August 17th, 2026 - Content Release
- This content release includes:
- New Check Point CloudGuard log mapper and parser for cloud security posture monitoring
- New AWS API Gateway parser with enhanced field extraction to support additional log formats
- Updated Threat Intel IP rules with adjusted severity scoring and improved signal descriptions for high, medium, and low confidence indicators
- Continued migration of log mappers from the direct security passthrough rule (MATCH-S00402) to the new normalized detection classes (Runtime, Identity, Network, Data Protection), adding the
threat_ruleTypefield for consistent threat categorization. Impacted products:- Runtime: AlphaSOC, Aqua, Contrast ADR, CrowdStrike FDR, Falco, Sysdig, Twistlock
- Identity: Azure, Box, CrowdStrike Falcon, Darktrace, DocuSign Monitor, Google Workspace Alert Center, Microsoft Cloud App Security, Microsoft Graph Identity Protection, Okta, Salesforce, Slack
- Network: Bitdefender, Check Point CloudGuard, Cisco Firepower, Claroty xDome, FireEye, Fortinet, Kemp, Microsoft Graph Security API, Office 365, Palo Alto, Trend Micro, Vectra, Vectra AI, Windows Defender
- Data Protection: Akamai CPC, Check Point Avanan, Egnyte, Fortinet DLP, Google Workspace Alert Center (DLP), IBM Guardium, Microsoft Graph Security (IPC/O365 Compliance), Mimecast, Netskope, Noname API Security, Office 365 (DLP/Compliance), Proofpoint TRAP, Thinkst Canary, Varonis
- New schema fields (
user_accessId,fromUser_accessId,targetUser_accessId) for tracking access key identifiers across user contexts - Additional changes are enumerated below
Rules
- [Updated] MATCH-S00455 O365 - Successful Authentication with PowerShell User Agent
- [Updated] MATCH-S01024 Threat Intel - Destination IP Address (High Confidence)
- [Updated] MATCH-S01026 Threat Intel - Destination IP Address (Low Confidence)
- [Updated] MATCH-S01028 Threat Intel - Destination IP Address (Medium Confidence)
- [Updated] MATCH-S01023 Threat Intel - Inbound Traffic from Threat Feed IP (High Confidence)
- [Updated] MATCH-S01025 Threat Intel - Inbound Traffic from Threat Feed IP (Low Confidence)
- [Updated] MATCH-S01027 Threat Intel - Inbound Traffic from Threat Feed IP (Medium Confidence)
Log Mappers
- [New] Check Point CloudGuard
- [Updated] Akamai CPC
- [Updated] Akamai Noname API Security Insight Log
- [Updated] Alert
- [Updated] AlphaSOC
- [Updated] AWS API Gateway
- [Updated] Bitdefender - fw
- [Updated] Bitdefender - network-monitor
- [Updated] Check Point Avanan
- [Updated] CrowdStrike Falcon - Catch DataProtectionDetectionSummaryEvent
- [Updated] CrowdStrike FDR - SuspiciousDnsRequest
- [Updated] Darktrace Parser - Catch All
- [Updated] Egnyte DLP Parser - Catch All
- [Updated] FireEye CMS DM
- [Updated] FireEye CMS IM
- [Updated] FireEye CMS Malware Callback
- [Updated] FireEye CMS RC
- [Updated] FireEye CMS RO
- [Updated] FireEye CMS WI
- [Updated] FireEye MPS Malware Object
- [Updated] Firepower Catch All
- [Updated] Firepower File Malware Events
- [Updated] Firepower Intrusion Events
- [Updated] Firepower Primary Detection Engine Intrusion Events
- [Updated] Firepower Snort Alerts
- [Updated] Fortinet Anomaly Logs
- [Updated] Fortinet DLP Logs
- [Updated] Fortinet Virus
- [Updated] Google Workspace Alert Center - Data Loss Prevention
- [Updated] Google Workspace Alert Center - Domain wide takeout
- [Updated] Google Workspace Alert Center - Gmail phishing
- [Updated] Google Workspace Alert Center - Gmail phishing (Misconfigured whitelist)
- [Updated] IBM Guardium Logs
- [Updated] Kemp WAF Message
- [Updated] Microsoft Graph Security API C2C - Dynamic Vendor/Product - Microsoft IPC
- [Updated] Microsoft Graph Security API C2C - Dynamic Vendor/Product - Microsoft Office 365 Security and Compliance
- [Updated] Microsoft Office 365 Active Directory Authentication Events
- [Updated] Microsoft Office 365 Threat Intelligence Atp Content Events
- [Updated] Microsoft Office 365 Threat Intelligence Events
- [Updated] Microsoft Office 365 Threat Intelligence Url Events
- [Updated] Mimecast Targeted Threat Protection Logs
- [Updated] Netskope - Alerts
- [Updated] Netskope - DLP Alerts
- [Updated] Office 365 - Compliance DLP Exchange Item Events
- [Updated] Office 365 - Compliance DLP SharePoint
- [Updated] Office 365 - Security Compliance Alerts
- [Updated] Palo Alto Threat Scan - Custom Parser
- [Updated] Palo Alto Threat Spyware - Custom Parser
- [Updated] Palo Alto Threat Virus - Custom Parser
- [Updated] Proofpoint TRAP Default Mapping
- [Updated] Thinkst Canary Parser - Catch All
- [Updated] Trend Micro Control Manager CEF CnC
- [Updated] Varonis Alerts Catch All
- [Updated] Varonis DatAdvantage - CEF
- [Updated] Varonis DatAlert - Parser
- [Updated] Vectra AI Catch All
- [Updated] Vectra AI User Login
- [Updated] Vectra Cognito Catch All
Parsers
- [New] /Parsers/System/AWS/AWS API Gateway
- [New] /Parsers/System/Check Point/Check Point CloudGuard
Schema
- [New] fromUser_accessId
- [New] targetUser_accessId
- [New] user_accessId
