Threat Intelligence Workbook: Query Logic Fix for Indicator Visualization
Workbook query issue resolved in Threat Intelligence solution — improves analyst dashboard reliability. Read More →
Workbook query issue resolved in Threat Intelligence solution — improves analyst dashboard reliability. Read More →
Two new analytic rules detect domain and user data breaches on the dark web, with enhanced ingestion logic for NordPass Data Breach Scanner integration. Read More →
New Veeam solution added providing comprehensive security monitoring for backup infrastructure with malware scanning, compliance analysis, and threat detection capabilities. Read More →
Fixed connector documentation by removing non-functional links to workspace key documentation. Read More →
All TI data connector templates now monitor the new ThreatIntelObjects table, expanding threat intelligence visibility beyond traditional indicators. Read More →
Added suppression comments for CodeQL security alerts in deprecated connectors and backward compatibility modules. Read More →
GCP NAT solution packaging updated to version 3.0.1 with minor metadata revisions. Read More →
Three Google Cloud Platform CCF connectors graduate from Preview to GA status, indicating production readiness for enterprise deployment. Read More →
Workbook update adds graphical views to complement table displays and fixes missing data source statistics headers. Read More →
Threat Intelligence imDns_IPEntity_DnsEvents rule updated to fix alert description field mapping from non-existent Type to ThreatType, restoring threat classification in DNS alerts. Read More →
Azure Firewall Abnormal Port to Protocol rule updated to fix brittle time range handling that caused duplicate alerts and failed detection when runtime was modified. Read More →
Microsoft Entra ID Conditional Access detection rules updated to fix lookbackDuration format preventing rule deployment in Microsoft Sentinel workspaces. Read More →
Threat Intelligence DomainEntity_imWebSession rule updated to fix alert description field mapping, replacing non-existent Type field with ThreatType for proper alert context. Read More →
ZPAEvent parser updated to version 1.0.3 with additional fields for SessionID, IPProtocol, and ClientCountryCode, improving zero-trust network monitoring capabilities. Read More →
GitHub webhook connector restored from deprecated status, indicating renewed support for GitHub security event ingestion via webhooks. Read More →
Cisco Umbrella elastic premium connector updated to match standard connector data types and table structures for consistent log processing and queries. Read More →
ProofPoint TAP CCF connector updated from deprecated sinceTime to interval-based polling, addressing incomplete data retrieval that affected threat visibility. Read More →