<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>T1059 on sentinelchangelog.net</title><link>http://sentinelchangelog.net/tags/t1059/</link><description>Recent content in T1059 on sentinelchangelog.net</description><generator>Hugo -- 0.157.0</generator><language>en</language><lastBuildDate>Thu, 28 May 2026 05:16:16 +0000</lastBuildDate><atom:link href="http://sentinelchangelog.net/tags/t1059/index.xml" rel="self" type="application/rss+xml"/><item><title>ASIM AlertEvent Support Added for Bitdefender GravityZone Security Platform</title><link>http://sentinelchangelog.net/posts/2026-05-28-pr-13330/</link><pubDate>Thu, 28 May 2026 05:16:16 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-28-pr-13330/</guid><description>New parsers enable normalization of Bitdefender GravityZone alert data into Microsoft Sentinel ASIM schema for unified threat detection.</description></item><item><title>AWS Content Quality Overhaul: Standardized Detection Rules and Improved Entity Mappings</title><link>http://sentinelchangelog.net/posts/2026-05-18-pr-14101/</link><pubDate>Mon, 18 May 2026 07:30:57 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-18-pr-14101/</guid><description>Comprehensive quality improvements to 61 AWS Analytic Rules and 35 Hunting Queries with standardized naming conventions, normalized MITRE technique mappings, and updated entity field references from legacy AccountCustomEntity to UserIdentityUserName.</description></item><item><title>SAP BTP: 10 New Enterprise Security Detections for Cloud Integration and Identity Service</title><link>http://sentinelchangelog.net/posts/2026-01-05-pr-13366/</link><pubDate>Mon, 05 Jan 2026 08:20:43 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-01-05-pr-13366/</guid><description>New threat detection coverage for SAP BTP Cloud Integration tampering, identity service compromise, and audit service availability.</description></item><item><title>AWS and VMware ESXi: Three New Analytic Rules for Execution, Exfiltration, and Lateral Movement</title><link>http://sentinelchangelog.net/posts/2025-10-09-pr-12696/</link><pubDate>Thu, 09 Oct 2025 12:07:12 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-10-09-pr-12696/</guid><description>Three new Analytic Rules added across AWS CloudTrail and VMware ESXi — detecting EC2 startup script tampering (T1059), anonymous S3 object exfiltration (T1530), and SSH enablement on ESXi hosts (T1021).</description></item></channel></rss>