Skip to content

Create 2026-08-04-content.md - #6986

Open
jc-sumo wants to merge 1 commit into
SumoLogic:mainfrom
jc-sumo:csiem-content-08-04-2026
Open

Create 2026-08-04-content.md#6986
jc-sumo wants to merge 1 commit into
SumoLogic:mainfrom
jc-sumo:csiem-content-08-04-2026

Conversation

@jc-sumo

@jc-sumo jc-sumo commented Aug 4, 2026

Copy link
Copy Markdown
Collaborator

Purpose of this pull request

This pull request adds CSIEM content release notes

Select the type of change

  • Minor Changes - Typos, formatting, slight revisions
  • Update Content - Revisions, updating sections
  • New Content - New features, sections, pages, tutorials
  • Site and Tools - .clabot, version updates, maintenance, dependencies, new packages for the site (Docusaurus, Gatsby, React, etc.)

Ticket (if applicable)

@jc-sumo jc-sumo self-assigned this Aug 4, 2026
@cla-bot cla-bot Bot added the cla-signed Contributor approved, listed in .clabot file label Aug 4, 2026

import useBaseUrl from '@docusaurus/useBaseUrl';

# Content Release 2026-08-04

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

None of the prior content-release posts (2026-07-14, 2026-06-25, 2026-06-12) have a body-level # Content Release ... heading — they start directly with **Important Notice**. The frontmatter title already renders as the page's H1 via the blog template, so this line will likely produce a duplicate title on the page. Suggest removing it.

- **August 13 — Network and Data Protection sources**
- **August 27 — Cloud and Endpoint sources**

## This content release includes

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Every prior post uses a single bullet with nested sub-bullets here, not an H2 + flat list:

* This content release includes:
    - item
    - item

Worth matching that pattern instead of ## This content release includes followed by a flat - item list, for consistency across releases.

- Runtime detections from Falco, Sysdig Secure, Twistlock (Prisma Cloud Compute), Aqua Security, and Contrast ADR now route to the Normalized Runtime Detection rule (MATCH-S01159) rather than the general passthrough rule, giving container and application runtime alerts their own tunable rule
- Identity detections from Azure AD Identity Protection, Microsoft Azure Advanced Threat Protection, Microsoft Defender for Cloud Apps, Google Workspace Alert Center, Okta, Slack, Box, DocuSign Monitor, Salesforce, and CrowdStrike Identity Protection now route to the Normalized Identity Detection rule (MATCH-S01161)
- MITRE ATLAS technique tags added to existing AI and LLM detection rules covering AWS Bedrock, Anthropic Claude, and GitHub Copilot, so signals from AI platform activity carry adversarial AI technique context alongside existing MITRE ATT&CK tagging
- Legacy Threat Intel rules renamed and their descriptions updated to identify them as legacy and note their pending deprecation in favor of the current threat intelligence rules using the hasThreatMatch operator.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Minor: this item (and the "Removed the Windows Defender SCCM grok parser..." item below) ends with a trailing period, but every other item in this list doesn't. Prior posts consistently omit trailing periods on these summary bullets — worth dropping both for consistency.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

cla-signed Contributor approved, listed in .clabot file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants