Check Point Cyberint: Bi-Directional Alert Sync and Critical Data Ingestion Fix

Adds comprehensive bi-directional sync playbooks and fixes critical ref_id column type bug that caused silent data loss in alert ingestion. Read More →

Contrast ADR: CCF Connector Deployment Unlocks Application Attack Visibility

Contrast ADR adds CCF ingestion support with standardized table schemas for production-ready Application Detection and Response monitoring. Read More →

Four Legacy Azure Function Connectors Marked for Deprecation - Migration to CCF Required

Microsoft has deprecated Azure Function-based connectors for Okta SSO, SentinelOne, Sophos Endpoint Protection, and VMware Carbon Black Cloud in favor of CCF alternatives. Read More →

Function App Connectors Deprecated: Four Solutions Migrate to CCF Framework

Legacy Azure Function connectors for Atlassian Jira, Auth0, Box, and CrowdStrike are now deprecated as solutions transition to the modern CCF architecture. Read More →

Microsoft Entra ID Conditional Access Bypass Detection: False Positive Reduction via Benign Status Code Watchlist

New watchlist filters out 7 known-benign status codes from Conditional Access bypass detection to reduce false positives from legitimate MFA prompts and session expiration events. Read More →

meshStack Solution: Publisher ID Alignment for Content Hub Certification

meshStack solution updated publisher ID to match Partner Center configuration, ensuring compliance with Microsoft certification requirements. Read More →

BeyondTrust PM Cloud: Critical Data Ingestion Fix Restores Partial Event Visibility

A batching bug in the BeyondTrust PM Cloud connector was causing 413 errors and incomplete endpoint security event ingestion when payload sizes exceeded Log Analytics limits. Read More →

Azure Security Benchmark Workbook: Parameter Filtering Logic Fixed

KQL queries in the Azure Security Benchmark workbook now properly filter by selected compliance domains. Read More →

Tanium CCF Data Connector: Enhanced Endpoint Visibility with DCR-Based Ingestion

New CCF push connector for Tanium enables endpoint compliance, threat response, and patch data ingestion via DCR streams. Read More →

Microsoft Entra ID: Account Creation/Deletion Detection Enhanced Against Timing Evasion

Critical improvements to AccountCreatedandDeletedinShortTimeframe rule extend detection window to 7 days and use immutable UserID correlation to prevent timing-based evasion techniques. Read More →

Vectra XDR Connector: Critical Exception Handling Bug Fixed

Exception handling bug in Vectra XDR data collector prevented proper error propagation during ingestion failures. Read More →

ASIM Authentication: New Parser for Cisco ISE Administrator Login Events

Added ASIM Authentication parser for Cisco ISE administrator authentication events, expanding centralized network device visibility. Read More →

Imperva Cloud WAF: Critical Fix for JSON Log Ingestion Failure

Imperva CCF connector now properly ingests WAF logs containing embedded JSON, preventing data loss during log processing. Read More →

Fortinet FortiGate ASIM Authentication Parsers: Schema Version Metadata Correction

Updates schema version metadata from 0.1.3 to 0.1.4 in FortiGate authentication parsers with no functional changes. Read More →

Microsoft Sentinel Training Lab: Comprehensive Hands-On Security Operations Environment Now Available

New deployment-ready training lab delivers 14 guided exercises with pre-recorded telemetry, detection rules, and automation workflows for practical Microsoft Sentinel skill development. Read More →

Threat Intelligence Domain-to-SecurityAlert Rule: Fixes Recursive Alert Loop with Self-Exclusion Filter

Threat Intelligence domain mapping rule updated to prevent infinite alert loops by excluding its own alerts from the source data. Read More →

Azure Security Benchmark: Updated Labels to Microsoft Cloud Security Benchmark

Replaced “Azure Security Benchmark” references with “Microsoft cloud security benchmark” across workbook labels and KQL queries. Read More →

Blacklens Logic App: Fixed Invalid secureData Configuration Breaking Deployment

Resolved deployment failure caused by invalid secureData configuration in Logic App Compose action. Read More →

Tenable VM: Vulnerability Data Checkpoint Field Update

Changed vulnerability export checkpoint field from last_found to indexed_at for customer enhancement. Read More →

ExtraHop RevealX: Azure Monitor Logs Ingestion API Replaces Legacy HTTP Data Collector

Added Log Ingestion API support with OAuth 2.0 authentication — modernizes data ingestion from legacy HTTP Data Collector API. Read More →