BloodHound Enterprise: Function App Upgrade Fixes Data Collection and Ingestion Gaps

Deployment source moved to stable Microsoft repo, custom table schemas fixed, and Function App ingestion enhanced for reliable attack path visibility. Read More →

VMware vCenter ASIM Parser: DvcId Type Correction Prevents Query Failures

Fixed critical data type mismatch in VMware vCenter authentication parser that caused DvcId field queries to fail. Read More →

Visa Threat Intelligence: Connector Description Update for Certification

Updated Data Connector description in Visa Threat Intelligence solution to resolve certification failure. Read More →

Claroty: Enhanced IoT/OT Detection with Improved Alert Fidelity

Updated 9 analytic rules and 10 hunting queries with strengthened entity mapping, alert details, and MITRE coverage for OT/IoT network monitoring. Read More →

ZeroFox Digital Risk Protection: Complete CCF Migration with Dual Solution Architecture

ZeroFox splits legacy connector into dedicated Alerts and Threat Intelligence solutions using modern CCF architecture with 17 specialized data streams. Read More →

Solutions Analyzer: Fix Connector Overcount in CCF v2 Solutions

Solutions Analyzer was double-counting connectors in CCF v2 solutions due to azuredeploy wrapper files creating phantom duplicates. Read More →

MISP2Sentinel: Critical Table Reference Fix for Upload Indicators API

MISP threat intelligence connector was broken due to incorrect table reference — deployments had zero indicator ingestion until this fix. Read More →

Vaikora AI Agent Security Monitoring for Defender for Cloud

New Vaikora solution enables real-time AI agent threat detection through automated security alert ingestion and behavioral anomaly monitoring. Read More →

Microsoft Threat Intelligence TAXII Export Connector Moves to General Availability

Microsoft’s TAXII Export connector for Threat Intelligence objects is now GA, removing preview limitations for production TI sharing workflows. Read More →

Salesforce Service Cloud Connector: Enhanced Event Log Coverage and Multi-Domain Support

Major connector upgrade introduces comprehensive event field collection and multi-tenant monitoring capabilities. Read More →

Teams Social Engineering Detection: New Hunting Queries for RMM-Based Attacks

Two new hunting queries detect Teams phishing campaigns that lure victims into launching remote access tools, addressing the Storm-1811 / Black Basta cross-tenant attack pattern. Read More →

Joe Sandbox Solution: ARM Template Fixes and IOC Handling Improvements

Joe Sandbox solution updated to v3.0.1 with Azure template fixes, updated storage API versions, and improved IOC processing in playbooks. Read More →

Abnormal Security CCF Connector: Schema Alignment Fixes Column Visibility Gaps

Abnormal Security CCF connector v3.0.1 fixes table column naming to match Microsoft Log Analytics output, restoring access to previously missing metadata fields. Read More →

Azure DevOps Auditing: Fixing Broken Connector After Parameter Mismatch

Critical configuration fix resolves parameter name mismatch that prevented Azure DevOps audit log ingestion entirely. Read More →

CrowdStrike Falcon Data Replicator: Incorrect Deprecation Reversed, Connector Restored to Active Status

CrowdStrike’s Function App-based data replicator was incorrectly deprecated and has been restored to active status to maintain government deployment support. Read More →

Upwind Connector: Function App Deployment Fixed After Broken Code Deployment

Upwind connector Function App deployment was failing due to incorrect zip structure and ARM template configuration - fixed with flat zip layout and implicit hosting plan. Read More →

GreyNoise Threat Intelligence: Packaging Fixes and Security Improvements

Fixed Function App deployment packaging errors and improved security by converting ARM template secrets to secure strings. Read More →

Cloudflare Connector: Critical DCR Fix Restores Data Ingestion After Field Mapping Failures

Fixed DCR transformKql failures for Type field and invalid data types that were preventing Cloudflare log ingestion. Read More →

Entra ID Brute Force Detection: Renamed for Broader Windows Device Coverage

Analytic rule renamed from Cloud PC-specific to cover all Entra-authenticated Windows devices, clarifying detection scope without logic changes. Read More →

Logstash Output Plugin: Documentation Update for Version 2.1.1

Version bump to 2.1.1 with efficiency improvements noted but no connector logic changes. Read More →