Azure Firewall: Five New IDPS Analytic Rules for Advanced Threat Detection

Azure Firewall solution expanded with 5 new analytic rules targeting high/medium severity threats, DDoS attacks, web application attacks, and privilege escalation attempts. Read More →

Lumen Threat Feed: V2 Connector Replaces Deprecated V1.1 with Paginated API Support

Lumen Defender Threat Feed solution updated with V2 connector using new API v3 endpoint, removing deprecated V1.1 connector entirely. Read More →

ASIM User Management: AWS CloudTrail Parser Enables IAM and Cognito Visibility

New ASIM parser normalizes AWS CloudTrail user management events from IAM and Cognito services into Microsoft Sentinel. Read More →

ASIM Authentication Schema: NetworkCleartext SubType Added

ASIM Authentication schema expanded to include NetworkCleartext authentication subtype for cleartext password events. Read More →

Tenable App: Enhanced Rsyslog Configuration with Source IP Filtering

Additional rsyslog configuration files added with source IP filtering capabilities to improve log collection accuracy and data connector UI guidance. Read More →

Documentation Fix: Broken Links Resolved in Microsoft Entra ID and Network Session Essentials

Customer-reported broken links fixed in analytic rule descriptions with corrected MITRE technique references and restored documentation. Read More →

Global Secure Access: Enhanced Threat Intelligence Correlation and MCP Monitoring

New analytic rules correlate threat intelligence indicators with GSA traffic while MCP Servers Dashboard provides Model Context Protocol server monitoring. Read More →

SAP Solution: Agentless Integration Suite Tooling Added for Enhanced ERP Connectivity

New PowerShell tooling enables agentless SAP data collection via Integration Suite with dual-mode credentials and CSV-based destination management. Read More →

Cisco Duo Security: Critical Deployment Fix Resolves Portal Installation Failures

Azure portal deployment failures resolved by fixing empty location parameters and updating Python runtime compatibility to prevent connector breakage. Read More →

New Solution: meshStack Platform Event Logs Integration for Cloud Governance

meshStack event logging connector enables cloud platform governance monitoring by ingesting developer platform events into Microsoft Sentinel. Read More →

ASIM AlertEvent: Microsoft Defender XDR Parser Enhanced with Improved Field Mappings

Microsoft Defender XDR AlertEvent parsers updated with optimized KQL logic, corrected field mappings, and enhanced IP address collection. Read More →

Solutions Analyzer: Enhanced Documentation with Lake-Only Ingestion and Statistics Features

Comprehensive documentation tool update adds lake-only ingestion tracking, collection methods index, and enhanced connector association analysis. Read More →

New Solution: TacitRed Defender Threat Intelligence Integration

Official TacitRed Defender TI solution from Data443 enables automated sync of compromised credentials to Microsoft Defender Threat Intelligence. Read More →

TacitRed SentinelOne Solution: Partner Center Metadata Alignment and Template Fixes

TacitRed SentinelOne solution metadata updated for Partner Center alignment with ARM template variable corrections. Read More →

TacitRed Threat Intelligence Solution: Partner Center Metadata Alignment

TacitRed solution metadata updated for Partner Center publisherId.offerId alignment. Read More →

CyberArk EPM Connector: Critical Package Fix Restores Function App Deployment

Missing .python_packages dependency added to function app package, resolving deployment failures that blocked connector installations. Read More →

ASIM Sudo Authentication Parser: Schema Version 0.1.4 Compliance and Field Mapping Enhancements

ASIM sudo parser updated to schema 0.1.4 with improved field mappings, severity normalization, and code deduplication. Read More →

Oracle Cloud Infrastructure Connector: Group Cursor Support for OCI Streaming

OCI connector now supports Group Cursor mode alongside Individual Cursor for improved streaming partition consumption flexibility. Read More →

Rapid7 InsightVM Data Connector: Azure Functions Extension Bundle Upgrade to 4.x

Rapid7 InsightVM Function App connector updated to use latest 4.x Azure Functions extension bundles from deprecated 3.x version. Read More →

Microsoft Defender XDR: New Hunting Query for Punycode Lookalike Domain Phishing

Advanced hunting query detects punycode domains using Cyrillic, Greek, and fullwidth ASCII characters to visually impersonate legitimate domains in email and Teams. Read More →