GitHub Enterprise Connector: Improved API URL Configuration Guidance

Enhanced connector definition for GitHub Enterprise audit logs with clearer API URL field labels and format examples to reduce customer configuration errors. Read More →

Palo Alto Prisma Cloud Connector: Policy Data Restored with Missing "detailed" API Flag

Critical data fidelity fix for Palo Alto Prisma Cloud CCF connector — added missing “detailed” flag to API queries, restoring previously excluded policy field data. Read More →

UEBA Essentials: Five New Hunting Queries for Advanced Anomaly Analysis and Threat Triage

UEBA Essentials v4.1.0 adds five targeted hunting queries for high-score anomaly triage, trend analysis, template distribution, user-centric investigation, and malicious source IP identification. Read More →

Snowflake Connector: Data Parsing Logic Restored After SQL Query Malformation

Critical fix to Snowflake connector data parsing logic, switching from array-based extraction to proper JSON field extraction, restoring visibility across all log types. Read More →

SAP BTP Connector: Mass Onboarding Tools for Multi-Subaccount Deployment

PowerShell automation tools added for scalable SAP BTP subaccount onboarding to Microsoft Sentinel, enabling SOC teams to efficiently connect dozens of BTP subaccounts at once. Read More →

ZeroNetworks Solution Connector Deprecation: Function App Integration Removed

ZeroNetworks solution updated to version 4.0.0, removing deprecated Function App connector per Microsoft guidance. Read More →

NCSC-NL Threat Intelligence Sharing: Playbook Bug Fixes and JSON Structure Improvements

Dutch National Detection Network threat intelligence sharing solution updated to v3.0.1 with playbook parameter fixes and improved JSON structure. Read More →

New Quokka Qscout Mobile App Security Solution: Mobile Threat Detection Visibility

CCF connector and detection rule for Quokka Qscout mobile app security analysis platform provides visibility into malicious mobile application findings. Read More →

Salesforce Service Cloud Connector: Column Name Bug Fix Plus Multi-Solution Updates

Fixed critical column name mapping bug in Salesforce Service Cloud CCF connector preventing proper data ingestion. Read More →

ZeroFox Enterprise: New CCF Connector Replaces Deprecated CCP Implementation

ZeroFox alert ingestion modernized with CCF-based connector, replacing deprecated CCP framework. Read More →

Microsoft Teams Security: 9 Additional Hunting Queries for Advanced Threat Detection

Extended Teams protection hunting coverage with queries for partner impersonation, admin submissions, and external sender analysis. Read More →

Open Systems Connector: aiohttp Security Update 3.10.11→3.12.14 Plus Multi-Solution Changes

Open Systems connector updated aiohttp dependency addressing potential security vulnerabilities, bundled with extensive solution packaging updates. Read More →

Threat Intelligence: Critical Logic Fix Stops False Alerts on Revoked Indicators

Broken condition in CloudAppEvents threat intelligence detection fixed to prevent firing on revoked/deleted indicators. Read More →

QualysVM Connector: API Rate Limiting and Configurable Truncation Protection

QualysVM connector enhanced with 1 QPS rate limiting and configurable truncation limits to prevent API abuse. Read More →

Check Point Cyberint Alerts: DCR Transform Fix and Customer Name Header Addition

Check Point Cyberint Alerts connector v3.0.1 fixes DCR formatting and adds customer name header for proper API authentication. Read More →

Threat Intelligence: AppService HTTP Logs Detection Restored After Missing Column Fix

Critical fix for broken IP entity detection rule that was missing AlertPriority column causing template failures. Read More →

Microsoft Teams Security: 7 New Hunting Queries for URL Threat Detection

New hunting queries added to detect malicious URL clicks, ZAP events, and user submissions in Microsoft Teams. Read More →

Cyera DSPM Solution: New Data Security Posture Management Integration

New solution added for Cyera DSPM providing data security monitoring with both CCF and Function App connectors. Read More →

Varonis Purview: New Push Connector for Microsoft Purview Data Governance Integration

New solution providing push connector to sync Varonis data resources into Microsoft Purview via Sentinel data lake. Read More →

Open Systems Solution: New Multi-Product Security Platform with ASIM Parsers

New Open Systems solution enables ingestion from multiple security products via Logstash with ASIM parsers for authentication, firewall, and proxy logs. Read More →