CrowdStrike Falcon Data Replicator: Incorrect Deprecation Reversed, Connector Restored to Active Status

CrowdStrike’s Function App-based data replicator was incorrectly deprecated and has been restored to active status to maintain government deployment support. Read More →

Upwind Connector: Function App Deployment Fixed After Broken Code Deployment

Upwind connector Function App deployment was failing due to incorrect zip structure and ARM template configuration - fixed with flat zip layout and implicit hosting plan. Read More →

GreyNoise Threat Intelligence: Packaging Fixes and Security Improvements

Fixed Function App deployment packaging errors and improved security by converting ARM template secrets to secure strings. Read More →

Cloudflare Connector: Critical DCR Fix Restores Data Ingestion After Field Mapping Failures

Fixed DCR transformKql failures for Type field and invalid data types that were preventing Cloudflare log ingestion. Read More →

Entra ID Brute Force Detection: Renamed for Broader Windows Device Coverage

Analytic rule renamed from Cloud PC-specific to cover all Entra-authenticated Windows devices, clarifying detection scope without logic changes. Read More →

Logstash Output Plugin: Documentation Update for Version 2.1.1

Version bump to 2.1.1 with efficiency improvements noted but no connector logic changes. Read More →

New Vaikora-CrowdStrike Integration: AI Agent Behavioral Signals to Custom IOCs

Logic App Playbook introduced to poll Vaikora AI agent signals and push high-risk actions as Custom IOCs to CrowdStrike Falcon for automated threat prevention. Read More →

ZoomReports: Cloud Recording API Polling Optimized to Reduce Data Duplication

Updates polling interval from 2-day to 1-day window with 1-day delay to eliminate duplicate Zoom cloud recording logs. Read More →

Visa Threat Intelligence: ARM Template Certification Fix

Replaces deprecated concat with uri function in ARM template to meet Azure certification requirements. Read More →

Qualys KB Connector Now GA: Production-Ready Vulnerability Intelligence

Qualys Knowledge Base connector moves from Preview to General Availability, providing production-grade vulnerability intelligence ingestion with enhanced monitoring capabilities. Read More →

Vaikora AI Security: New Logic App Playbook for SentinelOne Threat Intelligence Integration

Data443 introduces Vaikora AI agent behavioral signal integration with SentinelOne threat intelligence via a 6-hour polling playbook. Read More →

New Spur Context API Solution: High-Fidelity IP Intelligence for VPN and Proxy Detection

New solution provides real-time IP enrichment to detect VPN, residential proxy, and bot automation traffic in incidents and alerts. Read More →

Qualys VM Connector: API Version 5.0 Migration Before Deprecation

Qualys VM connector upgraded from API v3.0 to v5.0 to prevent June deprecation cutoff impacting vulnerability data ingestion. Read More →

Zoom Connector GA Release: Enhanced Data Ingestion with New Table Schema

ZoomReports CCF connector transitions to GA with parser supporting dual-table ingestion and expanded field coverage. Read More →

Training Lab: Fixed Detection Rule Deployment Script Resilience

Lab deployment script now retries on any table syntax errors, not just OktaV2_CL — prevents silent deployment failures. Read More →

Okta Detection Rule: Fixed Blind Spot After Connector Migration to OktaV2_CL

Critical Okta detection was broken after connector migration — now uses OktaSSO parser to restore session impersonation monitoring. Read More →

Seraphic Web Security: Upgraded to v3.0.0 Content Schema with Enhanced Polling

Seraphic Web Security solution upgraded to v3.0.0 schema with polling v3.0, health checks, and corrected connectivity criteria. Read More →

Salesforce Service Cloud Connector: Enhanced Event Coverage and OAuth2 Support

Salesforce connector v3.1.0 adds comprehensive Event Log File coverage and OAuth2 username-password authentication for improved deployment flexibility. Read More →

GitHub Webhook V2 Connector: CLv2 Migration Ensures Continued GitHub Advanced Security Ingestion

New CLv2-based GitHub Webhook connector replaces deprecated CLv1 API to maintain ingestion of code scanning, Dependabot, and secret scanning alerts. Read More →

Bitdefender GravityZone: New Push-Based Security Data Connector for Sentinel

New GravityZone solution brings enterprise endpoint threat data directly to Sentinel via DCR-based push ingestion without bundled detections. Read More →