Netskope Security Cloud Joins ASIM AlertEvent Schema — Threats Now Normalised from NetskopeAlerts_CL

A new ASIM AlertEvent parser for Netskope Security Cloud normalises DLP, malware, C2, IPS, compromised credential, UBA, and policy alerts from the NetskopeAlerts_CL table into the standard AlertEvent schema, enabling source-agnostic detections and hunting across Netskope data. Read More →

New BlueVoyant CCF Connector Brings Anthropic Claude Compliance Activity into Microsoft Sentinel

BlueVoyant new Solution adds a CCF-based Data Connector that polls the Anthropic Claude Compliance API every 10 minutes and lands compliance events in the custom table BV_ClaudeCompliance_ComplianceActivities_CL, opening a new AI platform audit surface in Sentinel. Read More →

CyberArk Audit Connector: Function App Runtime Updated to Python 3.12

The CyberArk Audit Function App connector has been updated from Python 3.10 (EOL) to Python 3.12, replacing all bundled dependency packages and deployment templates accordingly. Read More →

MuleSoft CloudHub Logs Connector: Empty Instruction Block Removed to Restore Marketplace Publishing

The MuleSoft CloudHub Logs CCF connector definition had an empty instructions array blocking marketplace validation—this fix removes it, restoring publishability with no change to ingestion logic or detection coverage. Read More →

New eDCRule Solution: 10 Entra ID and Azure Subscription Analytic Rules for Privilege Escalation and Identity Abuse Detection

A new community solution adds 10 scheduled Analytic Rules (plus Chinese-localized counterparts) targeting Microsoft Entra ID privilege escalation, OAuth token abuse, federation trust tampering, and Azure VM Run Command abuse correlated with UEBA signals. Read More →

BloodHound Enterprise Workbooks: Parameter Query Failures Fixed with Explicit 30-Day Time Context

All six BloodHound Enterprise workbooks had parameter dropdown queries silently failing due to missing time context; this fix adds an explicit 30-day timeContext (durationMs: 2592000000) to each parameter, restoring operator visibility into attack paths and posture data. Read More →

New AWS Config CCF Connector: Resource Configuration Visibility via Custom API Pull

A new community CCF connector ingests AWS Config configuration item notifications into Microsoft Sentinel via a self-hosted AWS API Gateway/Lambda/DynamoDB backend, populating the AWSConfig_CL table for cloud resource configuration monitoring. Read More →

ASIM Parser CI Workflows Fixed: File-Not-Found Errors Were Silently Skipping All Parser Tests

The ASIM parser schema and data ingestion test workflows were failing to read parser YAML and sample data files at runtime due to broken URL-based file access; this fix switches to local filesystem reads, restoring test coverage for all modified ASIM parsers. Read More →

SentinelOne CCF Connector Upgraded to Multi-Instance for MSSP Deployments

The SentinelOne CCF connector now supports multiple simultaneous instances via a grid/context-pane UX, enabling MSSPs to ingest from multiple SentinelOne tenants without deploying duplicate solutions. Read More →

CCF Solution Packaging Tool Gains Five New Auth Type Handlers

The createCCPConnector.ps1 solution packaging script now supports CiscoDuo, CommVault, VisaXpayToken, BarracudaWAF, and EdgeGrid auth types, unblocking connector packaging for products using these authentication schemes. Read More →

Silverfort Connector Docs Updated: MMA Reference Replaced with AMA, Python Check Command Fixed

The Silverfort AMA connector setup instructions now correctly reference Azure Monitoring Agent instead of the legacy Microsoft Monitoring Agent, and the Python version check command has been corrected. Read More →

Zimperium MTD Gains Incident Log Ingestion via Two New CCF Tables

The Zimperium Mobile Threat Defense CCF connector now ingests mobile incident data into two new custom tables, extending threat visibility beyond raw threat events to correlated incident and mitigation workflows. Read More →

Zoom Reports Function App Connector Officially Deprecated

The legacy Zoom Reports Azure Function-based connector has been formally deprecated; customers still using it should migrate to the CCF-based replacement. Read More →

ZeroFox Threat Intelligence: Marketplace Packaging Fix Restores Customer Access

Critical solution ID mismatch prevented customers from installing ZeroFox Threat Intelligence connector from marketplace. Read More →

Premium MDTI Connector Removed from Threat Intelligence Solution During MDTI Convergence

Premium Microsoft Defender Threat Intelligence connector no longer available in Threat Intelligence (NEW) solution v3.0.19 as part of MDTI convergence effort. Read More →

StealthTalk Solution Publisher ID Corrected for Partner Center Compliance

Fixed StealthTalk solution publisherId metadata to match Partner Center registration and resolve certification check. Read More →

QualysVM Connector Enhanced with QDS Score Parameter

Added QDS score parameter to QualysVM CCF connector, enabling users to include Qualys Detection Scores in vulnerability data collection. Read More →

Palo Alto Cortex XDR CCP Solution Repackaged to Version 3.0.4

Repackaged Palo Alto Cortex XDR CCP solution to address Marketplace UI discrepancy. Read More →

Darktrace CCF Migration: New ActiveAI Security Platform Connector Replaces Legacy REST API

New CCF-based Darktrace connector with enhanced visibility across six data streams and modernized detection logic. Read More →

Palo Alto XDR ASIM Parser: Normalizing Cortex XDR Alert Data for Cross-Platform Detection

New ASIM AlertEvent parser brings Palo Alto Cortex XDR alert normalization to Microsoft Sentinel via CCF connector. Read More →