Trend Micro Vision One — urllib3 Security Update Fixes Critical DoS Vulnerabilities

Dependency update from urllib3 1.26.20 to 2.6.0 addresses two high-severity CVEs preventing DoS attacks via decompression bombs and content encoding chains. Read More →

ESET Protect Platform Connector: urllib3 Security Update for CVE Fixes

Updated urllib3 dependency to v2.6.0 to address two high-severity CVEs affecting HTTP decompression handling. Read More →

Microsoft Copilot Connector — Critical Table Name Update from LLMActivity to CopilotActivity

Microsoft Copilot connector fixes critical table reference issue, standardizing on official CopilotActivity table name across all components. Read More →

Ermes Browser Security Connector — Enhanced Data Fidelity and Multi-Tenant Support

CCF connector update fixes timestamp extraction, adds configurable API endpoints, and expands log data collection for better event visibility. Read More →

Microsoft Entra ID Playbooks: API Permission Updates for Session Revocation

Updates Revoke-AADSignInSessions playbook documentation to use correct User.RevokeSessions.All permissions instead of broader User.ReadWrite.All. Read More →

Contrast ADR Detection: Fixed Field Reference Causing Query Failures

Corrected field name from incident_id_s to incidentId_s in Contrast EDR detection rule. Read More →

Lookout Mobile Security: Parser Fixes and Executive Dashboard Enhancement

Lookout solution updated to v3.0.1 with parser fixes, comprehensive security dashboards, and enhanced analytic rules. Read More →

Slack Audit Parser: Fixed Broken Field References Causing Data Loss

Corrected field name parsing errors in SlackAuditV2_CL that were causing channel sharing status and IP context data to return null. Read More →

ProofPoint TAP Detection Rules Updated for v2 Connector Migration

Two ProofPoint TAP Analytic Rules updated to reference ProofpointTAPv2 connector ID, ensuring compatibility with the newer connector version. Read More →

Fortigate ASIM Parser: Field Name Consistency Fix for Network Session Schema

Field name inconsistencies in Fortigate ASIM parsers corrected to ensure proper schema compliance and data normalization. Read More →

SAP Solution: Agentless Package Upgraded to Log Analytics v2 API

SAP agentless package updated to use Log Analytics v2 API for heartbeats and added audit log user exclusion capabilities. Read More →

Proofpoint POD: Fixing WebSocket Connector to Eliminate Duplicate Data Ingestion

Removed time-based query parameters from Proofpoint On-Demand Email Security connector to prevent duplicate data ingestion caused by time rounding overlaps. Read More →

SOC Prime Platform: New CCF Connector for Audit Log Visibility

New SOC Prime Platform audit logs data connector added using CCF framework, providing visibility into SOC Prime TDM platform user activities and administrative actions. Read More →

ASIM WebSession Parser: Fixed Broken Azure Firewall Template Reference

Corrected case-sensitive path reference that was preventing Azure Firewall WebSession parser deployment. Read More →

ProofPoint TAP Solution: Fixed ARM Template Validation Failures

Resolved ARM-TTK validation errors preventing ProofPoint TAP solution deployment. Read More →

SentinelSOARessentials: New Entity Analyzer Playbooks for Incident Response

Three new entity analyzer playbooks added with HTTP, URL, and incident triggers for automated URL and user entity enrichment. Read More →

Cyera DSPM Solution: Marketplace Preparation and Configuration Updates

Marketplace preparation updates including publisher ID changes, logo corrections, and DCR configuration fixes for Cyera DSPM solution. Read More →

AWS CloudTrail Connector: Fixed Script Logic and Command Syntax Errors

Corrected PowerShell variable scoping and AWS CLI command syntax in CloudTrail configuration script. Read More →

Corelight Network Monitoring: Six New Aggregation Parsers for Enhanced Analytics

Added six new aggregation parsers for Corelight sensor data including DNS, HTTP, files, connections, SSL, and weird events with improved CIM mapping. Read More →

AbuseIPDB Playbooks: Typo Fixes and Logo Source Update

Minor documentation and configuration fixes for AbuseIPDB playbooks including corrected image source and typo corrections. Read More →