Splunk: Version 67.0
Splunk: Version 67.0 • Updated the lookback timestamp progression logic when all fetched alerts in a cycle have already been processed in the following connector: Splunk ES - Notable Events…
100 updates from Google Cloud.
Splunk: Version 67.0 • Updated the lookback timestamp progression logic when all fetched alerts in a cycle have already been processed in the following connector: Splunk ES - Notable Events…
Microsoft Teams: Version 39.0 • Updated error handling in the following job: Refresh Token Renewal Job
Palo Alto Cortex XDR: Version 32.0 • Fixed an issue where the job repeatedly logged errors when a case was merged or deleted in Google SecOps in the following job: Sync Incidents
Exchange: Version 125.0 • Updated the parsing logic for nested S/MIME email attachments (.eml) sent from macOS and Windows in the following connector: Exchange Mail Connector v2 with Oauth…
Zscaler: Version 16.0 • Fixed an issue where legacy API key and password authentication failed due to URL path normalization issues.
Proofpoint Cloud Threat Response: Version 5.0 • Fixed an issue where null, missing, or unmapped priority values in API payloads caused log ingestion errors in the following connector: Proofpoint…
Wiz: Version 9.0 • Added the following new job: Wiz and Google SecOps Bi-directional Sync Job
Pub/Sub: Version 4.0 • Added support for pubsub_message_id in the Unique ID Field parameter in the following connector: Pub/Sub - Messages Connector
CrowdStrike Falcon: Version 81.0 • Added the ability to use device IDs as input parameters in the following actions: Hide Hosts • Contain Endpoint • Download File • Execute Command • Get Host…
Cisco Umbrella: Version 21.0 • Fixed an issue in the following action where entity attachment failed due to a bytes object serialization error: Get Domain Security Info
Microsoft 365 Defender: Version 30.0 • Added support for GCC High tenants by dynamically constructing API token scopes and adding a configurable API Root parameter in the…
Microsoft Graph Mail: Version 45.0 • Fixed an issue in the following action where an unhandled exception occurred when a user mailbox was not found: Get Mailbox Account Out Of Facility Settings
Enrichment • Fixed an issue in the following action where unsupported entity types were selected during enrichment: Whois
AWS WAF: Version 14.0 • Updated integration dependencies.
Active Directory: Version 45.0 • Fixed an issue in the following action where entity properties were incorrectly reset on update: Enrich Entities
Microsoft Graph Mail: Version 45.0 • The following new actions have been added: Block Domain • Block Sender • Delete Inbox Rules • List Rules • Remove Block Domain • Remove Block Sender
CyberArk Credential Provider: Version 5.0 • The following new job has been added: Sync Integration Credentials Job
GitSync • Fixed an issue in the following action where the Include Playbook Blocks parameter was ignored when a folder allowlist was used: Push Playbook
ServiceNow: Version 70.0 • Fixed verification logic when updating reference fields in the following action: Update Incident
Microsoft Graph Mail Delegated: Version 21.0 • Updated logic for parsing email headers and S/MIME digitally signed emails in the following connector: Microsoft Graph Mail Delegated Connector
Jira: Version 61.0 • Added support for customizable status-to-closure mapping, Case-level job scope, custom field variables in Closed Reason Mapping, context value alignment to JIRA_ISSUE_KEY, and…
CrowdStrike Falcon: Version 80.0 • Implemented 500-device safety limit per entity search, updated device sorting by last_seen.desc, and added batch request chunking for device details,…
Google Chronicle: Version 92.0 • Updated the action to use new search API in the following action: Is Value in Data Table
Microsoft 365 Defender: Version 29.0 • Updated Google SecOps event structure, added support for incident tags and assignee filtering, updated ontology mapping, and optimized evidence handling with…
Google Chronicle: Version 91.0 • Updated Wiz Defend alert naming format in the following connector: Google Chronicle - Chronicle Alerts Connector
Google Threat Intelligence: Version 20.0 • Added support for CHILDHASH and PARENTHASH entity types in the following action: Enrich Entities Added Entity Type Filter parameter to allow configuring…
Vertex AI: Version 8.0 • Added support for multi-region endpoints across the integration configuration.
Active Directory: Version 44.0 • Added optional Connection Timeout and Receive Timeout parameters to configure network connectivity limits in the following action: Enrich Entities
Microsoft 365 Defender: Version 28.0 • Updated case syncing logic in the following action: Sync Alerts Updated alert processing logic in the following connector: • Microsoft 365 Defender -…
Anomali ThreatStream: Version 18.0 • Updated API output handling in the following action: Enrich Entities
Siemplify: Version 112.0 • Added Update Enabled Connectors Only filtering option in the following job: Response Integration & Connector Upgrade Job
SentinelOne Singularity Operations Center: Version 1.0 • Added SentinelOne Singularity Operations Center integration.
Jira: Version 60.0 • Added support for the Created Before date filter and Custom JQL query parameter in the following action: List Issues
Proofpoint Email Protection: Version 10.0 • Added the following action: Download Quarantined Email
Azure Monitor: Version 5.0 • Updated integration documentation links in the integration configuration.
Wiz: Version 14.0 • Added the following action: Get Blue Agent Analysis
QRadar: Version 69.0 • Updated timestamp filtering to use last_persisted_time for tracking modifications in the following connector: Qradar Offenses Connector
Google Chronicle: Version 90.0 • Updated handling of Wiz Defend detections and ontology mapping in the following connector: Chronicle Alerts Connector
Microsoft Defender ATP: Version 33.0 • Updated execution processing logic to improve backend tracking stability in the following action: Execute Live Response Command
CrowdStrike Falcon: Version 78.0 • Fixed pagination loop logic to prevent infinite timeouts during high-volume sweeps in the following action: Get Host Information
AWS GuardDuty: Version 14.0 • Added support for Google Cloud Web Identity (OIDC) Federation authentication.
Google Threat Intelligence: Version 18.0 • Added an optional Active Group parameter to support multi-tenant organization context routing in the integration configuration and the following…
ServiceNow: Version 68.0 • Updated affected CIs processing logic to handle missing reference keys smoothly in the following job: Sync Incidents Job
Google Chronicle: Version 88.0 • Added api_root parameter to alert extensions to expand normalization metadata options in the following connector: Chronicle Alerts Connector
SCC Enterprise: Version 22.0 • Refactored integration code to optimize underlying execution performance.
Google Threat Intelligence: Version 17.0 • Fixed widget rendering failures by escaping raw HTML script tags within extended_response_body in the following action: Get ASM Entity Details
Google Chronicle: Version 87.0 • Improved case and alert synchronization logic by fixing the verification handling of valid external ID values in the following job: Google Chronicle Sync Job
FileUtilities: Version 27.0 • Added support for extracting files from .7z archives in the following action: Extract Zip Files
CrowdStrike Falcon: Version 77.0 • Updated syncing logic to support multiple CrowdStrike alert IDs mapped to a single SecOps alert and improved error handling for alert ID context values in the…
Siemplify: Version 110.0 • Updated results processing logic to cleanly escape backslashes in the following action: Create Gemini Case Summary
FireEye Helix: Version 20.0 • Added Trellix IAM OAuth authentication support.
EmailV2: Version 42.0 • Updated default values for IMAP server address, port, username, and password for the following connector: Generic IMAP Email Connector
Azure Active Directory: Version 29.0 • Updated error handling for sign-in activity retrieval in the following action: Enrich User
Palo Alto Cortex XDR: Version 30.0 • The following new action has been added: Download File
Google Cloud Compute: Version 19.0 • Refactored action code in the following actions: Add IP To Firewall Rule • Remove external IP addresses • Execute VM Patch Job • Update Firewall Rule
VirusTotalV3: Version 41.0 • Updated Predefined Widgets to fix cached fallback rendering in the following actions: Enrich Hash • Enrich IOC • Enrich IP • Enrich URL • Get Domain Details
CyberArk PAM: Version 11.0 • The following new action has been added: Change Account Password
Google Threat Intelligence: Version 16.0 • Updated Predefined Widgets to optimize loading performance and aligned layouts to prevent visual shifts in the following actions: Enrich Entities •…
Secret Manager: Version 2.0 • Updated action description in the following action: Ping
FireEye ETP: Version 9.0 • Added Trellix OAuth support, updated public API endpoints to v2, and removed legacy V1 API support.
Secret Manager: Version 1.0 • New Secret Manager integration.
Source code is now publicly available on <a href="https://github.com/chronicle/content-hub">GitHub</a> for the following integrations: • AlienVault USM Appliance: Version 29.0 • AlienVaultTI:…
Google Chronicle: Version 86.0 • Fixed an issue where the connector would idle or hang on heartbeats instead of breaking early when nextPageToken or nextPageStartTime is received, and updated…
Palo Alto Cortex XDR: Version 29.0 • Updated host name extraction logic in the raw payload in the following connector: Palo Alto Cortex XDR Connector
Siemplify: Version 109.0 • Refactored the code in the following action: Attach Playbook to Alert
Qualys VM: Version 28.0 • Fixed AttributeError during parsing of multiple host lists and added fallback hostname matching in the following actions: List Endpoint Detections • Enrich Host
Microsoft Graph Mail: Version 42.0 • Updated the logic for robust handling of transient upstream API errors and connection issues in the following connector: Microsoft Graph Mail Connector
Google Chronicle: Version 85.0 • Updated partial batch handling and added dynamic batch sizing to prevent timeout loops, refactored logging and added monitoring signals for process health, and…
Microsoft Azure Sentinel: Version 64.0 • Announced deprecation notice. Connector will be deprecated on 30th March 2027. Only critical bug fixes will be considered. For more information refer to the…
Microsoft Defender ATP: Version 32.0 • Announced deprecation notice. Connector will be deprecated on 30th March 2027. Only critical bug fixes will be considered. For more information refer to the…
Azure Security Center: Version 17.0 • Announced deprecation notice. Connector will be deprecated on 30th March 2027. Only critical bug fixes will be considered. For more information refer to the…
Microsoft Graph Security: Version 27.0 • Announced deprecation notice. Connector will be deprecated on 30th March 2027. Only critical bug fixes will be considered. For more information refer to the…
Protectwise: Version 7.0 • Refactored the code in the following action: Get Pcap
Google Cloud IAM: Version 20.0 • Updated Predefined Widgets in the following widgets: List Roles • List Service Accounts
ConnectWise: Version 23.0 • Refactored the code for the following action: Create Alerts Ticket
ServiceNow: Version 67.0 • Refactored the code for the following action: Create Alert Incident
ServiceDesk PlusV3: Version 10.0 • Refactored the code for the following action: Create Alert Request
Siemplify: Version 245.0 • Refactored internal code execution logic for the platform integration.
ServiceDesk Plus: Version 10.0 • Refactored the code for the following action: Create Alert Request
Microsoft Sentinel Incident Tracking Connector: Version 29.0 • Added the Incident Creation Time Filter (days) advanced parameter and optimized error handling logic.
AlienVault USM Appliance: Version 28.0 • Refactored the code for the following action: Get PCAP Files For Events
MISP: Version 275.6 • Refactored internal code execution logic and optimized core integration components.
Jira: Version 58.0 • Refactored the code for the following action: Create Alert Issue
Google Chronicle: Version 84.0 • Refactored the code for the following action: Get Detection Details
Service Desk Plus: Version 9.0 • Refactored the code for the following action: Create Alert Request
Tanium: Version 20.0 • Integration: Added a partner header to all API requests.
Google Chronicle: Version 83.0 • Added support for filtering alerts by rule type to the following connector: Google Chronicle - Chronicle Alerts Connector
AlienVault USM Appliance: Version 27.0 • Refactored the code for the following action: Get PCAP Files For Events
ServiceNow: Version 66.0 • Updated the code for the following action: Update Incident: Added support for updating reference fields.
Protectwise: Version 6.0 • Refactored the code for the following action: Get Pcap
ConnectWise: Version 22.0 • Refactored the code for the following action: Create Alerts Ticket
Azure Active Directory: Version 28.0 • Integration: Updated TIPCommon to 2.3.8.
EmailV2: Version 41.0 • Integration: Updated TIPCommon to 2.3.8 and migrated EnvironmentCommon imports to TIPCommon.envcommon.
Jira: Version 57.0 • Refactored the code for the following action: Create Alert Issue
Google Chronicle: Version 82.0 • Integration: Improved memory efficiency to prevent OOM crashes when querying large timeframes for Lookup Similar Alerts. • Updated the code for the following…
ServiceNow: Version 65.0 • Refactored the code for the following action: Create Alert Incident
MITRE ATT&CK: Version 19.0 • Integration: Updated TIPCommon to 2.3.8.
Palo Alto Next Gen Firewall: Version 29.0 • Integration: Updated Manager to reuse the API token instead of generating a new one.
Azure Active Directory: Version 27.0 • Updated enrichment logic to ensure id is fetched when Include Last Sign In Details is enabled in the following action: Enrich User