Create 2026-08-04-content.md - #6986
Conversation
|
|
||
| import useBaseUrl from '@docusaurus/useBaseUrl'; | ||
|
|
||
| # Content Release 2026-08-04 |
There was a problem hiding this comment.
None of the prior content-release posts (2026-07-14, 2026-06-25, 2026-06-12) have a body-level # Content Release ... heading — they start directly with **Important Notice**. The frontmatter title already renders as the page's H1 via the blog template, so this line will likely produce a duplicate title on the page. Suggest removing it.
| - **August 13 — Network and Data Protection sources** | ||
| - **August 27 — Cloud and Endpoint sources** | ||
|
|
||
| ## This content release includes |
There was a problem hiding this comment.
Every prior post uses a single bullet with nested sub-bullets here, not an H2 + flat list:
* This content release includes:
- item
- item
Worth matching that pattern instead of ## This content release includes followed by a flat - item list, for consistency across releases.
| - Runtime detections from Falco, Sysdig Secure, Twistlock (Prisma Cloud Compute), Aqua Security, and Contrast ADR now route to the Normalized Runtime Detection rule (MATCH-S01159) rather than the general passthrough rule, giving container and application runtime alerts their own tunable rule | ||
| - Identity detections from Azure AD Identity Protection, Microsoft Azure Advanced Threat Protection, Microsoft Defender for Cloud Apps, Google Workspace Alert Center, Okta, Slack, Box, DocuSign Monitor, Salesforce, and CrowdStrike Identity Protection now route to the Normalized Identity Detection rule (MATCH-S01161) | ||
| - MITRE ATLAS technique tags added to existing AI and LLM detection rules covering AWS Bedrock, Anthropic Claude, and GitHub Copilot, so signals from AI platform activity carry adversarial AI technique context alongside existing MITRE ATT&CK tagging | ||
| - Legacy Threat Intel rules renamed and their descriptions updated to identify them as legacy and note their pending deprecation in favor of the current threat intelligence rules using the hasThreatMatch operator. |
There was a problem hiding this comment.
Minor: this item (and the "Removed the Windows Defender SCCM grok parser..." item below) ends with a trailing period, but every other item in this list doesn't. Prior posts consistently omit trailing periods on these summary bullets — worth dropping both for consistency.
Purpose of this pull request
This pull request adds CSIEM content release notes
Select the type of change
Ticket (if applicable)