Snowflake Multiple Failed Queries Detection: Fixed False Positives from Load Operations

Snowflake detection rule now filters out events lacking QueryExecutionStatus to prevent false alerts from data loading operations. Read More →

Solution Package Tool: Local Version Bumping Mode Added for Offline Development

CreateSolutionV3 script now supports offline semantic versioning with local version management alongside existing catalog API mode. Read More →

OAuth Data Connectors: Dynamic Redirect URI Support Simplifies Authentication Setup

Four OAuth-based data connectors now support dynamic redirect URIs, eliminating manual Azure portal configuration requirements. Read More →

ASIM SSH Authentication Parser: Improved Invalid User Event Parsing

OpenSSH authentication parser now correctly extracts source IP addresses from “Invalid user” events regardless of port format. Read More →

CI Pipeline: Sample Data Validation Workflow Modernized to Node.js 20

Legacy npm 6.14.18 dependency causing validation failures replaced with modern Node.js 20 LTS setup and deterministic builds. Read More →

GitHub Enterprise Cloud Connector: Audit Log Data Ingestion Now Generally Available

GitHub Enterprise audit log connector and 11 accompanying detection rules promoted from Preview to GA status. Read More →

Versasec CMS Solution: Publishing Configuration Updates

Versasec CMS solution packaging updated to meet Content Hub publishing requirements. Read More →

BigID DSPM: P0 ARM Template Fix Addresses Deployment Failure

ARM template toolkit validation failure resolved by centralizing hardcoded step identifiers into reusable variables. Read More →

ASIM Authentication Parser: Linux Su Command Enhanced with Failed Authentication Support

Linux su parser significantly enhanced to capture failed su attempts, correct event classification from Elevation to Logon, and improve field mappings for comprehensive privilege escalation monitoring. Read More →

ASIM Authentication Parser: Palo Alto Cortex Data Lake Performance and Schema Fixes

Palo Alto Cortex Data Lake authentication parser enhanced with schema compliance improvements, performance optimizations, and corrected field mappings for better data fidelity. Read More →

ASIM Authentication Parser: Microsoft 365 Defender Schema Compliance Enhancement

Microsoft 365 Defender authentication parser improved ASIM compliance by removing unnormalized columns and relocating process/hash metadata to AdditionalFields structure. Read More →

BeyondTrust PM Cloud: Workbook Preview Image Standardization

Renamed BeyondTrust PM Cloud workbook preview images from Dark/Light to Black/White convention and added BeyondTrust logo asset for UI consistency. Read More →

Azure DevOps Auditing Solution: Description Text Cleanup and Repackaging

Azure DevOps Auditing solution repackaged with updated description removing outdated streaming configuration text references. Read More →

Microsoft Defender XDR: SUNSPOT Detection Rule Documentation Update

Updated SUNSPOT malware detection rule with corrected reference link formatting and MITRE technique mapping fixes across multiple solutions. Read More →

New Solution: JoeSandbox Threat Intelligence and Malware Analysis Platform Integration

Complete JoeSandbox solution deployment enabling automated malware analysis, threat intelligence feed ingestion, and incident enrichment playbooks for Microsoft Sentinel. Read More →

Microsoft Defender XDR: Teams Hunting Queries Version Number Fix

Corrected malformed version numbers in Microsoft Teams threat hunting queries from invalid “l.0.0” to proper “1.0.0” format. Read More →

Check Point Cyberint IOC Connector: Critical Data Ingestion Restoration

Cyberint threat intelligence connector restored from complete ingestion failure caused by malformed API endpoint and duplicate schema nesting blocking IOC data collection. Read More →

Multi-Solution Link Updates: MITRE Technique Corrections and Reference Refreshes

Updated outdated links and corrected MITRE ATT&CK technique mapping in detection rules across Microsoft Business Applications, Microsoft Defender XDR, and Windows Security Events solutions. Read More →

Compliance Solutions: Microsoft Exchange Product Link Rebrand Update

NIST SP 800-53 and Zero Trust compliance workbooks updated with current Microsoft Defender for Office 365 documentation links following EOP rebrand. Read More →

ASIM Authentication Parser: Enhanced SSH Authentication Method Detection

SSH authentication parser now accurately identifies logon methods (password, PKI, PAM) and adds improved field mappings for better authentication visibility. Read More →