<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Malware Analysis on sentinelchangelog.net</title><link>http://sentinelchangelog.net/tags/malware-analysis/</link><description>Recent content in Malware Analysis on sentinelchangelog.net</description><generator>Hugo -- 0.157.0</generator><language>en</language><lastBuildDate>Wed, 27 May 2026 08:59:01 +0000</lastBuildDate><atom:link href="http://sentinelchangelog.net/tags/malware-analysis/index.xml" rel="self" type="application/rss+xml"/><item><title>Hunting Query: Ephemeral Code Signing Certificates for Malware-Signing-as-a-Service Detection</title><link>http://sentinelchangelog.net/posts/2026-05-27-pr-14308/</link><pubDate>Wed, 27 May 2026 08:59:01 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-27-pr-14308/</guid><description>New hunting query identifies short-lived code signing certificates (≤14 days) on non-developer endpoints to detect Fox Tempest MSaaS operations.</description></item><item><title>Joe Sandbox Solution: ARM Template Fixes and IOC Handling Improvements</title><link>http://sentinelchangelog.net/posts/2026-05-04-pr-14130/</link><pubDate>Mon, 04 May 2026 12:39:49 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-04-pr-14130/</guid><description>Joe Sandbox solution updated to v3.0.1 with Azure template fixes, updated storage API versions, and improved IOC processing in playbooks.</description></item><item><title>Recorded Future Sandbox: Enhanced Region Support and Improved Threat Intelligence Structure</title><link>http://sentinelchangelog.net/posts/2026-04-20-pr-14056/</link><pubDate>Mon, 20 Apr 2026 05:13:10 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-04-20-pr-14056/</guid><description>Recorded Future adds sandbox region configuration parameter and moves threat intelligence evidence details to comply with STIX standard structure.</description></item><item><title>JoeSandbox Solution: Updated Deployment Links and Removed Manual Installation Steps</title><link>http://sentinelchangelog.net/posts/2026-02-13-pr-13623/</link><pubDate>Fri, 13 Feb 2026 11:30:47 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-02-13-pr-13623/</guid><description>JoeSandbox solution deployment documentation updated with corrected Azure links and streamlined automated deployment options.</description></item><item><title>New Solution: JoeSandbox Threat Intelligence and Malware Analysis Platform Integration</title><link>http://sentinelchangelog.net/posts/2026-01-22-pr-12801/</link><pubDate>Thu, 22 Jan 2026 09:02:45 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-01-22-pr-12801/</guid><description>Complete JoeSandbox solution deployment enabling automated malware analysis, threat intelligence feed ingestion, and incident enrichment playbooks for Microsoft Sentinel.</description></item><item><title>VMRay Connector: Fixed Premium ARM Template Security Configuration</title><link>http://sentinelchangelog.net/posts/2025-11-10-pr-13100/</link><pubDate>Mon, 10 Nov 2025 11:12:27 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-11-10-pr-13100/</guid><description>ARM template deployment fix adds mandatory TLS 1.2 enforcement and corrects resource configuration for VMRay Function App connector.</description></item></channel></rss>