September 3rd, 2026 - Content Release
This content release includes:
- Updated Threat Intel IP rules to exclude internal destination IP addresses from triggering alerts, reducing false positives for inbound and outbound threat feed matches
- Added source device IP mapping for Microsoft Office 365 Teams events
- Fixed Proofpoint on Demand email disposition mapping to correctly populate action, normalized action, and delivery success fields
- Removed redundant device IP mapping from Suricata to prevent duplicate IP enrichment
- Additional changes are enumerated below
Rules
- [Updated] MATCH-S01024 Threat Intel - Destination IP Address (High Confidence)
- [Updated] MATCH-S01026 Threat Intel - Destination IP Address (Low Confidence)
- [Updated] MATCH-S01028 Threat Intel - Destination IP Address (Medium Confidence)
- [Updated] MATCH-S01023 Threat Intel - Inbound Traffic from Threat Feed IP (High Confidence)
- [Updated] MATCH-S01025 Threat Intel - Inbound Traffic from Threat Feed IP (Low Confidence)
- [Updated] MATCH-S01027 Threat Intel - Inbound Traffic from Threat Feed IP (Medium Confidence)
Log Mappers
- [Updated] Microsoft Office 365 Teams Events
- Added source device IP (
srcDevice_ip) mapping
- Added source device IP (
- [Updated] Proofpoint on Demand C2C - Catch All
- Fixed
actionfield to usefilter.disposition - Added
normalizedAction(allow/deny) andsuccess(true/false) lookups
- Fixed
- [Updated] Suricata - JSON
- Removed redundant
device_ipmapping
- Removed redundant