<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>AWS on sentinelchangelog.net</title><link>http://sentinelchangelog.net/tags/aws/</link><description>Recent content in AWS on sentinelchangelog.net</description><generator>Hugo -- 0.157.0</generator><language>en</language><lastBuildDate>Thu, 28 May 2026 12:40:08 +0000</lastBuildDate><atom:link href="http://sentinelchangelog.net/tags/aws/index.xml" rel="self" type="application/rss+xml"/><item><title>AWS Security Hub Compliance Workbook: Comprehensive Security Posture Visualization Now Available</title><link>http://sentinelchangelog.net/posts/2026-05-28-pr-13870/</link><pubDate>Thu, 28 May 2026 12:40:08 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-28-pr-13870/</guid><description>New AWS Security Hub compliance workbook provides executive dashboards and operational analytics for security findings, compliance tracking, and multi-account posture management.</description></item><item><title>AWS S3 and CrowdStrike Connectors: Non-Analytics Tier Query Support for Basic/Auxiliary Plans</title><link>http://sentinelchangelog.net/posts/2026-05-28-pr-14264/</link><pubDate>Thu, 28 May 2026 10:37:30 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-28-pr-14264/</guid><description>AWS S3 and CrowdStrike Falcon S3 Data Replicator connectors now support Usage table fallback queries for deployments using Basic/Auxiliary Log Analytics plans.</description></item><item><title>AWS Content Quality Overhaul: Standardized Detection Rules and Improved Entity Mappings</title><link>http://sentinelchangelog.net/posts/2026-05-18-pr-14101/</link><pubDate>Mon, 18 May 2026 07:30:57 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-18-pr-14101/</guid><description>Comprehensive quality improvements to 61 AWS Analytic Rules and 35 Hunting Queries with standardized naming conventions, normalized MITRE technique mappings, and updated entity field references from legacy AccountCustomEntity to UserIdentityUserName.</description></item><item><title>AWS ELB Solution Moves to General Availability</title><link>http://sentinelchangelog.net/posts/2026-04-24-pr-14127/</link><pubDate>Fri, 24 Apr 2026 08:42:53 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-04-24-pr-14127/</guid><description>AWS Elastic Load Balancer solution transitions from Public Preview to GA status, confirming production readiness for ALB/NLB access log monitoring.</description></item><item><title>AWS CloudTrail Connector: Function App Crash Fix for Unsupported File Types</title><link>http://sentinelchangelog.net/posts/2026-04-21-pr-14104/</link><pubDate>Tue, 21 Apr 2026 11:12:13 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-04-21-pr-14104/</guid><description>Fixes potential Python exception in CloudTrail ingestion function when encountering unsupported file formats, preventing data ingestion failure.</description></item><item><title>AWS S3 and CEF Connectors: Security Alert Remediation Fixes Error Handling Gaps</title><link>http://sentinelchangelog.net/posts/2026-04-20-pr-14088/</link><pubDate>Mon, 20 Apr 2026 09:51:55 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-04-20-pr-14088/</guid><description>Python connector security vulnerabilities patched with improved error handling and null check additions.</description></item><item><title>Microsoft Sentinel Training Lab: Comprehensive Hands-On Security Operations Environment Now Available</title><link>http://sentinelchangelog.net/posts/2026-04-10-pr-13848/</link><pubDate>Fri, 10 Apr 2026 15:05:24 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-04-10-pr-13848/</guid><description>New deployment-ready training lab delivers 14 guided exercises with pre-recorded telemetry, detection rules, and automation workflows for practical Microsoft Sentinel skill development.</description></item><item><title>AWS ELB Connector: Public Preview CCF Ingestion for ALB, NLB, and GLB Logs</title><link>http://sentinelchangelog.net/posts/2026-03-23-pr-13872/</link><pubDate>Mon, 23 Mar 2026 11:41:03 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-03-23-pr-13872/</guid><description>New CCF connector enables ingestion of AWS Elastic Load Balancer access and flow logs into Microsoft Sentinel for network traffic monitoring and threat detection.</description></item><item><title>AWS EKS Connector: CloudFormation Template Revert Fixes Deployment Issues</title><link>http://sentinelchangelog.net/posts/2026-03-12-pr-13812/</link><pubDate>Thu, 12 Mar 2026 21:03:03 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-03-12-pr-13812/</guid><description>AWS EKS connector CloudFormation templates reverted to resolve deployment errors affecting EKS audit log ingestion setup.</description></item><item><title>AWS Network Firewall Connector: Fixed Critical Deployment Bug Causing Duplicate Collectors</title><link>http://sentinelchangelog.net/posts/2026-03-11-pr-13589/</link><pubDate>Wed, 11 Mar 2026 21:39:27 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-03-11-pr-13589/</guid><description>Deployment bug fix prevents multiple collector creation for AWS Network Firewall multi-stream connectors.</description></item><item><title>AWS EKS Connector: New Public Preview for Kubernetes Audit Log Security Monitoring</title><link>http://sentinelchangelog.net/posts/2026-03-11-pr-13749/</link><pubDate>Wed, 11 Mar 2026 21:35:04 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-03-11-pr-13749/</guid><description>New CCF-based solution ingests Amazon Elastic Kubernetes Service audit logs via SQS for real-time cluster security monitoring.</description></item><item><title>AWS Athena Function App: Resolving Extension Bundle Compatibility and Query Result Parsing</title><link>http://sentinelchangelog.net/posts/2026-03-10-pr-13648/</link><pubDate>Tue, 10 Mar 2026 06:57:45 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-03-10-pr-13648/</guid><description>AWS Athena Function App connector updated to Azure Functions v4+ bundle and fixed Python query parsing logic that previously failed on empty result data.</description></item><item><title>ASIM FileEvent Parser: New AWS CloudTrail S3 Support Added</title><link>http://sentinelchangelog.net/posts/2026-02-20-pr-13569/</link><pubDate>Fri, 20 Feb 2026 21:46:53 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-02-20-pr-13569/</guid><description>New FileEvent parser enables normalized S3 object activity monitoring from AWS CloudTrail logs across bucket operations and object lifecycle events.</description></item><item><title>ASIM User Management: AWS CloudTrail Parser Enables IAM and Cognito Visibility</title><link>http://sentinelchangelog.net/posts/2026-02-12-pr-13503/</link><pubDate>Thu, 12 Feb 2026 17:56:32 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-02-12-pr-13503/</guid><description>New ASIM parser normalizes AWS CloudTrail user management events from IAM and Cognito services into Microsoft Sentinel.</description></item><item><title>AWS Access Logs: Security Enhancement for SQS Principal Access Control</title><link>http://sentinelchangelog.net/posts/2025-12-30-pr-13365/</link><pubDate>Tue, 30 Dec 2025 07:59:46 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-12-30-pr-13365/</guid><description>AWS S3 Server Access Logs CloudFormation template receives critical security update restricting SQS queue principal from wildcard to S3 service only.</description></item><item><title>AWS CloudTrail Connector: Fixed Script Logic and Command Syntax Errors</title><link>http://sentinelchangelog.net/posts/2025-12-10-pr-13281/</link><pubDate>Wed, 10 Dec 2025 03:31:36 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-12-10-pr-13281/</guid><description>Corrected PowerShell variable scoping and AWS CLI command syntax in CloudTrail configuration script.</description></item><item><title>AWS S3 Connector: Python Runtime Upgrade and Boto3 Compatibility Fix</title><link>http://sentinelchangelog.net/posts/2025-11-14-pr-13129/</link><pubDate>Fri, 14 Nov 2025 09:29:58 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-11-14-pr-13129/</guid><description>Function App connector updated to Python 3.11 with boto3 fix for missing CommonPrefixes handling.</description></item><item><title>AWS CloudWatch Connectors: Critical Python 3.13 Compatibility Fix</title><link>http://sentinelchangelog.net/posts/2025-11-13-pr-13104/</link><pubDate>Thu, 13 Nov 2025 03:41:19 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-11-13-pr-13104/</guid><description>Removed problematic CSV handling causing Lambda function failures on Python 3.13 runtime in CloudWatch connectors.</description></item><item><title>UEBA Essentials: Enhanced Multi-Cloud Detection with 6 New AWS, GCP &amp; Okta Hunting Queries</title><link>http://sentinelchangelog.net/posts/2025-11-12-pr-13065/</link><pubDate>Wed, 12 Nov 2025 11:17:58 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-11-12-pr-13065/</guid><description>Major update adds comprehensive multi-cloud anomaly detection capabilities across AWS, GCP, and Okta platforms with 6 new hunting queries.</description></item><item><title>AWS S3 Connector: PowerShell Version Enforcement Prevents Configuration Failures</title><link>http://sentinelchangelog.net/posts/2025-10-22-pr-12924/</link><pubDate>Wed, 22 Oct 2025 12:30:02 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-10-22-pr-12924/</guid><description>AWS S3 connector script now enforces PowerShell 7+ requirement to prevent customer deployment failures.</description></item><item><title>AWS and VMware ESXi: Three New Analytic Rules for Execution, Exfiltration, and Lateral Movement</title><link>http://sentinelchangelog.net/posts/2025-10-09-pr-12696/</link><pubDate>Thu, 09 Oct 2025 12:07:12 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-10-09-pr-12696/</guid><description>Three new Analytic Rules added across AWS CloudTrail and VMware ESXi — detecting EC2 startup script tampering (T1059), anonymous S3 object exfiltration (T1530), and SSH enablement on ESXi hosts (T1021).</description></item><item><title>AWS S3 Server Access Logs Connector: GA Promotion Removes Preview Status</title><link>http://sentinelchangelog.net/posts/2025-10-07-pr-12918/</link><pubDate>Tue, 07 Oct 2025 06:30:45 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-10-07-pr-12918/</guid><description>AWS S3 Server Access Logs connector promoted from Preview to General Availability with version 3.0.1.</description></item></channel></rss>