<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Hunting Queries on sentinelchangelog.net</title><link>http://sentinelchangelog.net/tags/hunting-queries/</link><description>Recent content in Hunting Queries on sentinelchangelog.net</description><generator>Hugo -- 0.157.0</generator><language>en</language><lastBuildDate>Mon, 01 Jun 2026 04:39:34 +0000</lastBuildDate><atom:link href="http://sentinelchangelog.net/tags/hunting-queries/index.xml" rel="self" type="application/rss+xml"/><item><title>Slack Audit Solution: Enhanced Detection Logic and Alert Enrichment</title><link>http://sentinelchangelog.net/posts/2026-06-01-pr-14245/</link><pubDate>Mon, 01 Jun 2026 04:39:34 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-06-01-pr-14245/</guid><description>Slack Audit analytic rules, hunting queries, and workbook upgraded with improved KQL logic, custom alert details, and enhanced entity mappings for stronger workspace monitoring.</description></item><item><title>Entra ID Post-Credential Activity Detection: Service Principal Staging and Privileged Role Escalation</title><link>http://sentinelchangelog.net/posts/2026-05-29-pr-14299/</link><pubDate>Fri, 29 May 2026 10:56:48 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-29-pr-14299/</guid><description>Three new hunting queries target Midnight Blizzard-style persistence patterns — service principal credential staging, privileged role assignments to new accounts, and Temporary Access Pass abuse.</description></item><item><title>Gentlemen Ransomware Campaign: New Hunting Queries for EtherRAT/TukTuk IOCs and Web3 C2 Infrastructure</title><link>http://sentinelchangelog.net/posts/2026-05-29-pr-14338/</link><pubDate>Fri, 29 May 2026 08:24:12 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-29-pr-14338/</guid><description>Two hunting queries added targeting Gentlemen ransomware campaign artifacts including payload hashes and decentralized Web3/SaaS C2 infrastructure used by EtherRAT and TukTuk malware.</description></item><item><title>LockBit Hunting Query: ActiveMQ Exploit IoC Detection Added</title><link>http://sentinelchangelog.net/posts/2026-05-29-pr-14350/</link><pubDate>Fri, 29 May 2026 05:32:22 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-29-pr-14350/</guid><description>New hunting query provides hash-based detection for LockBit ransomware artifacts deployed via Apache ActiveMQ CVE-2023-46604 exploitation.</description></item><item><title>Entra ID Identity Boundary Expansion: Three New Hunting Queries for Stealthy Persistence</title><link>http://sentinelchangelog.net/posts/2026-05-28-pr-14307/</link><pubDate>Thu, 28 May 2026 11:14:14 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-28-pr-14307/</guid><description>Added three hunting queries targeting identity boundary expansion techniques in Entra ID that escalate privileges without creating new accounts.</description></item><item><title>Entra ID Authentication Anomalies: Advanced Hunting for Privilege Abuse and Defense Evasion</title><link>http://sentinelchangelog.net/posts/2026-05-27-pr-14339/</link><pubDate>Wed, 27 May 2026 13:42:33 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-27-pr-14339/</guid><description>Adds three-query pack detecting legacy auth bypass, guest account abuse, and post-reset privileged operations.</description></item><item><title>Entra ID Account Takeover: Three-Query Hunting Pack for Post-Compromise Detection</title><link>http://sentinelchangelog.net/posts/2026-05-27-pr-14335/</link><pubDate>Wed, 27 May 2026 13:41:06 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-27-pr-14335/</guid><description>Adds hunting pack targeting device code phishing, service principal persistence, and bulk password resets by privileged actors.</description></item><item><title>BadUSB HID Injection Detection: New Hunt for PowerShell via Windows Run Dialog</title><link>http://sentinelchangelog.net/posts/2026-05-27-pr-14336/</link><pubDate>Wed, 27 May 2026 13:38:59 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-27-pr-14336/</guid><description>Adds hunting query to detect hardware keystroke injectors spawning PowerShell through explorer.exe with evasion patterns.</description></item><item><title>Microsoft Entra ID OAuth Consent Query: Fixing Zero-Result Bug in High-Risk Permission Detection</title><link>http://sentinelchangelog.net/posts/2026-05-27-pr-14334/</link><pubDate>Wed, 27 May 2026 13:38:30 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-27-pr-14334/</guid><description>Corrects broken hunting query that returned no results due to incorrect property name filter.</description></item><item><title>Hunting Query: Ephemeral Code Signing Certificates for Malware-Signing-as-a-Service Detection</title><link>http://sentinelchangelog.net/posts/2026-05-27-pr-14308/</link><pubDate>Wed, 27 May 2026 08:59:01 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-27-pr-14308/</guid><description>New hunting query identifies short-lived code signing certificates (≤14 days) on non-developer endpoints to detect Fox Tempest MSaaS operations.</description></item><item><title>Hunting Query: Rootkit Network Evasion Detection via Firewall-EDR Telemetry Delta</title><link>http://sentinelchangelog.net/posts/2026-05-27-pr-14337/</link><pubDate>Wed, 27 May 2026 08:36:31 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-27-pr-14337/</guid><description>New hunting query detects kernel-level rootkits bypassing EDR network telemetry by comparing perimeter firewall logs against Microsoft Defender for Endpoint data streams.</description></item><item><title>Defender for Endpoint: Cryptographic Identity Baselining Hunting Query for Process Network Anomalies</title><link>http://sentinelchangelog.net/posts/2026-05-26-pr-14333/</link><pubDate>Tue, 26 May 2026 09:05:22 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-26-pr-14333/</guid><description>New hunting query detects first-time network connections by processes using cryptographic signer baselining to defeat DLL sideloading and BYOTA attacks.</description></item><item><title>Entra ID Attack Chain Correlation: Three New Hunting Queries for Sequential Compromise Patterns</title><link>http://sentinelchangelog.net/posts/2026-05-26-pr-14311/</link><pubDate>Tue, 26 May 2026 08:14:04 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-26-pr-14311/</guid><description>Three hunting queries detect multi-event attack chains in Entra ID—privileged role grants followed by SP credential additions and MFA disabling followed by sign-ins from unknown IPs.</description></item><item><title>Phishing Detection: Raw IP URLs in Delivered Email</title><link>http://sentinelchangelog.net/posts/2026-05-26-pr-14340/</link><pubDate>Tue, 26 May 2026 06:30:21 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-26-pr-14340/</guid><description>New hunting query identifies delivered emails using raw IPv4 addresses as URL domains to detect phishing campaigns bypassing domain reputation systems.</description></item><item><title>Entra ID Hunting Pack: Defense Weakening and Privilege Abuse Detection</title><link>http://sentinelchangelog.net/posts/2026-05-26-pr-14240/</link><pubDate>Tue, 26 May 2026 06:12:52 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-26-pr-14240/</guid><description>Three hunting queries targeting silent defense weakening techniques and off-hours privilege escalation in Entra ID environments.</description></item><item><title>LSASS Credential Dumping: Resilient Behavioral Detection Pack Added</title><link>http://sentinelchangelog.net/posts/2026-05-26-pr-14341/</link><pubDate>Tue, 26 May 2026 05:29:06 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-26-pr-14341/</guid><description>Three new hunting queries detect LSASS memory dumping using behavioral physics rather than brittle timing or tool names.</description></item><item><title>Entra ID Workload Identity and Privileged Role Hunting Pack: Three New Detection Queries</title><link>http://sentinelchangelog.net/posts/2026-05-21-pr-14281/</link><pubDate>Thu, 21 May 2026 12:50:47 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-21-pr-14281/</guid><description>New hunting pack targeting workload identity abuse and privileged role assignment anomalies with coverage gaps for service principal credential theft and PIM bypass techniques.</description></item><item><title>ETW-Resistant .NET Fileless Injection Detection via Kernel-Level CLR Loading</title><link>http://sentinelchangelog.net/posts/2026-05-21-pr-14314/</link><pubDate>Thu, 21 May 2026 12:14:25 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-21-pr-14314/</guid><description>New hunting query detects fileless .NET execution even when attackers patch ETW by monitoring kernel-level .NET runtime DLL loading in native processes and untrusted paths.</description></item><item><title>Microsoft Defender XDR: New Hunting Query for Delegate Mailbox Phish Reporting Analysis</title><link>http://sentinelchangelog.net/posts/2026-05-21-pr-14257/</link><pubDate>Thu, 21 May 2026 04:14:42 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-21-pr-14257/</guid><description>New hunting query helps identify the actual user who reported a phishing message when recipients and actors differ in delegate or shared mailbox scenarios.</description></item><item><title>Entra ID Cross-Source Hunting Pack: Post-Compromise Pattern Detection</title><link>http://sentinelchangelog.net/posts/2026-05-19-pr-14262/</link><pubDate>Tue, 19 May 2026 10:09:11 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-19-pr-14262/</guid><description>Three new hunting queries correlate AuditLogs and SigninLogs to surface post-compromise identity patterns using baseline-driven anomaly detection.</description></item><item><title>AWS Content Quality Overhaul: Standardized Detection Rules and Improved Entity Mappings</title><link>http://sentinelchangelog.net/posts/2026-05-18-pr-14101/</link><pubDate>Mon, 18 May 2026 07:30:57 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-18-pr-14101/</guid><description>Comprehensive quality improvements to 61 AWS Analytic Rules and 35 Hunting Queries with standardized naming conventions, normalized MITRE technique mappings, and updated entity field references from legacy AccountCustomEntity to UserIdentityUserName.</description></item><item><title>Microsoft Entra ID Table Rename: Hunting Queries Updated for Current Schema</title><link>http://sentinelchangelog.net/posts/2026-05-18-pr-14186/</link><pubDate>Mon, 18 May 2026 05:36:36 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-18-pr-14186/</guid><description>12 hunting queries updated to use EntraIdSignInEvents and EntraIdSpnSignInEvents tables, replacing deprecated AADSignInEventsBeta and AADSpnSignInEventsBeta references.</description></item><item><title>Entra ID Attack Chain Detection: 5 New Hunting Queries Target Application Layer Persistence</title><link>http://sentinelchangelog.net/posts/2026-05-13-pr-14239/</link><pubDate>Wed, 13 May 2026 10:29:56 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-13-pr-14239/</guid><description>Five hunting queries expose OAuth consent abuse, privileged escalation, and Conditional Access evasion used in Midnight Blizzard and Storm-0558 campaigns.</description></item><item><title>Microsoft Entra ID: Service Principal Credential Manipulation by Rare Actors</title><link>http://sentinelchangelog.net/posts/2026-05-07-pr-14213/</link><pubDate>Thu, 07 May 2026 10:51:04 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-07-pr-14213/</guid><description>Identifies service principal credential additions by actors not observed performing these operations in the previous 90 days, targeting persistence techniques.</description></item><item><title>Microsoft Entra ID: Hunting Query for Password Spraying Detection via IP Failure Bursts</title><link>http://sentinelchangelog.net/posts/2026-05-07-pr-14208/</link><pubDate>Thu, 07 May 2026 10:50:43 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-07-pr-14208/</guid><description>Correlates failed sign-ins across multiple identities followed by successful authentication from the same IP within 15 minutes, targeting password spraying patterns.</description></item><item><title>Microsoft Entra ID: New Hunting Query Detects Post-Compromise Token Abuse via ASN Mismatches</title><link>http://sentinelchangelog.net/posts/2026-05-07-pr-14207/</link><pubDate>Thu, 07 May 2026 10:50:16 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-07-pr-14207/</guid><description>Surfaces rapid ASN changes between interactive and non-interactive sign-ins within 10 minutes, indicating potential post-compromise token misuse.</description></item><item><title>Azure Firewall Detection Quality Overhaul: Enhanced Alert Context and Reduced Query Costs</title><link>http://sentinelchangelog.net/posts/2026-05-06-pr-13820/</link><pubDate>Wed, 06 May 2026 09:37:20 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-06-pr-13820/</guid><description>Comprehensive quality improvements to 11 Azure Firewall detections and 5 hunting queries add entity mappings, custom details, and query optimizations to reduce false positives and improve incident context.</description></item><item><title>Claroty: Enhanced IoT/OT Detection with Improved Alert Fidelity</title><link>http://sentinelchangelog.net/posts/2026-05-05-pr-14107/</link><pubDate>Tue, 05 May 2026 09:58:40 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-05-pr-14107/</guid><description>Updated 9 analytic rules and 10 hunting queries with strengthened entity mapping, alert details, and MITRE coverage for OT/IoT network monitoring.</description></item><item><title>Teams Social Engineering Detection: New Hunting Queries for RMM-Based Attacks</title><link>http://sentinelchangelog.net/posts/2026-05-04-pr-14117/</link><pubDate>Mon, 04 May 2026 12:53:39 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-04-pr-14117/</guid><description>Two new hunting queries detect Teams phishing campaigns that lure victims into launching remote access tools, addressing the Storm-1811 / Black Basta cross-tenant attack pattern.</description></item><item><title>Valimail Enforce Solution: New Email Authentication Monitoring for DMARC/SPF/DKIM Configuration Changes</title><link>http://sentinelchangelog.net/posts/2026-04-24-pr-14045/</link><pubDate>Fri, 24 Apr 2026 05:26:39 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-04-24-pr-14045/</guid><description>Complete Valimail Enforce monitoring solution delivers real-time detection of email authentication policy weakening and suspicious admin activity affecting domain security posture.</description></item><item><title>SOCRadar XTI Platform: New Extended Threat Intelligence Solution Launches with Bidirectional Sync</title><link>http://sentinelchangelog.net/posts/2026-04-23-pr-13858/</link><pubDate>Thu, 23 Apr 2026 05:24:37 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-04-23-pr-13858/</guid><description>SOCRadar XTI Platform solution now available in Content Hub with automated alarm import, incident sync, and comprehensive threat intelligence monitoring capabilities.</description></item><item><title>Microsoft Security Copilot: Six New Detections for AI Assistant Abuse</title><link>http://sentinelchangelog.net/posts/2026-03-27-pr-13735/</link><pubDate>Fri, 27 Mar 2026 05:01:42 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-03-27-pr-13735/</guid><description>New analytic rules target jailbreak attempts, external access, plugin tampering, and file upload disabling - covering major AI security attack vectors.</description></item><item><title>AI Agents Hunting Query: Schema Field Case Correction Enables Query Execution</title><link>http://sentinelchangelog.net/posts/2026-03-06-pr-13740/</link><pubDate>Fri, 06 Mar 2026 05:08:34 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-03-06-pr-13740/</guid><description>Fixed IdentityInfo field reference from AccountUPN to AccountUpn to resolve KQL validation failure and restore query functionality.</description></item><item><title>Azure Activity: Hunting Query Documentation Enhancement for Custom Script Extensions</title><link>http://sentinelchangelog.net/posts/2026-02-26-pr-13705/</link><pubDate>Thu, 26 Feb 2026 04:54:57 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-02-26-pr-13705/</guid><description>Minor documentation improvement clarifying protected settings visibility in Custom Script Extension hunting query.</description></item><item><title>Microsoft Defender XDR Solution: Punycode Hunting Query Added for Lookalike Domain Detection</title><link>http://sentinelchangelog.net/posts/2026-02-17-pr-13596/</link><pubDate>Tue, 17 Feb 2026 06:43:02 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-02-17-pr-13596/</guid><description>Microsoft Defender XDR solution v3.0.14 adds hunting query targeting Punycode character abuse in lookalike domain attacks.</description></item><item><title>Microsoft Defender XDR: New Hunting Query for Punycode Lookalike Domain Phishing</title><link>http://sentinelchangelog.net/posts/2026-02-03-pr-13535/</link><pubDate>Tue, 03 Feb 2026 09:48:09 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-02-03-pr-13535/</guid><description>Advanced hunting query detects punycode domains using Cyrillic, Greek, and fullwidth ASCII characters to visually impersonate legitimate domains in email and Teams.</description></item><item><title>Microsoft Defender XDR: SUNSPOT Detection Rule Documentation Update</title><link>http://sentinelchangelog.net/posts/2026-01-22-pr-13485/</link><pubDate>Thu, 22 Jan 2026 11:09:59 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-01-22-pr-13485/</guid><description>Updated SUNSPOT malware detection rule with corrected reference link formatting and MITRE technique mapping fixes across multiple solutions.</description></item><item><title>New Solution: JoeSandbox Threat Intelligence and Malware Analysis Platform Integration</title><link>http://sentinelchangelog.net/posts/2026-01-22-pr-12801/</link><pubDate>Thu, 22 Jan 2026 09:02:45 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-01-22-pr-12801/</guid><description>Complete JoeSandbox solution deployment enabling automated malware analysis, threat intelligence feed ingestion, and incident enrichment playbooks for Microsoft Sentinel.</description></item><item><title>Microsoft Defender XDR: Teams Hunting Queries Version Number Fix</title><link>http://sentinelchangelog.net/posts/2026-01-22-pr-13205/</link><pubDate>Thu, 22 Jan 2026 06:09:17 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-01-22-pr-13205/</guid><description>Corrected malformed version numbers in Microsoft Teams threat hunting queries from invalid &amp;ldquo;l.0.0&amp;rdquo; to proper &amp;ldquo;1.0.0&amp;rdquo; format.</description></item><item><title>Multi-Solution Link Updates: MITRE Technique Corrections and Reference Refreshes</title><link>http://sentinelchangelog.net/posts/2026-01-21-pr-13480/</link><pubDate>Wed, 21 Jan 2026 13:39:25 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-01-21-pr-13480/</guid><description>Updated outdated links and corrected MITRE ATT&amp;amp;CK technique mapping in detection rules across Microsoft Business Applications, Microsoft Defender XDR, and Windows Security Events solutions.</description></item><item><title>Schema Correction: MITRE ATT&amp;CK Field Name Fix Across Multiple Solutions</title><link>http://sentinelchangelog.net/posts/2025-12-24-pr-13346/</link><pubDate>Wed, 24 Dec 2025 11:51:45 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-12-24-pr-13346/</guid><description>Critical schema update replaces deprecated requiredTechniques field with correct relevantTechniques field in analytic rules.</description></item><item><title>Fortigate ASIM Parser: Field Name Consistency Fix for Network Session Schema</title><link>http://sentinelchangelog.net/posts/2025-12-12-pr-12927/</link><pubDate>Fri, 12 Dec 2025 09:49:09 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-12-12-pr-12927/</guid><description>Field name inconsistencies in Fortigate ASIM parsers corrected to ensure proper schema compliance and data normalization.</description></item><item><title>Critical Cloudflare Analytics Rules: Enhanced URL Entity Mapping and Repository Maintenance</title><link>http://sentinelchangelog.net/posts/2025-12-08-pr-13138/</link><pubDate>Mon, 08 Dec 2025 06:57:34 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-12-08-pr-13138/</guid><description>P0-labeled update improves URL entity mapping in Cloudflare detection rules alongside extensive repository maintenance and validation improvements.</description></item><item><title>Google Threat Intelligence: Enhanced Threat Hunting with MITRE ATT&amp;CK Integration</title><link>http://sentinelchangelog.net/posts/2025-12-04-pr-13198/</link><pubDate>Thu, 04 Dec 2025 05:49:38 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-12-04-pr-13198/</guid><description>Updated threat hunting rules add MITRE ATT&amp;amp;CK mappings and fix parser function calls for improved threat detection coverage.</description></item><item><title>UEBA Essentials: Five New Hunting Queries for Advanced Anomaly Analysis and Threat Triage</title><link>http://sentinelchangelog.net/posts/2025-11-24-pr-13182/</link><pubDate>Mon, 24 Nov 2025 11:31:39 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-11-24-pr-13182/</guid><description>UEBA Essentials v4.1.0 adds five targeted hunting queries for high-score anomaly triage, trend analysis, template distribution, user-centric investigation, and malicious source IP identification.</description></item><item><title>Microsoft Teams Security: 9 Additional Hunting Queries for Advanced Threat Detection</title><link>http://sentinelchangelog.net/posts/2025-11-21-pr-13167/</link><pubDate>Fri, 21 Nov 2025 05:16:08 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-11-21-pr-13167/</guid><description>Extended Teams protection hunting coverage with queries for partner impersonation, admin submissions, and external sender analysis.</description></item><item><title>Open Systems Connector: aiohttp Security Update 3.10.11→3.12.14 Plus Multi-Solution Changes</title><link>http://sentinelchangelog.net/posts/2025-11-20-pr-13158/</link><pubDate>Thu, 20 Nov 2025 08:54:08 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-11-20-pr-13158/</guid><description>Open Systems connector updated aiohttp dependency addressing potential security vulnerabilities, bundled with extensive solution packaging updates.</description></item><item><title>Microsoft Teams Security: 7 New Hunting Queries for URL Threat Detection</title><link>http://sentinelchangelog.net/posts/2025-11-19-pr-13156/</link><pubDate>Wed, 19 Nov 2025 08:50:58 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-11-19-pr-13156/</guid><description>New hunting queries added to detect malicious URL clicks, ZAP events, and user submissions in Microsoft Teams.</description></item><item><title>GCP Security Command Center: New Detection Suite for Cloud Misconfigurations</title><link>http://sentinelchangelog.net/posts/2025-11-14-pr-13116/</link><pubDate>Fri, 14 Nov 2025 08:22:41 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-11-14-pr-13116/</guid><description>New Solution delivers 5 Analytic Rules and 5 Hunting Queries to detect GCP security misconfigurations including unrestricted API keys, disabled security features, and risky IAM configurations.</description></item><item><title>UEBA Essentials: Enhanced Multi-Cloud Detection with 6 New AWS, GCP &amp; Okta Hunting Queries</title><link>http://sentinelchangelog.net/posts/2025-11-12-pr-13065/</link><pubDate>Wed, 12 Nov 2025 11:17:58 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-11-12-pr-13065/</guid><description>Major update adds comprehensive multi-cloud anomaly detection capabilities across AWS, GCP, and Okta platforms with 6 new hunting queries.</description></item></channel></rss>