TheHive Incident Response: New CCF Connector for SOAR Platform Integration

Microsoft Sentinel gains native ingestion from TheHive security incident response platform via CCF connector, enabling case management visibility and response workflow correlation. Read More →

Cyera DSPM Connector: Critical DCR Transform Fix Restores Asset Visibility After KQL Function Errors

Cyera DSPM connector v3.0.4 fixes DCR transformation failures that prevented data ingestion, restoring visibility into cloud asset security posture and compliance. Read More →

CTM360 HackerView: Connector Ingestion Restored After Complete Deployment Failure

CTM360 HackerView Function App connector was completely broken due to backup flag logic errors, preventing all threat intelligence ingestion until this fix. Read More →

WithSecure Elements Connector: Python Runtime Upgrade to 3.12

WithSecure Elements Function App connector upgraded from Python 3.10 to 3.12 to align with updated function code. Read More →

Microsoft Sentinel SOAR Playbook: Enhanced User Entity Resolution Prevents Silent Failures

Incident-Trigger-Entity-Analyzer playbook upgraded with intelligent user identifier detection, resolving silent failures when entities lack AadUserId. Read More →

Rapid7 InsightVM: New CCF Connector Expands Vulnerability Management Data Ingestion Options

Rapid7InsightVM solution adds CCF-based data connector for cloud-native ingestion alongside legacy Function App connector, enhancing deployment flexibility for vulnerability management visibility. Read More →

Versasec CMS: Microsoft API Version Update for SavedSearches

Microsoft updated the SavedSearches API version in the Versasec CMS solution packaging. Read More →

Solution Analyzer v9.0: Enhanced Table Schema Discovery and Documentation Source Prioritization

Major enhancement adds comprehensive table schema extraction from DCR configs and Azure Monitor docs, plus improved discovery source hierarchy for better data source visibility. Read More →

Open Systems Connector: Enhanced Kafka Consumer Thread Configuration for Scalability

ARM template gains configurable consumer threads for each log type to address Logstash performance bottlenecks in high-volume deployments. Read More →

CyberArk Audit: New CCF Connector Alternative Replaces Function App Dependency

CyberArk adds CCF-based connector to eliminate Azure Functions dependency for audit data ingestion. Read More →

New Trellix Endpoint Security: CCF Connector Unlocks ePO Threat Visibility in Sentinel

New solution delivers Trellix ePO endpoint security events via CCF with OAuth2 authentication and comprehensive threat intelligence data. Read More →

TacitRed-SentinelOne v3.0.2: Critical Fix for Broken SentinelOne Connection

Fixes a critical deployment bug present since v1.0.0 where hardcoded placeholder URL caused complete playbook failure for all Content Hub installations. Read More →

Gigamon AMX Connector: Migration to CCF Push Restores Network Visibility After Deprecation

Gigamon connector migrated from deprecated Log Analytics method to CCF push architecture, preventing complete loss of network traffic and threat visibility. Read More →

Cisco Duo Connector: Function Timeout Mitigation and Dependency Security Updates

Fixes timeout-induced ingestion failures in offline enrollment log processing and updates duo-client library for security maintenance. Read More →

Google Kubernetes Engine Connector: Documentation Update Links to Official Microsoft Learn

Google Kubernetes Engine connector documentation updated to reference official Microsoft Learn guides instead of personal repositories. Read More →

ASIM Registry Event: Added Mandatory Fields for Microsoft 365 Defender Parser Compliance

Updated ASIM Registry Event parser for Microsoft 365 Defender to include mandatory EventSchema and EventResult fields per schema compliance requirements. Read More →

Cyren Threat Intelligence: Partner Center Compliance Fix and Version Alignment

Compliance update removes credential scanner violations from securestring parameters and aligns all content versions to 3.0.3. Read More →

IONIX: Migration to CCF RestApiPoller with Enhanced Data Deduplication

Major migration from HTTP Data Collector API to CCF RestApiPoller enabling automatic polling with query-time deduplication for IONIX attack surface management data. Read More →

Logstash Connector: Extended Version Support for Newer Logstash Releases

Documentation update adds support for Logstash versions 8.19.2, 9.0.8, 9.1.10, and 9.2.4-9.2.5. Read More →

Global Secure Access: Critical Fix for Abnormal Deny Rate Detection Baseline Computation

Critical fix aligns queryPeriod with 5-day learning window, restoring proper baseline computation for abnormal deny rate detection. Read More →