Checkmarx SAST Ingestion Playbook: Static Application Security Testing Integration

New playbook for ingesting Checkmarx SAST scan findings into Microsoft Sentinel via DCR/DCE for application vulnerability tracking. Read More →

D3 Smart SOAR Connector: Fixing Critical Duplicate Incident Ingestion

Fixes broken paging mechanism that was causing duplicate D3 Smart SOAR incidents to be ingested into Microsoft Sentinel. Read More →

ASIM Schema Standardization: Removing Unused User Role Fields Across Multiple Schemas

Cleanup of unused Actor/Target user role fields and alignment of empty parsers improves schema consistency but does not affect active detection capabilities. Read More →

Semperis Lightning: New Active Directory Security Monitoring Platform Added to Content Hub

Semperis Lightning connector brings comprehensive Active Directory tier-0 attack path monitoring and privileged access visibility to Microsoft Sentinel via real-time API ingestion. Read More →

A365 Observability Connector: New AI Agent Telemetry Visibility in Microsoft Sentinel

New data connector for AI agent behavior monitoring brings telemetry from A365, AI Foundry, and Copilot into Microsoft Sentinel for security investigations. Read More →

AWS EKS Connector: Critical Data Ingestion Fix for Missing Table Configuration

CCF connector was unable to ingest any data due to empty destinationTable field preventing log routing to AWSEKSLogs_CL. Read More →

Threat Intelligence: Duo Security IP Detection Updated for ASIM Schema Compliance

IPEntity_DuoSecurity detection migrated from legacy DuoSecurityAuthentication_CL table to normalized CiscoDuo ASIM schema. Read More →

IPinfo Data Connectors: Critical Function App Runtime Fix for Production Deployment

Azure Functions were completely non-functional for marketplace deployments due to incorrect zip folder structure preventing runtime from locating host.json. Read More →

Alibaba Cloud Networking: New CCF Connector Brings VPC Flow, WAF, and API Gateway Visibility

Microsoft Sentinel gains visibility into Alibaba Cloud network infrastructure with a new CCF connector supporting VPC Flow Logs, WAF events, and API Gateway data ingestion via Simple Log Service. Read More →

CrowdStrike Connector: Enhanced Rate Limiting and GA Release

CrowdStrike API Data Connector moves to General Availability with advanced rate limit handling for Alerts and Detections data ingestion. Read More →

ASIM Schema Cleanup: Removing Unused User Fields from Test Configuration

Maintenance cleanup removes unused optional user fields from ASIM test configuration with no impact on parser or detection functionality. Read More →

Zoom Reports: CCF Connector Replaces Azure Function for Report Ingestion

ZoomReports solution migrates from Azure Function to CCF architecture, providing streamlined OAuth-based ingestion for six report types covering usage, telephony, and audit activities. Read More →

OpenAI Solution: New Data Source for AI Security Monitoring

New Microsoft Sentinel solution introduces CCF connector for OpenAI audit logs and chat completions, enabling AI governance and threat detection. Read More →

AWS EKS Connector: Package Template Fix Restores Deployment Capability

AWS EKS solution packaging error fixed — deployments were failing due to malformed ARM template. Read More →

Cisco Umbrella Connector: Critical CSV Ingestion Failure Fixed

Resolves complete ingestion stall caused by oversized CSV fields and null character parsing errors. Read More →

Logstash Plugin: Configurable Retransmission Delay Reduces HTTP 429 Throttling Impact

Microsoft Sentinel Logstash plugin v1.2.1 adds configurable retry delay parameter to mitigate data loss during throttling scenarios. Read More →

Zero Networks: Enhanced Audit Parser and CCF Connectors Expand Microsegmentation Visibility

Zero Networks parser update adds 182 new audit types plus dual CCF connectors for comprehensive microsegmentation telemetry. Read More →

XBOW Autonomous Security Platform: Function App Connector and Detection Rules

New XBOW solution provides asset inventory, vulnerability finding correlation, and automated security assessment visibility through Function App ingestion and four analytic rules. Read More →

Cyren Threat Intelligence: Flexible Deployment with Optional JWT Tokens

Cyren threat intelligence connectors now support conditional deployment — customers can install either IP reputation or malware URL feeds individually based on their subscription. Read More →

TacitRed-CrowdStrike IOC Playbook: Partner Certification Header Compliance

TacitRed-CrowdStrike playbook updated to include required User-Agent header for CrowdStrike Technology Partner certification compliance. Read More →