New Solution: Whisper Security Adds Internet-Scale Infrastructure Graph Coverage to Microsoft Sentinel

Whisper Security new Sentinel solution ingests threat intelligence from a 7-billion-node internet infrastructure graph, unlocking C2, Tor, BGP anomaly, and domain-ASN threat detections that have no coverage in the default Sentinel content. Read More →

New Tailscale CCF Solution: Zero-Trust Network Telemetry and Detection Coverage for Sentinel

A new community solution delivers full Tailscale zero-trust network observability into Microsoft Sentinel via two CCF data connectors (Standard and Premium tiers), shipping 24 Analytic Rules, 22 Hunting Queries, and ASIM NetworkSession parsers covering identity abuse, lateral movement, DNS manipulation, and network exfiltration. Read More →

Akamai DDOS Protection CCF Connector Promoted to GA with Polling Timeout Tightened

The Akamai DDOS Protection CCF connector exits public preview with a polling timeout cut from 120s to 35s – teams should validate API response times before upgrading to avoid WAF event ingestion gaps. Read More →

Auth0 Connector: Multi-Domain Support Added with Per-Host Tagging via DCR Schema Update

The Auth0 CCF connector (v3.2.0) now supports ingesting logs from multiple Auth0 tenants simultaneously, tagging each record with a new Auth0Domain column - organizations running multiple Auth0 environments previously had no native way to distinguish log sources in Auth0Logs_CL. Read More →

Hybrid Attack Kill-Chain: CVE Exploitation on Third-Party Network Appliances Now Correctly Hunted

A hunting query was replaced wholesale - the previous version hunted Azure network config tampering by compromised identities, while the corrected version targets known CVE exploitation against third-party perimeter appliances (Fortinet, Palo Alto, Ivanti, SonicWall, Citrix) via CommonSecurityLog. Read More →

Four New Hunting Queries Add AI Agent Configuration Drift Detection via AgentsInfo Table

Four new hunting queries give SOC teams their first structured visibility into AI agent configuration drift covering instruction tampering, unauthorized MCP server additions, new owner grants on MCP-enabled agents, and org-wide sharing expansion. Read More →

New HubSpot CCF Connector: Audit Logs and Security Activity Now Ingestible into Microsoft Sentinel

A community-contributed CCF connector brings HubSpot account audit logs and security activity events into Microsoft Sentinel for the first time, populating two custom tables via DCR. Read More →

XBOW Connector: API Version Bump to Deprecate April 2026 Endpoint

The XBOW Function App connector updates its API version constant from 2026-04-01 to 2026-07-01 ahead of the old endpoint deprecation; no detection logic changes. Read More →

Rubrik Security Cloud: Function App Python Runtime Bumped to 3.12 to Address Package Vulnerability

The RubrikWebhookEvents Function App connector ARM template updates the Azure Functions runtime from Python 3.11 to Python 3.12 to resolve an unspecified Python package vulnerability; no CVE was cited — review the updated package versions in the bundled zip for any security advisories. Read More →

Oracle Cloud Infrastructure Connector: DCR Overhaul Restores SrcIpAddr Visibility and Eliminates Triple-Ingestion Cost Multiplier

The OCI CCF connectors DCR transform was storing every event up to three times causing 3x ingestion costs, retaining credential-bearing headers in a 180-day table, and leaving SrcIpAddr null for all audit events due to a field-path typo; this overhaul slims the schema from 201 to 86 columns, fixes the data-exposure risk, restores source-IP visibility, and retargets all 10 Analytic Rules and 10 Hunting Queries to the CCF connector so they show as connected. Read More →

Elastic Agent CCF Connector Promoted to GA: Template Variable Bug Fixed in Graph Queries

The Elastic Agent CCF connector moves from public preview to GA (v3.0.1), simultaneously fixing a connector definition bug where graphQueriesTableName template substitution failed in graph queries, leaving the Sentinel connector UI unable to render data volume metrics. Read More →

ASIM Authentication: New Palo Alto Prisma Cloud Compute Parser Brings Login Visibility to Sentinel

Two new ASIM Authentication parsers normalize Palo Alto Prisma Cloud Compute management audit login events into the unified schema, closing a previously uncovered authentication blind spot for Prisma Cloud Compute deployments. Read More →

42Crunch API Protection Solution: Publisher and Support Metadata Update (v3.0.2)

Version 3.0.2 bumps publisher and support contact information in SolutionMetadata.json only — no detection logic, connector configuration, or parser changes. Read More →

Qualys VM KnowledgeBase Connector: Restoring Vulnerability Intelligence After CCF Polling Blind Spot

The Qualys KB CCF connector was silently dropping vulnerability records – switching from publish-time to last-modified filtering and fixing optional parameter handling restores complete KB ingestion. Read More →

1Password Connector: Silent Data Loss Fixed for Late-Synced Item Usage Events

The 1Password CCF connector was silently dropping item usage events (e.g., credential reveals and secure-copies) whenever client sync was delayed by 10+ minutes, due to time-window polling advancing past client-side event timestamps – switched to cursor-based PersistentToken polling to close this blind spot. Read More →

Gambit Security Solution: Unique Offer ID to Unblock Content Hub Publishing

Metadata-only update replacing the duplicate offerId so the Gambit Security solution can be published to Microsoft Sentinel Content Hub without Partner Center conflicts. Read More →

New ASIM Authentication Parser Adds Google Workspace Login Visibility via GoogleWorkspaceReports Table

A new ASIM Authentication parser for Google Workspace Logins normalises login, logout, and suspicious sign-in events from the GoogleWorkspaceReports table, enabling source-agnostic detections to cover Google Workspace identity activity for the first time. Read More →

Atlassian Organization Audit Connector: Marketplace Validation Fix Unblocks Deployment

An empty instructions array in the connector UI definition was failing ARM-TTK validation, blocking this connector from being published or updated in the Marketplace. Read More →

Rapid7 InsightVM Solution: CCF Version Bump to 3.3.0

Packaging-only update adjusting the CCF version to 3.3.0 in the Rapid7 InsightVM solution; no connector logic or detection content changed. Read More →

Transmit Security Connector Migrated from Deprecated Function App to CCF

The legacy Azure Function App-based Transmit Security connector is replaced by a CCF connector that polls the REST API natively and writes to a new custom table, eliminating the customer-managed Function App dependency. Read More →