SAP ETD Cloud: User Account Correlation Now Available After Data Collection Gap

SAP ETD alerts now surface user account names and email addresses for incident correlation, filling a critical entity mapping gap that prevented effective identity-based investigations. Read More →

PowerShell Tool Simplifies CLv1 Table Migration Assessment Before September 2026 Deadline

New PowerShell script automates discovery of classic custom log tables and dependency impact assessment for the mandatory HTTP Data Collector API migration. Read More →

Microsoft Sentinel Training Lab: Federation and Split Transformation Capabilities Expanded

Two advanced data ingestion exercises added to training lab covering ADLS Gen2 federation and tier-based transformation routing. Read More →

Dynatrace Solution: DCR Migration Introduces v2 Connectors for All Data Sources

All Dynatrace connectors migrated to DCR-based CCF architecture with dual-version parser support for seamless transitions. Read More →

AWS S3 and CEF Connectors: Security Alert Remediation Fixes Error Handling Gaps

Python connector security vulnerabilities patched with improved error handling and null check additions. Read More →

Upwind Solution: Publisher ID Update for Content Hub Validation

Updated publisher ID in Upwind solution metadata to comply with Content Hub deployment requirements. Read More →

Proofpoint POD Connector: Critical Time Parameter Fix to Prevent Data Gaps

Proofpoint POD connector updated to include sinceTime parameter configuration, addressing potential data collection gaps during initial ingestion windows. Read More →

Microsoft Sentinel Logstash Plugin: Documentation Update Reveals Major Architecture Changes

Documentation updated for Logstash output plugin to reflect version 2.1.0 with Ruby-to-Java refactor, managed identity support, and closed-source transition. Read More →

Recorded Future Sandbox: Enhanced Region Support and Improved Threat Intelligence Structure

Recorded Future adds sandbox region configuration parameter and moves threat intelligence evidence details to comply with STIX standard structure. Read More →

Sentinel Training Lab: Enhanced Detection Rules and Cost Management Features

Comprehensive update to the Sentinel Training Lab with improved detection entity correlation, new cost management capabilities, and standardized naming conventions. Read More →

ASIM Process Event Parsers: Parameter Standardization Fixes Filtering Logic Inconsistencies

ASIM Process Event parser parameter names corrected to match documentation, fixing filtering logic discrepancies that could affect query performance and parser interoperability. Read More →

Censys Solution: New Related Infrastructure Playbook Enhances Threat Pivot Capabilities

Censys solution adds playbook and workbook for automated infrastructure pivoting and pivot analysis visualization using the Pivot Analysis API. Read More →

Global Secure Access: Threat Intelligence Detection Restored After URL Regex Failure

Fixed broken URL threat intelligence detection and expanded workbook coverage for new Entra traffic type. Read More →

QRadar Migration Tool: Streamlining SIEM Detection Rule Migration to Microsoft Sentinel

New Python-based data collector extracts custom QRadar detection rules and building blocks for migration-ready analysis and conversion to Microsoft Sentinel. Read More →

Blacklens Connector: Logic App Deployment Failure Fixed

Removes unsupported secureData configuration preventing Blacklens ASM connector deployments from completing successfully. Read More →

SAP: Agentless Integration Package v1.1.10 with Security Enhancements

SAP agentless solution updated to version 1.1.10 with security and usability improvements, plus official release status designation. Read More →

SAP: New Agentless User Blocking Playbook for Defender XDR Integration

New SAP playbook enables automated user blocking via Teams adaptive cards with enhanced support for complex multi-alert incidents from Microsoft Defender XDR. Read More →

D3 Smart SOAR: New Detection for High/Critical Severity Incidents

D3 Smart SOAR solution now includes an Analytic Rule to automatically detect and escalate High or Critical severity incidents from SOAR platform data. Read More →

Cisco ISE ASIM Parser: Correcting IP Address Field Mappings

Cisco ISE Administrator authentication parser fixes swap incorrect SrcIpAddr and TargetIpAddr mappings that broke network forensics queries. Read More →

VMware vCenter ASIM Parser: Fixing Field Mappings After ASIM Schema Updates

Critical fixes to VMware vCenter authentication parser resolve incorrect field mappings that broke queries referencing User and DvcId fields. Read More →