VMware Workspace ONE Connector: Corrupted Poller Resource Names Prevented All Deployments

A stray {{GUID}} suffix in the ARM template poller resource name expressions caused a “content template not found” error on every Connect attempt, making the VMware Workspace ONE CCF connector non-deployable since its v3.0.0 release. Read More →

CEF and Syslog Connector Templates Modernised: MMA Instructions Replaced with AMA/Marketplace Pattern

The shared ISV connector templates for CEF and Syslog were still instructing partners to install the retired Microsoft Monitoring Agent; both templates now reflect the AMA-based ingestion pattern, correct the sharedKeys permission artifact, and replace placeholder queries with vendor-discriminated KQL. Read More →

VMware Carbon Black Cloud: DCR Type Mismatch Caused Silent Data Loss in Alerts and Watchlist Streams

A type mismatch between the Carbon Black API (numeric severity, long PIDs) and the DCR schema (string) caused ingestion failures for the Alerts and Watchlist streams; v3.0.9 corrects the schema and adds tostring() casts in the transformKql. Read More →

Digital Shadows Connector: Logs Ingestion API Migration Required Before September 2026 Ingestion Cutoff

The Digital Shadows SearchLight connector has been fully migrated from the retiring HTTP Data Collector API to the Logs Ingestion API (DCE + DCR + Managed Identity), with a new table DigitalShadows_V2_CL replacing the legacy DigitalShadows_CL – customers who do not upgrade will lose all Digital Shadows ingestion on 2026-09-14. Read More →

Isolate-MDEMachine Playbook: Missing Machine.Read.All Permission Causes Runtime Failures

Any deployment of the Isolate-MDEMachine playbook that followed the existing post-deployment instructions has been silently failing with a Forbidden error at runtime – device isolation never executed. Read More →

New Check Point Harmony Email and Collaboration Solution Adds Email Threat Detection and SOAR Response

A new Microsoft Sentinel Solution for Check Point Harmony Email and Collaboration brings a CCF/DCR-based data connector ingesting into CheckpointHEC_CL, one phishing Analytic Rule, five Hunting Queries covering phishing/DLP/spam, and a Quarantine Playbook for automated response. Read More →

Sentinel Training Lab: Idempotent Bash Script Eliminates Graph Propagation Race Condition in UAMI Setup

A new Bash onboarding script for the Microsoft Sentinel Training Lab resolves a race condition where assigning the CustomDetection.ReadWrite.All Graph app role immediately after UAMI creation would fail due to service principal propagation lag. Read More →

CrowdStrike Falcon Analytic Rules Renamed to Clarify CEF via AMA Ingestion Source

Two CrowdStrike Falcon Analytic Rules are renamed to prepend “Common Event Format (CEF) via AMA -” to their titles, with no logic changes — purely a UI labeling update to clarify the ingestion mechanism. Read More →

Box CCF Connector: Restoring Classification Visibility and Fixing OAuth Auth Failure After DCR Field Mismatch

The Box CCF connector had a broken DCR field mapping (source_owned_by_id pointing to owned_by.type) and missing classification columns, causing data fidelity gaps and an OAuth 400 error that prevented connectivity for affected deployments. Read More →

Microsoft Entra ID: Sign-in Detection Blind Spot for Disabled Accounts Closed Across Commercial and Government Tenants

The SigninAttemptsByIPviaDisabledAccounts Analytic Rule was silently missing sign-in attempts that returned the shorter ResultDescription variant “The user account is disabled.” - meaning brute-force attempts against disabled accounts from a given IP were going undetected in affected tenants. Read More →

New Mimecast Email Security Connector: CCF Push Replaces Legacy Function App with Credential-less Ingestion

A new Content Hub solution delivers credential-less Mimecast event ingestion via CCF Push directly to a custom MimecastEvents_CL table, with 7 KQL parser views maintaining backward compatibility with legacy Function App column schemas. Read More →

Forescout Host Property Monitor Migrates to CCF Push Connector with Three New Custom Tables

The Forescout Host Property Monitor solution (v3.1.0) adds a CCF push connector backed by a new DCR with three custom streams — deployments that have not upgraded retain the old connector but miss richer endpoint telemetry now available in the new tables. Read More →

Google Threat Intelligence ASIM AlertEvent Parser: Relevance System Alerts Now Normalised

New ASIM AlertEvent parsers add native normalisation for Google Threat Intelligence Relevance System Alerts, making GTI alert data available to all source-agnostic detections using the imAlertEvent and ASimAlertEvent schemas. Read More →

Cisco Secure Endpoint ASIM AlertEvent Parser: Missing Mandatory Fields Causing Data Fidelity Gap

TimeGenerated and Type fields were absent from the Cisco Secure Endpoint ASIM AlertEvent parser output, causing null returns for all rows referencing these now-mandatory schema fields in downstream queries. Read More →

New ASIM AgentEvent Parser Unlocks Anthropic Claude Compliance Log Normalization

Two new ASIM AgentEvent parsers normalize Anthropic Claude Compliance API logs (via BlueVoyant CCF connector) into the ASIM AgentEvent schema, enabling unified hunting across AI agent activity events. Read More →

Okta SSO Detection Suite: Richer Alert Context, Configurable Thresholds, and Corrected Entity Mappings Across 9 Rules and 10 Hunting Queries

Nine Analytic Rules and ten Hunting Queries for Okta SSO have been overhauled with configurable thresholds, allowlist variables, improved JSON parsing, and corrected entity mappings, closing fidelity gaps that degraded Sentinel entity behaviour and alert context. Read More →

New Check Point Harmony Email and Collaboration Connector: Four-Stream Email Threat Visibility via CCF

A new Microsoft Sentinel CCF connector ingests Check Point Email Security (Harmony Email and Collaboration) data across four streams covering security events, anti-phishing exceptions, spam exceptions, and audit logs, unlocking visibility into zero-day, phishing, account takeover, DLP, and shadow IT threats via email. Read More →

New Netskope Alerts and Events Solution: DLP, Shadow IT, and Malware Threat Visibility via CCF Blob Storage Connector

A new Microsoft Sentinel solution delivers full-stack Netskope Security Cloud visibility including DLP incidents, malware detections, policy enforcement, and Shadow IT via a CCF Blob Storage connector ingesting gzip-compressed positional CSV into a 254-column custom table. Read More →

New Atlassian Organization Audit CCF Connector: Cloud Org-Level Audit Events Now Ingestible in Sentinel

A brand-new CCF connector brings Atlassian Cloud organization audit events (user management, authentication, group changes, policy updates) across Jira, Confluence, Bitbucket, Trello, Opsgenie, Statuspage, and Loom into the AtlassianAuditEvents_CL table in Microsoft Sentinel. Read More →

SentinelOne V2 CCF Connector: UAM GraphQL Alerts Now Visible in Sentinel (Plus Packaging Fix)

The SentinelOne solution adds a new CCF-based V2 connector ingesting Unified Alert Management (UAM) alerts from the GraphQL API into SentinelOneAlertsV2_CL, closing a blind spot for Wayfinder, cloud, identity, STAR, and third-party detections that the legacy REST connector never surfaced. Read More →