntity Schema: EntitySource Enumeration and EntityOriginalSource Added

ASIM AssetEntity schema now enforces cloud platform enumeration and adds source traceability field. Read More →

Alibaba Cloud Networking: Missing Data Stream Visualization Restored

UI graph charts for WAF and API Gateway data streams were broken in the connector interface since v3.0.0 launch. Read More →

Check Point Smart Defense: ASIM NetworkSession Parser Expands Threat Prevention Visibility

New ASIM NetworkSession parser adds Check Point Smart Defense logs to normalized threat monitoring and detection coverage. Read More →

Claroty Analytic Rule: Critical Typo Fix Restores Threat Detection Logic

Fixed critical typo in Claroty threat detection rule where “Treat” was incorrectly used instead of “Threat” in both rule name and KQL logic. Read More →

Netskope Secure Web Gateway Solution: New Detection Coverage for Cloud Application Visibility

New Netskope solution adds 10 detections for web transaction monitoring including impossible travel, excessive downloads, shadow IT detection, and data exfiltration patterns. Read More →

Proofpoint TAP and POD Connectors: User-Agent Header Added for Solution Version Tracking

Proofpoint connectors now send user-agent headers with solution package version information for improved API request identification. Read More →

SAP Data Connector: Docker Image Integrity Verification Added to Deployment Scripts

SAP deployment scripts now verify Docker image digest integrity to prevent container supply chain attacks during installation. Read More →

Trellix Solution Enters GA: Production Ready for Cyberthreat Detection

Trellix solution transitioned from preview to GA status, now production-ready for deployment. Read More →

Visa Threat Intelligence Solution: Packaging Metadata Corrected

Fixed missing connector information in deployment template and updated solution tier to Partner status. Read More →