QRadar Migration Tool: Summary Row and Delimiter Changes Affect CSV Output Format

The QRadar collector script (v0.4.1) appends a sentinel summary row of all active Log Source Types to the exported rules CSV and switches bracket-list formatting from comma to pipe separators, breaking any downstream parsers expecting the previous format. Read More →

Agent 365 Solution v3.1.2: Microsoft Agent Identities Connector Version Refresh

Bumps the Microsoft Agent Identities (EntraNHIAssets) data connector to version 1.0.1 so Content Hub correctly detects and applies the latest connector configuration on solution update. Read More →

New ASIM NetworkSession Parser for Cisco FTD Extends Network Visibility via AMA Connector

Cisco Firepower Threat Defense (FTD) logs ingested via the Cisco ASA/FTD AMA connector can now be normalised into the ASIM NetworkSession schema, enabling source-agnostic detections and hunting queries to run against FTD firewall and IDS events. Read More →

New ASIM Authentication Parser for Cisco Firepower Threat Defense Closes Syslog Auth Visibility Gap

A new ASIM Authentication parser for Cisco FTD normalises SSH login success and failure events from Syslog into the imAuthentication/ASimAuthentication schema, enabling source-agnostic detection coverage for Cisco firewall authentication activity. Read More →

ASIM Schema Docs Pruned -- Canonical Definitions Moved to Microsoft Learn

Nine ASIM schema YAML files and a parsers list have been removed from the repo as the canonical schema definitions are now hosted on Microsoft Learn, with two new schemas (Agent Event and Asset Entity) documented in the README. Read More →

Trend Micro Cloud App Security: Offer ID Alignment for Marketplace Publishing

Solution metadata offer ID updated to match the Azure Marketplace listing — no detection logic or connector changes. Read More →

Darktrace CCF Connector: Setup Guide Link Updated to Customer Portal

Version 3.1.1 fixes a broken documentation link in the connector UI, replacing the prior URL with the Darktrace customer portal guides page (https://customerportal.darktrace.com/guides) after a manual validation failure. Read More →

Semperis Lightning Connector: TLS Certificate Verification Restored Across All API Calls

The Semperis Lightning data connector was making all outbound API requests with TLS verification disabled (verify=False), exposing token acquisition and all data collection calls to man-in-the-middle attacks; this fix re-enables certificate validation across seven affected modules. Read More →

Google Workspace Reports: Google Meet Activity Logs Restored After Polling Window Gap

A missing queryWindowDelayInMin setting caused Google Meet audit events to be silently dropped by the CCF connector - adding a 30-minute delay restores ingestion of events that arrive late from Google API. Read More →

Fortinet FortiNDR Cloud Connector: Migration from Deprecated HTTP Data Collector API to Log Ingestion API with Managed Identity

The Fortinet FortiNDR Cloud Function App connector has been migrated from the deprecated HTTP Data Collector API (using client secret credentials) to the Log Ingestion API using Managed Identity - deployments running the previous version were heading toward a complete ingestion failure as the old API reaches end-of-life. Read More →

Cofense Intelligence Connector: SSRF and Credential Leakage Vulnerabilities Patched in DownloadThreatReports Function

Critical security hardening of the Cofense Intelligence Azure Function eliminates a Server-Side Request Forgery (SSRF) vector and credential leakage risk that allowed callers to redirect authenticated requests to arbitrary or internal hosts. Read More →

Microsoft Entra ID Assets Connector: EntraEligibleMembers Table Added (Preview)

The Microsoft Entra ID Assets connector gains a new EntraEligibleMembers table checkbox in the portal, expanding Privileged Identity Management (PIM) visibility for eligible role assignment tracking. Read More →

Hybrid Attack Solution: Packaging Fix for Missing Workbook Content ID and Version

Corrects missing content ID and version fields in the Hybrid Attack — Cloud & Identity solution packaging template to resolve a validation failure preventing Content Hub deployment. Read More →

New Workbook: Hybrid Attack Kill-Chain Hunting Across Cloud and On-Prem Identity

A new behavior-led hunting workbook registers in Microsoft Sentinel covering end-to-end hybrid identity attack scenarios across 7 MITRE ATT&CK phases, correlating signals from Entra ID, Azure, on-prem AD, and Defender XDR. Read More →

New Solution: Hybrid Attack Chain Hunting Across On-Premises, Cloud, and Kubernetes

A new Microsoft Sentinel Solution ships 55+ multi-stage hunting queries designed to detect attacker pivots across on-premises identity, Azure control plane, Kubernetes, and Microsoft Entra ID – covering full kill chains that individual, single-source detections routinely miss. Read More →

Salesforce Service Cloud ASIM Authentication Parser: Extended to Cover CCF V2/V3 Connector Tables

The ASIM Authentication parser for Salesforce Service Cloud now normalises logs from the V2 and V3 CCF connector tables – environments using the updated codeless connectors were previously producing zero normalised authentication events. Read More →

Holm Security VMP: New CCF Connector Ingests Network and Web Asset Inventory into Sentinel

A new CCF-based Data Connector for the Holm Security Vulnerability Management Platform adds direct ingestion of network and web asset inventory – including IP, hostname, OS, severity, and vulnerability counts – into two custom Log Analytics tables, enabling asset-aware threat hunting and vulnerability correlation in Microsoft Sentinel. Read More →

Cisco ISE ASIM Auth Parser: Regex Fix Restores EventOriginalType Extraction Across Log Format Variants

A broken regex in both the ASimAuthenticationCiscoISE and vimAuthenticationCiscoISE parsers caused EventOriginalType to return null for Cisco ISE syslog messages that include extended timestamp/sequence prefixes, silently dropping event classification for those log variants. Read More →

Cybersixgill Actionable Alerts: Packaging Fix for Channel and Step ID Variables (P0)

P0-labeled packaging-only update to the Cybersixgill Actionable Alerts solution that extracts hardcoded channel and step IDs into template variables in mainTemplate.json – no YAML content or detection logic changes. Read More →

New Solution: Vaikora for O365 Brings CTASD-Powered Phishing Quarantine Telemetry into Microsoft Sentinel

A brand-new Sentinel solution for Vaikora for O365 (by Data443) adds three Analytic Rules over the VaikoraO365_Quarantine_CL custom table – covering high-confidence phishing/suspected quarantine events, abnormal quarantine volume spikes, and engine-offline detection – plus an incident-response Playbook and a quarantine dashboard Workbook. Read More →