TacitRed-SentinelOne v3.0.2: Critical Fix for Broken SentinelOne Connection

Fixes a critical deployment bug present since v1.0.0 where hardcoded placeholder URL caused complete playbook failure for all Content Hub installations. Read More →

Gigamon AMX Connector: Migration to CCF Push Restores Network Visibility After Deprecation

Gigamon connector migrated from deprecated Log Analytics method to CCF push architecture, preventing complete loss of network traffic and threat visibility. Read More →

Cisco Duo Connector: Function Timeout Mitigation and Dependency Security Updates

Fixes timeout-induced ingestion failures in offline enrollment log processing and updates duo-client library for security maintenance. Read More →

Google Kubernetes Engine Connector: Documentation Update Links to Official Microsoft Learn

Google Kubernetes Engine connector documentation updated to reference official Microsoft Learn guides instead of personal repositories. Read More →

ASIM Registry Event: Added Mandatory Fields for Microsoft 365 Defender Parser Compliance

Updated ASIM Registry Event parser for Microsoft 365 Defender to include mandatory EventSchema and EventResult fields per schema compliance requirements. Read More →

Cyren Threat Intelligence: Partner Center Compliance Fix and Version Alignment

Compliance update removes credential scanner violations from securestring parameters and aligns all content versions to 3.0.3. Read More →

IONIX: Migration to CCF RestApiPoller with Enhanced Data Deduplication

Major migration from HTTP Data Collector API to CCF RestApiPoller enabling automatic polling with query-time deduplication for IONIX attack surface management data. Read More →

Logstash Connector: Extended Version Support for Newer Logstash Releases

Documentation update adds support for Logstash versions 8.19.2, 9.0.8, 9.1.10, and 9.2.4-9.2.5. Read More →

Global Secure Access: Critical Fix for Abnormal Deny Rate Detection Baseline Computation

Critical fix aligns queryPeriod with 5-day learning window, restoring proper baseline computation for abnormal deny rate detection. Read More →

IPinfo: Multi-Workspace Support and Function App Deployment Reliability Improvements

Comprehensive update to 17 IPinfo connectors enhancing deployment reliability with runtime pinning, dependency fixes, and multi-workspace DCR support. Read More →

Lookout Connector: Critical DCR Transform Fix Restores Mobile Threat Visibility

Critical fix resolves undefined symbol error that prevented Lookout connector creation, restoring mobile threat detection capability. Read More →

Trend Micro Vision One: Azure Storage Account TLS Security Hardening

Critical security hardening update enforces minimum TLS 1.2 for Azure storage accounts in Function App deployment template. Read More →

DataBahn Platform: New CCF Connector for Real-Time Security Telemetry Ingestion

New CCF push connector enables direct ingestion of DataBahn audit logs, alerts, and device inventory into Microsoft Sentinel. Read More →

Azure Activity: Hunting Query Documentation Enhancement for Custom Script Extensions

Minor documentation improvement clarifying protected settings visibility in Custom Script Extension hunting query. Read More →

Solutions Analyzer Tools: Kusto Upload, CCF Legacy Support, and Parser Analysis Enhancements

Major tooling update adds Kusto integration, improves CCF connector classification, and fixes ASIM parser documentation generation. Read More →

ASIM FileEvent Parser: New AWS CloudTrail S3 Support Added

New FileEvent parser enables normalized S3 object activity monitoring from AWS CloudTrail logs across bucket operations and object lifecycle events. Read More →

New CCF Template: Azure Storage Blob Data Connector

New Codeless Connector Framework template enables ingestion from Azure Storage blob containers via event-driven data flows. Read More →

Solution Creation Tools: API Version Update for Saved Searches

Updated savedSearches API version from 2022-10-01 to 2025-07-01 in solution metadata generation tool. Read More →

Cyren Threat Intelligence: Critical Fix for 1,535:1 Duplicate Data Ingestion

Configuration updates eliminate massive duplicate indicator ingestion caused by small page sizes and frequent polling intervals. Read More →

Threat Intelligence: URL IOC Detection Added for Web Session Monitoring

New Analytic Rule enables detection of malicious URLs from threat feeds in web traffic, closing coverage gap for URL-based indicators. Read More →