Corelight Network Monitoring: Six New Aggregation Parsers for Enhanced Analytics
Added six new aggregation parsers for Corelight sensor data including DNS, HTTP, files, connections, SSL, and weird events with improved CIM mapping. Read More →
Added six new aggregation parsers for Corelight sensor data including DNS, HTTP, files, connections, SSL, and weird events with improved CIM mapping. Read More →
Minor documentation and configuration fixes for AbuseIPDB playbooks including corrected image source and typo corrections. Read More →
GDPR compliance workbook now monitors security alerts across Azure, AWS, GCP, and blob storage assets, not just traditional servers. Read More →
P0-labeled update improves URL entity mapping in Cloudflare detection rules alongside extensive repository maintenance and validation improvements. Read More →
New ASIM normalisation parsers added for six Azure Firewall log tables, expanding detection coverage for network sessions, DNS queries, and web traffic analysis. Read More →
Updates Cisco Umbrella Function App connectors to support log schema version 14 with enhanced workspace key documentation. Read More →
Reverts detection rule logic changes due to GitHub issue reporting incorrect filtering logic causing operational problems. Read More →
Solutions Analyzer tool enhanced to generate markdown documentation files for all 1000+ connectors in addition to CSV output. Read More →
ZeroFox CCF connector receives missing KQL query fixes alongside packaging updates across 8+ solutions. Read More →
Updated threat hunting rules add MITRE ATT&CK mappings and fix parser function calls for improved threat detection coverage. Read More →
Fixes SrcHostname resolution logic and IpAddr aliases in Microsoft Windows Event and SSH authentication parsers. Read More →
Added Linux-compatible version of Sentinel Transition Helper script using Azure CLI for cross-platform SOC environment analysis. Read More →
Deleted legacy O365 DataCSharp Teams connector and RDAPQuery tool due to vulnerable .NET dependencies and security risks. Read More →
Released Solutions Analyzer tool for automated discovery and mapping of connector-to-table relationships across Sentinel solutions with CSV reporting. Read More →
Authomize connector dependency updated to address credential leakage vulnerability in requests library. Read More →
Added support for Cisco Secure log formats v13-v14, exposing AI model tracking and event correlation fields for improved threat context. Read More →
Updated Microsoft Defender for Office 365 workbook to version 3 with new visuals and improved insights based on user feedback. Read More →
Stream name mismatch between DCR and connector config prevented ZeroFox threat alerts from reaching Sentinel workspaces. Read More →
Marketplace certification fixes for Open Systems solution — updated SVG logo path and corrected contact email address for Azure Marketplace deployment. Read More →
Critical security update patches CVE-2024-47081 netrc credential leak vulnerability in Python requests library. Read More →