<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>T1204 on sentinelchangelog.net</title><link>http://sentinelchangelog.net/tags/t1204/</link><description>Recent content in T1204 on sentinelchangelog.net</description><generator>Hugo -- 0.157.0</generator><language>en</language><lastBuildDate>Mon, 01 Jun 2026 04:39:34 +0000</lastBuildDate><atom:link href="http://sentinelchangelog.net/tags/t1204/index.xml" rel="self" type="application/rss+xml"/><item><title>Slack Audit Solution: Enhanced Detection Logic and Alert Enrichment</title><link>http://sentinelchangelog.net/posts/2026-06-01-pr-14245/</link><pubDate>Mon, 01 Jun 2026 04:39:34 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-06-01-pr-14245/</guid><description>Slack Audit analytic rules, hunting queries, and workbook upgraded with improved KQL logic, custom alert details, and enhanced entity mappings for stronger workspace monitoring.</description></item><item><title>LockBit Hunting Query: ActiveMQ Exploit IoC Detection Added</title><link>http://sentinelchangelog.net/posts/2026-05-29-pr-14350/</link><pubDate>Fri, 29 May 2026 05:32:22 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-29-pr-14350/</guid><description>New hunting query provides hash-based detection for LockBit ransomware artifacts deployed via Apache ActiveMQ CVE-2023-46604 exploitation.</description></item><item><title>AWS Content Quality Overhaul: Standardized Detection Rules and Improved Entity Mappings</title><link>http://sentinelchangelog.net/posts/2026-05-18-pr-14101/</link><pubDate>Mon, 18 May 2026 07:30:57 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-18-pr-14101/</guid><description>Comprehensive quality improvements to 61 AWS Analytic Rules and 35 Hunting Queries with standardized naming conventions, normalized MITRE technique mappings, and updated entity field references from legacy AccountCustomEntity to UserIdentityUserName.</description></item><item><title>Microsoft Entra ID Table Rename: Hunting Queries Updated for Current Schema</title><link>http://sentinelchangelog.net/posts/2026-05-18-pr-14186/</link><pubDate>Mon, 18 May 2026 05:36:36 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-18-pr-14186/</guid><description>12 hunting queries updated to use EntraIdSignInEvents and EntraIdSpnSignInEvents tables, replacing deprecated AADSignInEventsBeta and AADSpnSignInEventsBeta references.</description></item><item><title>Microsoft Sentinel Training Lab: Comprehensive Hands-On Security Operations Environment Now Available</title><link>http://sentinelchangelog.net/posts/2026-04-10-pr-13848/</link><pubDate>Fri, 10 Apr 2026 15:05:24 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-04-10-pr-13848/</guid><description>New deployment-ready training lab delivers 14 guided exercises with pre-recorded telemetry, detection rules, and automation workflows for practical Microsoft Sentinel skill development.</description></item><item><title>Visa Threat Intelligence Solution: Initial Package Release with IOC Detection Rules</title><link>http://sentinelchangelog.net/posts/2026-02-13-pr-13616/</link><pubDate>Fri, 13 Feb 2026 21:02:02 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-02-13-pr-13616/</guid><description>New Visa Threat Intelligence (VTI) solution providing IOC feeds via DCR connector with high-severity detection rules for domains and file hashes.</description></item><item><title>Azure Firewall: Five New IDPS Analytic Rules for Advanced Threat Detection</title><link>http://sentinelchangelog.net/posts/2026-02-13-pr-13591/</link><pubDate>Fri, 13 Feb 2026 08:19:01 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-02-13-pr-13591/</guid><description>Azure Firewall solution expanded with 5 new analytic rules targeting high/medium severity threats, DDoS attacks, web application attacks, and privilege escalation attempts.</description></item><item><title>VMware ESXi SSH Brute Force Detection Plus Multi-Solution Updates</title><link>http://sentinelchangelog.net/posts/2025-11-10-pr-13063/</link><pubDate>Mon, 10 Nov 2025 06:23:07 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-11-10-pr-13063/</guid><description>New VMware ESXi detection for multiple failed SSH login attempts, plus comprehensive solution updates across 15+ vendor solutions.</description></item></channel></rss>