<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>T1021 on sentinelchangelog.net</title><link>http://sentinelchangelog.net/tags/t1021/</link><description>Recent content in T1021 on sentinelchangelog.net</description><generator>Hugo -- 0.157.0</generator><language>en</language><lastBuildDate>Wed, 06 May 2026 09:37:20 +0000</lastBuildDate><atom:link href="http://sentinelchangelog.net/tags/t1021/index.xml" rel="self" type="application/rss+xml"/><item><title>Azure Firewall Detection Quality Overhaul: Enhanced Alert Context and Reduced Query Costs</title><link>http://sentinelchangelog.net/posts/2026-05-06-pr-13820/</link><pubDate>Wed, 06 May 2026 09:37:20 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-06-pr-13820/</guid><description>Comprehensive quality improvements to 11 Azure Firewall detections and 5 hunting queries add entity mappings, custom details, and query optimizations to reduce false positives and improve incident context.</description></item><item><title>Contrast ADR: CCF Connector Deployment Unlocks Application Attack Visibility</title><link>http://sentinelchangelog.net/posts/2026-04-15-pr-13954/</link><pubDate>Wed, 15 Apr 2026 04:58:02 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-04-15-pr-13954/</guid><description>Contrast ADR adds CCF ingestion support with standardized table schemas for production-ready Application Detection and Response monitoring.</description></item><item><title>SAP BTP: 10 New Enterprise Security Detections for Cloud Integration and Identity Service</title><link>http://sentinelchangelog.net/posts/2026-01-05-pr-13366/</link><pubDate>Mon, 05 Jan 2026 08:20:43 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-01-05-pr-13366/</guid><description>New threat detection coverage for SAP BTP Cloud Integration tampering, identity service compromise, and audit service availability.</description></item><item><title>UEBA Essentials: Enhanced Multi-Cloud Detection with 6 New AWS, GCP &amp; Okta Hunting Queries</title><link>http://sentinelchangelog.net/posts/2025-11-12-pr-13065/</link><pubDate>Wed, 12 Nov 2025 11:17:58 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-11-12-pr-13065/</guid><description>Major update adds comprehensive multi-cloud anomaly detection capabilities across AWS, GCP, and Okta platforms with 6 new hunting queries.</description></item><item><title>AWS and VMware ESXi: Three New Analytic Rules for Execution, Exfiltration, and Lateral Movement</title><link>http://sentinelchangelog.net/posts/2025-10-09-pr-12696/</link><pubDate>Thu, 09 Oct 2025 12:07:12 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-10-09-pr-12696/</guid><description>Three new Analytic Rules added across AWS CloudTrail and VMware ESXi — detecting EC2 startup script tampering (T1059), anonymous S3 object exfiltration (T1530), and SSH enablement on ESXi hosts (T1021).</description></item></channel></rss>