Multiple Solution Updates: GKE GA Promotion and SAP ETD Investigation Capability

Google Kubernetes Engine connector promoted to GA while SAP ETD Cloud gains investigation data ingestion and enhanced detection coverage. Read More →

Threat Intelligence: TAXII Export Connector Added for External Sharing

New TAXII Export connector enables Microsoft Sentinel to share threat intelligence indicators with external TAXII 2.1 servers. Read More →

AWS S3 Server Access Logs Connector: GA Promotion Removes Preview Status

AWS S3 Server Access Logs connector promoted from Preview to General Availability with version 3.0.1. Read More →

Cloudflare Connector: Security Dependency Update for aiohttp Library

aiohttp library updated from 3.10.11 to 3.12.14 in Cloudflare connector addressing potential security vulnerabilities. Read More →

SAP ETD Cloud: Investigations Data Source Added for Enhanced Threat Tracking

SAP Enterprise Threat Detection solution expands with new Investigations connector, providing comprehensive investigation tracking and correlation capabilities. Read More →

Illumio Insight Connectors: Enhanced Documentation and Polling Configuration

Documentation improvements and polling frequency adjustment enhance user experience for Illumio threat analysis deployment. Read More →

Samsung Knox Asset Intelligence: DCR Schema Reduction and Rule Removal

Knox connector DCR updated to remove 13 event types, with corresponding analytic rule deleted due to missing data source. Read More →

VirtualMetric DataStream Solution: New Multi-Path Data Ingestion Platform for Sentinel

New VirtualMetric DataStream solution provides comprehensive data ingestion capabilities with ASIM support and multiple deployment options for Sentinel and data lake environments. Read More →

Cisco Duo Security: Support Information and Metadata Updates

Solution package updated with revised support information and compatibility metadata. Read More →

Network Session Anomaly Detection: Simplified EPS Threshold Logic

Two network session analytic rules updated with unified EPS threshold and simplified query logic for improved maintainability. Read More →

MongoDB Atlas: Fixed Category Filter Bug and Improved Deployment Instructions

Fixed filtering bug when category is ’none’ and streamlined deployment documentation for MongoDB Atlas data connector. Read More →

Google Threat Intelligence: Enhanced Filtering for Threat List Queries

Custom connector updated with filter query parameters for more targeted threat intelligence retrieval. Read More →

Vectra XDR Connector: Python Runtime Upgrade and Authentication Security Fix

Vectra XDR connector upgraded to Python 3.12 and switched from DefaultAzureCredential to managed identity for production security. Read More →

SecurityBridge App Schema Update: New SecurityBridge_CL Table Enables Native SAP Log Ingestion

SecurityBridge App solution adds dedicated SecurityBridge_CL custom table with enhanced schema for native SAP security log processing via DCR. Read More →

GCP IAM Parser: Critical Type Handling Fix Resolves Parser Execution Failure

GCP IAM parser updated to version 3.0.7 with explicit type conversions for bool and datetime fields, fixing parser execution failures that prevented data ingestion. Read More →

BloodHound Enterprise Solution: Major v2.0 Upgrade with 105 New Detection Rules

Complete solution overhaul adds 105 analytic rules, new workbooks, and updated data connector with Azure Function v2 for enhanced Active Directory threat detection. Read More →

Tanium Solution: Content Hub Preview Image Display Fix (P0)

Fixed workbook preview image metadata for proper Content Hub display across multiple solutions including Tanium. Read More →

SOC Handbook: Fixed Mean Time to Triage Calculation Logic

Security Operations Efficiency workbook query corrected to properly calculate incident triage metrics. Read More →

Continuous Diagnostics & Mitigation: Workbook Hyperlink and Metrics Fix

Fixed broken hyperlinks and metrics in the Continuous Diagnostics & Mitigation workbook. Read More →

Tanium Playbook API Failure Fix: URL Encoding Bug Breaks Host Quarantine Operations

Critical fix for Tanium quarantine/unquarantine playbooks resolves API failures caused by improper URL encoding of package names containing special characters. Read More →