<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>T1562 on sentinelchangelog.net</title><link>http://sentinelchangelog.net/tags/t1562/</link><description>Recent content in T1562 on sentinelchangelog.net</description><generator>Hugo -- 0.157.0</generator><language>en</language><lastBuildDate>Thu, 21 May 2026 12:01:33 +0000</lastBuildDate><atom:link href="http://sentinelchangelog.net/tags/t1562/index.xml" rel="self" type="application/rss+xml"/><item><title>CrowdStrike Content Doctor Enhancement: Improved Detection Logic and Alert Customization</title><link>http://sentinelchangelog.net/posts/2026-05-21-pr-14268/</link><pubDate>Thu, 21 May 2026 12:01:33 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-21-pr-14268/</guid><description>Content Doctor improvements to CrowdStrike Falcon detection rules enhancing KQL logic, MITRE mappings, and alert presentation for critical/high severity detections.</description></item><item><title>AWS Content Quality Overhaul: Standardized Detection Rules and Improved Entity Mappings</title><link>http://sentinelchangelog.net/posts/2026-05-18-pr-14101/</link><pubDate>Mon, 18 May 2026 07:30:57 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-18-pr-14101/</guid><description>Comprehensive quality improvements to 61 AWS Analytic Rules and 35 Hunting Queries with standardized naming conventions, normalized MITRE technique mappings, and updated entity field references from legacy AccountCustomEntity to UserIdentityUserName.</description></item><item><title>Valimail Enforce Solution: New Email Authentication Monitoring for DMARC/SPF/DKIM Configuration Changes</title><link>http://sentinelchangelog.net/posts/2026-04-24-pr-14045/</link><pubDate>Fri, 24 Apr 2026 05:26:39 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-04-24-pr-14045/</guid><description>Complete Valimail Enforce monitoring solution delivers real-time detection of email authentication policy weakening and suspicious admin activity affecting domain security posture.</description></item><item><title>Check Point Cyberint: Bi-Directional Alert Sync and Critical Data Ingestion Fix</title><link>http://sentinelchangelog.net/posts/2026-04-15-pr-13790/</link><pubDate>Wed, 15 Apr 2026 14:01:43 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-04-15-pr-13790/</guid><description>Adds comprehensive bi-directional sync playbooks and fixes critical ref_id column type bug that caused silent data loss in alert ingestion.</description></item><item><title>Microsoft Sentinel Training Lab: Comprehensive Hands-On Security Operations Environment Now Available</title><link>http://sentinelchangelog.net/posts/2026-04-10-pr-13848/</link><pubDate>Fri, 10 Apr 2026 15:05:24 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-04-10-pr-13848/</guid><description>New deployment-ready training lab delivers 14 guided exercises with pre-recorded telemetry, detection rules, and automation workflows for practical Microsoft Sentinel skill development.</description></item><item><title>Netskope Secure Web Gateway Solution: New Detection Coverage for Cloud Application Visibility</title><link>http://sentinelchangelog.net/posts/2026-04-03-pr-13618/</link><pubDate>Fri, 03 Apr 2026 11:24:10 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-04-03-pr-13618/</guid><description>New Netskope solution adds 10 detections for web transaction monitoring including impossible travel, excessive downloads, shadow IT detection, and data exfiltration patterns.</description></item><item><title>Microsoft Security Copilot: Six New Detections for AI Assistant Abuse</title><link>http://sentinelchangelog.net/posts/2026-03-27-pr-13735/</link><pubDate>Fri, 27 Mar 2026 05:01:42 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-03-27-pr-13735/</guid><description>New analytic rules target jailbreak attempts, external access, plugin tampering, and file upload disabling - covering major AI security attack vectors.</description></item><item><title>New Attack Surface Management Solution: blacklens.io Brings External Threat Visibility to Microsoft Sentinel</title><link>http://sentinelchangelog.net/posts/2026-03-26-pr-13375/</link><pubDate>Thu, 26 Mar 2026 12:48:50 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-03-26-pr-13375/</guid><description>blacklens.io Attack Surface Management platform now available in Content Hub with webhook-based alert ingestion and automated incident creation.</description></item><item><title>GitHub 2FA Detection Restored: Critical Blind Spot Fixed After Parser Migration</title><link>http://sentinelchangelog.net/posts/2026-03-20-pr-13770/</link><pubDate>Fri, 20 Mar 2026 09:23:24 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-03-20-pr-13770/</guid><description>GitHub Enterprise 2FA disablement detection rule was completely broken due to deprecated table reference — restored monitoring for T1562 defense impairment.</description></item><item><title>VMware ESXi SSH Brute Force Detection Plus Multi-Solution Updates</title><link>http://sentinelchangelog.net/posts/2025-11-10-pr-13063/</link><pubDate>Mon, 10 Nov 2025 06:23:07 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-11-10-pr-13063/</guid><description>New VMware ESXi detection for multiple failed SSH login attempts, plus comprehensive solution updates across 15+ vendor solutions.</description></item></channel></rss>