<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Microsoft Defender XDR on sentinelchangelog.net</title><link>http://sentinelchangelog.net/tags/microsoft-defender-xdr/</link><description>Recent content in Microsoft Defender XDR on sentinelchangelog.net</description><generator>Hugo -- 0.157.0</generator><language>en</language><lastBuildDate>Thu, 21 May 2026 04:14:42 +0000</lastBuildDate><atom:link href="http://sentinelchangelog.net/tags/microsoft-defender-xdr/index.xml" rel="self" type="application/rss+xml"/><item><title>Microsoft Defender XDR: New Hunting Query for Delegate Mailbox Phish Reporting Analysis</title><link>http://sentinelchangelog.net/posts/2026-05-21-pr-14257/</link><pubDate>Thu, 21 May 2026 04:14:42 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-21-pr-14257/</guid><description>New hunting query helps identify the actual user who reported a phishing message when recipients and actors differ in delegate or shared mailbox scenarios.</description></item><item><title>Microsoft Sentinel to Defender Portal Migration Readiness Tool</title><link>http://sentinelchangelog.net/posts/2026-05-15-pr-14195/</link><pubDate>Fri, 15 May 2026 08:53:22 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-15-pr-14195/</guid><description>New PowerShell assessment tool identifies migration blockers for Sentinel-to-Defender portal transitions.</description></item><item><title>Teams Social Engineering Detection: New Hunting Queries for RMM-Based Attacks</title><link>http://sentinelchangelog.net/posts/2026-05-04-pr-14117/</link><pubDate>Mon, 04 May 2026 12:53:39 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-04-pr-14117/</guid><description>Two new hunting queries detect Teams phishing campaigns that lure victims into launching remote access tools, addressing the Storm-1811 / Black Basta cross-tenant attack pattern.</description></item><item><title>SAP: New Agentless User Blocking Playbook for Defender XDR Integration</title><link>http://sentinelchangelog.net/posts/2026-04-16-pr-14071/</link><pubDate>Thu, 16 Apr 2026 05:05:00 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-04-16-pr-14071/</guid><description>New SAP playbook enables automated user blocking via Teams adaptive cards with enhanced support for complex multi-alert incidents from Microsoft Defender XDR.</description></item><item><title>ASIM AlertEvent Parser: Microsoft Defender XDR Missing AlertOriginalStatus Field Restored</title><link>http://sentinelchangelog.net/posts/2026-04-02-pr-13970/</link><pubDate>Thu, 02 Apr 2026 16:47:47 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-04-02-pr-13970/</guid><description>Critical data fidelity fix restores missing AlertOriginalStatus field in Microsoft Defender XDR ASIM AlertEvent parser, resolving alert status visibility gap.</description></item><item><title>Microsoft Defender XDR Solution: Punycode Hunting Query Added for Lookalike Domain Detection</title><link>http://sentinelchangelog.net/posts/2026-02-17-pr-13596/</link><pubDate>Tue, 17 Feb 2026 06:43:02 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-02-17-pr-13596/</guid><description>Microsoft Defender XDR solution v3.0.14 adds hunting query targeting Punycode character abuse in lookalike domain attacks.</description></item><item><title>ASIM AlertEvent: Microsoft Defender XDR Parser Enhanced with Improved Field Mappings</title><link>http://sentinelchangelog.net/posts/2026-02-05-pr-13418/</link><pubDate>Thu, 05 Feb 2026 01:04:06 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-02-05-pr-13418/</guid><description>Microsoft Defender XDR AlertEvent parsers updated with optimized KQL logic, corrected field mappings, and enhanced IP address collection.</description></item><item><title>Microsoft Defender XDR: New Hunting Query for Punycode Lookalike Domain Phishing</title><link>http://sentinelchangelog.net/posts/2026-02-03-pr-13535/</link><pubDate>Tue, 03 Feb 2026 09:48:09 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-02-03-pr-13535/</guid><description>Advanced hunting query detects punycode domains using Cyrillic, Greek, and fullwidth ASCII characters to visually impersonate legitimate domains in email and Teams.</description></item><item><title>Microsoft Defender XDR: SUNSPOT Detection Rule Documentation Update</title><link>http://sentinelchangelog.net/posts/2026-01-22-pr-13485/</link><pubDate>Thu, 22 Jan 2026 11:09:59 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-01-22-pr-13485/</guid><description>Updated SUNSPOT malware detection rule with corrected reference link formatting and MITRE technique mapping fixes across multiple solutions.</description></item><item><title>Microsoft Defender XDR: Teams Hunting Queries Version Number Fix</title><link>http://sentinelchangelog.net/posts/2026-01-22-pr-13205/</link><pubDate>Thu, 22 Jan 2026 06:09:17 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-01-22-pr-13205/</guid><description>Corrected malformed version numbers in Microsoft Teams threat hunting queries from invalid &amp;ldquo;l.0.0&amp;rdquo; to proper &amp;ldquo;1.0.0&amp;rdquo; format.</description></item><item><title>Multi-Solution Link Updates: MITRE Technique Corrections and Reference Refreshes</title><link>http://sentinelchangelog.net/posts/2026-01-21-pr-13480/</link><pubDate>Wed, 21 Jan 2026 13:39:25 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-01-21-pr-13480/</guid><description>Updated outdated links and corrected MITRE ATT&amp;amp;CK technique mapping in detection rules across Microsoft Business Applications, Microsoft Defender XDR, and Windows Security Events solutions.</description></item><item><title>ZeroFox CCF Connector: KQL Query Restoration and Multi-Solution Maintenance</title><link>http://sentinelchangelog.net/posts/2025-12-04-pr-13209/</link><pubDate>Thu, 04 Dec 2025 10:45:58 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-12-04-pr-13209/</guid><description>ZeroFox CCF connector receives missing KQL query fixes alongside packaging updates across 8+ solutions.</description></item><item><title>Microsoft Defender XDR Workbook Version 3: Enhanced Visualizations and Insights</title><link>http://sentinelchangelog.net/posts/2025-12-02-pr-13215/</link><pubDate>Tue, 02 Dec 2025 05:53:01 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-12-02-pr-13215/</guid><description>Updated Microsoft Defender for Office 365 workbook to version 3 with new visuals and improved insights based on user feedback.</description></item><item><title>Microsoft Teams Security: 9 Additional Hunting Queries for Advanced Threat Detection</title><link>http://sentinelchangelog.net/posts/2025-11-21-pr-13167/</link><pubDate>Fri, 21 Nov 2025 05:16:08 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-11-21-pr-13167/</guid><description>Extended Teams protection hunting coverage with queries for partner impersonation, admin submissions, and external sender analysis.</description></item><item><title>Open Systems Connector: aiohttp Security Update 3.10.11→3.12.14 Plus Multi-Solution Changes</title><link>http://sentinelchangelog.net/posts/2025-11-20-pr-13158/</link><pubDate>Thu, 20 Nov 2025 08:54:08 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-11-20-pr-13158/</guid><description>Open Systems connector updated aiohttp dependency addressing potential security vulnerabilities, bundled with extensive solution packaging updates.</description></item><item><title>Microsoft Teams Security: 7 New Hunting Queries for URL Threat Detection</title><link>http://sentinelchangelog.net/posts/2025-11-19-pr-13156/</link><pubDate>Wed, 19 Nov 2025 08:50:58 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-11-19-pr-13156/</guid><description>New hunting queries added to detect malicious URL clicks, ZAP events, and user submissions in Microsoft Teams.</description></item><item><title>VMware ESXi SSH Brute Force Detection Plus Multi-Solution Updates</title><link>http://sentinelchangelog.net/posts/2025-11-10-pr-13063/</link><pubDate>Mon, 10 Nov 2025 06:23:07 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-11-10-pr-13063/</guid><description>New VMware ESXi detection for multiple failed SSH login attempts, plus comprehensive solution updates across 15+ vendor solutions.</description></item><item><title>CyberArk Audit Security Update: CVE-2024-47081 Fix Plus Multi-Solution Maintenance</title><link>http://sentinelchangelog.net/posts/2025-11-05-pr-13061/</link><pubDate>Wed, 05 Nov 2025 13:11:45 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-11-05-pr-13061/</guid><description>Critical security update for CyberArk Audit requests library addressing credential leak vulnerability, plus comprehensive updates across 8 solutions.</description></item></channel></rss>