Skip to main content

September 3rd, 2026 - Content Release

This content release includes:

  • Updated Threat Intel IP rules to exclude internal destination IP addresses from triggering alerts, reducing false positives for inbound and outbound threat feed matches
  • Added source device IP mapping for Microsoft Office 365 Teams events
  • Fixed Proofpoint on Demand email disposition mapping to correctly populate action, normalized action, and delivery success fields
  • Removed redundant device IP mapping from Suricata to prevent duplicate IP enrichment
  • Additional changes are enumerated below

Rules

  • [Updated] MATCH-S01024 Threat Intel - Destination IP Address (High Confidence)
  • [Updated] MATCH-S01026 Threat Intel - Destination IP Address (Low Confidence)
  • [Updated] MATCH-S01028 Threat Intel - Destination IP Address (Medium Confidence)
  • [Updated] MATCH-S01023 Threat Intel - Inbound Traffic from Threat Feed IP (High Confidence)
  • [Updated] MATCH-S01025 Threat Intel - Inbound Traffic from Threat Feed IP (Low Confidence)
  • [Updated] MATCH-S01027 Threat Intel - Inbound Traffic from Threat Feed IP (Medium Confidence)

Log Mappers

  • [Updated] Microsoft Office 365 Teams Events
    • Added source device IP (srcDevice_ip) mapping
  • [Updated] Proofpoint on Demand C2C - Catch All
    • Fixed action field to use filter.disposition
    • Added normalizedAction (allow/deny) and success (true/false) lookups
  • [Updated] Suricata - JSON
    • Removed redundant device_ip mapping
Status
Legal
Privacy Statement
Terms of Use
CA Privacy Notice

Copyright © 2026 by Sumo Logic, Inc.