ASIM NetworkSession Parser: Critical IP Address Mapping Fix for Azure NSG Flow Data

Azure NTANetAnalytics parser now correctly maps source and destination IP addresses from PublicIPs fields when primary IP fields are empty, closing a data fidelity blind spot. Read More →

OCI Data Connector: Packaging Configuration Fix

Oracle Cloud Infrastructure connector package repair addresses polling configuration naming issue preventing proper deployment. Read More →

VMware ESXi Solution: Broken Link Removed

Documentation maintenance removing broken link from VMware ESXi solution. Read More →

SAP BTP: 10 New Enterprise Security Detections for Cloud Integration and Identity Service

New threat detection coverage for SAP BTP Cloud Integration tampering, identity service compromise, and audit service availability. Read More →

AWS Access Logs: Security Enhancement for SQS Principal Access Control

AWS S3 Server Access Logs CloudFormation template receives critical security update restricting SQS queue principal from wildcard to S3 service only. Read More →

Armis IoT Security Solution: Enhanced Log Ingestion and Data Collection Rule Integration

Major enhancement to Armis data connectors implementing Azure Monitor Logs Ingestion API with DCR support for improved data fidelity and performance. Read More →

Schema Correction: MITRE ATT&CK Field Name Fix Across Multiple Solutions

Critical schema update replaces deprecated requiredTechniques field with correct relevantTechniques field in analytic rules. Read More →

Threat Intelligence: Alert Severity Field Standardisation and Query Optimisation

Threat Intelligence solution updated with standardised severity field naming and query performance improvements in IP entity analytics. Read More →

Snowflake Connector: Data Ingestion Timing Fix and Parser Field Corrections

Snowflake connector updated with 120-minute ingestion delay and corrected timestamp parsing to address customer-reported data gaps. Read More →

Major Solution Release: Cyble Vision and Tropico Solutions Added Plus Multi-Solution Updates

Large release adds two new threat intelligence solutions (Cyble Vision, Tropico) and updates to 15+ existing solutions across the repository. Read More →

Miro Solution: New Enterprise Collaboration Security and Compliance Monitoring

New Miro solution added with CCF connectors for audit logs and content logs to enable collaboration platform security monitoring. Read More →

Microsoft Entra ID: New Conditional Access Security Insights and Monitoring Workbook

New Conditional Access SISM workbook added to provide comprehensive CA policy monitoring and Zero Trust analytics. Read More →

SAP BTP Tools: Improved Connection Management and Subaccount Naming

SAP BTP connector tools updated with better subaccount handling, connection naming, and performance optimisations. Read More →

WithSecure Elements Connector: Critical Security Fix for HTTP Decompression Vulnerabilities

WithSecure Elements connector urllib3 dependency updated to address two high-severity CVEs causing potential DoS attacks. Read More →

Box Connector: Critical Security Fix for HTTP Decompression Vulnerabilities

Box connector urllib3 dependency updated to address two high-severity CVEs causing potential DoS attacks. Read More →

Infoblox NIOS Parsers: Enhanced Log Filtering Reduces Noise in DHCP Monitoring

Updated Infoblox NIOS parsers exclude additional administrative log categories to improve signal-to-noise ratio. Read More →

Intel471: Added Verity471 Platform Support for Enhanced Malware Intelligence

Intel471 solution now supports the new Verity471 backend alongside Titan for ingesting malware threat indicators. Read More →

New Cyble Vision Threat Intelligence Solution: Comprehensive CCF-Based Alert Platform

Massive new Cyble Vision solution providing 40+ specialized detection rules and parsers for diverse threat intelligence feeds from dark web to cloud security. Read More →

GCP IAM Detection Logic Fixed — Correcting Service Account Key Detection Gaps

Two GCP IAM analytic rules had syntax errors preventing proper detection of token generation and key enumeration attacks. Read More →

SOX IT Compliance Solution Released: IT Change Monitoring for Financial Controls

New compliance monitoring solution provides IT systems change tracking and segregation of duties controls for Sarbanes-Oxley compliance programs. Read More →