Halcyon Anti-Ransomware: Connector Overhaul from ASIM to OCSF Schema Architecture

Halcyon connector migrated from direct ASIM ingestion to OCSF schema with ASIM transformation parsers, replacing 5 custom tables with unified HalcyonEvents_CL table. Read More →

SOCRadar XTI Platform: New Extended Threat Intelligence Solution Launches with Bidirectional Sync

SOCRadar XTI Platform solution now available in Content Hub with automated alarm import, incident sync, and comprehensive threat intelligence monitoring capabilities. Read More →

Microsoft 365 Defender Process Parsers: Enhanced File Metadata Visibility

ASIM Process Event parsers for Microsoft 365 Defender now extract file version metadata, improving process attribution and hunt query precision. Read More →

Microsoft Sentinel Training Lab: Authentication Simplified to UAMI-Only

Training lab removes dual-auth complexity, standardizing on User-Assigned Managed Identity for Microsoft Defender XDR custom detection rule deployment. Read More →

BitSight Solution: Packaging Fix Resolves Content Hub Republishing Failure

BitSight solution package updated to v3.1.1 fixing a solution ID issue that prevented proper republishing to Microsoft Sentinel Content Hub. Read More →

Cyjax Threat Intelligence Platform: Complete Solution for IOC Ingestion and Investigation

New comprehensive Microsoft Sentinel integration adds automated IOC collection, incident enrichment, and interactive threat intelligence dashboards for the Cyjax platform. Read More →

Lookout Connector: ARM Template Fix Prevents Deployment Location Errors

Fixed workspace-location defaultValue in Lookout solution ARM template to prevent deployment failures when location parameter is unset. Read More →

Visa Threat Intelligence: Package Publishing Fix for Content Hub Deployment

Resolved package publishing failure by adding missing connector information to UI definition file. Read More →

ExtraHop RevealX Connector: Function App Package Reverted to Address Customer Issues

ExtraHop connector reverted to previous function app package to resolve customer-facing deployment issues affecting data ingestion. Read More →

AWS CloudTrail Connector: Function App Crash Fix for Unsupported File Types

Fixes potential Python exception in CloudTrail ingestion function when encountering unsupported file formats, preventing data ingestion failure. Read More →

Recorded Future Identity: Prepares for Microsoft Defender Portal Migration by Deprecating Legacy Incident Creation

Recorded Future Identity solution deprecates Logic Apps-based incident creation and introduces Analytic Rules for Microsoft Defender Portal compatibility. Read More →

SAP ETD Cloud: User Account Correlation Now Available After Data Collection Gap

SAP ETD alerts now surface user account names and email addresses for incident correlation, filling a critical entity mapping gap that prevented effective identity-based investigations. Read More →

PowerShell Tool Simplifies CLv1 Table Migration Assessment Before September 2026 Deadline

New PowerShell script automates discovery of classic custom log tables and dependency impact assessment for the mandatory HTTP Data Collector API migration. Read More →

Microsoft Sentinel Training Lab: Federation and Split Transformation Capabilities Expanded

Two advanced data ingestion exercises added to training lab covering ADLS Gen2 federation and tier-based transformation routing. Read More →

Dynatrace Solution: DCR Migration Introduces v2 Connectors for All Data Sources

All Dynatrace connectors migrated to DCR-based CCF architecture with dual-version parser support for seamless transitions. Read More →

AWS S3 and CEF Connectors: Security Alert Remediation Fixes Error Handling Gaps

Python connector security vulnerabilities patched with improved error handling and null check additions. Read More →

Upwind Solution: Publisher ID Update for Content Hub Validation

Updated publisher ID in Upwind solution metadata to comply with Content Hub deployment requirements. Read More →

Proofpoint POD Connector: Critical Time Parameter Fix to Prevent Data Gaps

Proofpoint POD connector updated to include sinceTime parameter configuration, addressing potential data collection gaps during initial ingestion windows. Read More →

Microsoft Sentinel Logstash Plugin: Documentation Update Reveals Major Architecture Changes

Documentation updated for Logstash output plugin to reflect version 2.1.0 with Ruby-to-Java refactor, managed identity support, and closed-source transition. Read More →

Recorded Future Sandbox: Enhanced Region Support and Improved Threat Intelligence Structure

Recorded Future adds sandbox region configuration parameter and moves threat intelligence evidence details to comply with STIX standard structure. Read More →