Skip to main content

August 17th, 2026 - Content Release

  • This content release includes:
    • New Check Point CloudGuard log mapper and parser for cloud security posture monitoring
    • New AWS API Gateway parser with enhanced field extraction to support additional log formats
    • Updated Threat Intel IP rules with adjusted severity scoring and improved signal descriptions for high, medium, and low confidence indicators
    • Continued migration of log mappers from the direct security passthrough rule (MATCH-S00402) to the new normalized detection classes (Runtime, Identity, Network, Data Protection), adding the threat_ruleType field for consistent threat categorization. Impacted products:
      • Runtime: AlphaSOC, Aqua, Contrast ADR, CrowdStrike FDR, Falco, Sysdig, Twistlock
      • Identity: Azure, Box, CrowdStrike Falcon, Darktrace, DocuSign Monitor, Google Workspace Alert Center, Microsoft Cloud App Security, Microsoft Graph Identity Protection, Okta, Salesforce, Slack
      • Network: Bitdefender, Check Point CloudGuard, Cisco Firepower, Claroty xDome, FireEye, Fortinet, Kemp, Microsoft Graph Security API, Office 365, Palo Alto, Trend Micro, Vectra, Vectra AI, Windows Defender
      • Data Protection: Akamai CPC, Check Point Avanan, Egnyte, Fortinet DLP, Google Workspace Alert Center (DLP), IBM Guardium, Microsoft Graph Security (IPC/O365 Compliance), Mimecast, Netskope, Noname API Security, Office 365 (DLP/Compliance), Proofpoint TRAP, Thinkst Canary, Varonis
    • New schema fields (user_accessId, fromUser_accessId, targetUser_accessId) for tracking access key identifiers across user contexts
    • Additional changes are enumerated below

Rules

  • [Updated] MATCH-S00455 O365 - Successful Authentication with PowerShell User Agent
  • [Updated] MATCH-S01024 Threat Intel - Destination IP Address (High Confidence)
  • [Updated] MATCH-S01026 Threat Intel - Destination IP Address (Low Confidence)
  • [Updated] MATCH-S01028 Threat Intel - Destination IP Address (Medium Confidence)
  • [Updated] MATCH-S01023 Threat Intel - Inbound Traffic from Threat Feed IP (High Confidence)
  • [Updated] MATCH-S01025 Threat Intel - Inbound Traffic from Threat Feed IP (Low Confidence)
  • [Updated] MATCH-S01027 Threat Intel - Inbound Traffic from Threat Feed IP (Medium Confidence)

Log Mappers

  • [New] Check Point CloudGuard
  • [Updated] Akamai CPC
  • [Updated] Akamai Noname API Security Insight Log
  • [Updated] Alert
  • [Updated] AlphaSOC
  • [Updated] AWS API Gateway
  • [Updated] Bitdefender - fw
  • [Updated] Bitdefender - network-monitor
  • [Updated] Check Point Avanan
  • [Updated] CrowdStrike Falcon - Catch DataProtectionDetectionSummaryEvent
  • [Updated] CrowdStrike FDR - SuspiciousDnsRequest
  • [Updated] Darktrace Parser - Catch All
  • [Updated] Egnyte DLP Parser - Catch All
  • [Updated] FireEye CMS DM
  • [Updated] FireEye CMS IM
  • [Updated] FireEye CMS Malware Callback
  • [Updated] FireEye CMS RC
  • [Updated] FireEye CMS RO
  • [Updated] FireEye CMS WI
  • [Updated] FireEye MPS Malware Object
  • [Updated] Firepower Catch All
  • [Updated] Firepower File Malware Events
  • [Updated] Firepower Intrusion Events
  • [Updated] Firepower Primary Detection Engine Intrusion Events
  • [Updated] Firepower Snort Alerts
  • [Updated] Fortinet Anomaly Logs
  • [Updated] Fortinet DLP Logs
  • [Updated] Fortinet Virus
  • [Updated] Google Workspace Alert Center - Data Loss Prevention
  • [Updated] Google Workspace Alert Center - Domain wide takeout
  • [Updated] Google Workspace Alert Center - Gmail phishing
  • [Updated] Google Workspace Alert Center - Gmail phishing (Misconfigured whitelist)
  • [Updated] IBM Guardium Logs
  • [Updated] Kemp WAF Message
  • [Updated] Microsoft Graph Security API C2C - Dynamic Vendor/Product - Microsoft IPC
  • [Updated] Microsoft Graph Security API C2C - Dynamic Vendor/Product - Microsoft Office 365 Security and Compliance
  • [Updated] Microsoft Office 365 Active Directory Authentication Events
  • [Updated] Microsoft Office 365 Threat Intelligence Atp Content Events
  • [Updated] Microsoft Office 365 Threat Intelligence Events
  • [Updated] Microsoft Office 365 Threat Intelligence Url Events
  • [Updated] Mimecast Targeted Threat Protection Logs
  • [Updated] Netskope - Alerts
  • [Updated] Netskope - DLP Alerts
  • [Updated] Office 365 - Compliance DLP Exchange Item Events
  • [Updated] Office 365 - Compliance DLP SharePoint
  • [Updated] Office 365 - Security Compliance Alerts
  • [Updated] Palo Alto Threat Scan - Custom Parser
  • [Updated] Palo Alto Threat Spyware - Custom Parser
  • [Updated] Palo Alto Threat Virus - Custom Parser
  • [Updated] Proofpoint TRAP Default Mapping
  • [Updated] Thinkst Canary Parser - Catch All
  • [Updated] Trend Micro Control Manager CEF CnC
  • [Updated] Varonis Alerts Catch All
  • [Updated] Varonis DatAdvantage - CEF
  • [Updated] Varonis DatAlert - Parser
  • [Updated] Vectra AI Catch All
  • [Updated] Vectra AI User Login
  • [Updated] Vectra Cognito Catch All

Parsers

  • [New] /Parsers/System/AWS/AWS API Gateway
  • [New] /Parsers/System/Check Point/Check Point CloudGuard

Schema

  • [New] fromUser_accessId
  • [New] targetUser_accessId
  • [New] user_accessId
Status
Legal
Privacy Statement
Terms of Use
CA Privacy Notice

Copyright © 2026 by Sumo Logic, Inc.