Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
97 changes: 97 additions & 0 deletions blog-cse/2026-08-04-content.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,97 @@
---
title: August 4th, 2026 - Content Release
hide_table_of_contents: true
keywords:
- log mappers
- parsers
- schema
image: https://assets-www.sumologic.com/company-logos/_800x418_crop_center-center_82_none/SumoLogic_Preview_600x600.jpg?mtime=1617040082
---

import useBaseUrl from '@docusaurus/useBaseUrl';

# Content Release 2026-08-04

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

None of the prior content-release posts (2026-07-14, 2026-06-25, 2026-06-12) have a body-level # Content Release ... heading — they start directly with **Important Notice**. The frontmatter title already renders as the page's H1 via the blog template, so this line will likely produce a duplicate title on the page. Suggest removing it.


**Important Notice**

This release delivers the Runtime and Identity phase of the Normalized Detection rule migration announced in the 2026-07-14 content release. Log mappings for these sources no longer contribute to the Normalized Security Signal passthrough rule (MATCH-S00402) and instead route to MATCH-S01159 (Normalized Runtime Detection) and MATCH-S01161 (Normalized Identity Detection). Custom content built on MATCH-S00402 for these vendors — tuning expressions, custom insights, and rule tuning — needs to be migrated to the new rules.

Additionally, Legacy Threat Intelligence rules using the 'threat' match list have been renamed to reflect their pending deprecation in favor of the current threat intelligence rules using the hasThreatMatch operator which have been available for over a year. The legacy rules will continue to function, but they will be removed in a future content release and the feature will cease to work. Customers should migrate any custom content built on the legacy rules to the current threat intelligence rules.

**Remaining target dates:**

- **August 13 — Network and Data Protection sources**
- **August 27 — Cloud and Endpoint sources**

## This content release includes

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Every prior post uses a single bullet with nested sub-bullets here, not an H2 + flat list:

* This content release includes:
    - item
    - item

Worth matching that pattern instead of ## This content release includes followed by a flat - item list, for consistency across releases.

- Runtime detections from Falco, Sysdig Secure, Twistlock (Prisma Cloud Compute), Aqua Security, and Contrast ADR now route to the Normalized Runtime Detection rule (MATCH-S01159) rather than the general passthrough rule, giving container and application runtime alerts their own tunable rule
- Identity detections from Azure AD Identity Protection, Microsoft Azure Advanced Threat Protection, Microsoft Defender for Cloud Apps, Google Workspace Alert Center, Okta, Slack, Box, DocuSign Monitor, Salesforce, and CrowdStrike Identity Protection now route to the Normalized Identity Detection rule (MATCH-S01161)
- MITRE ATLAS technique tags added to existing AI and LLM detection rules covering AWS Bedrock, Anthropic Claude, and GitHub Copilot, so signals from AI platform activity carry adversarial AI technique context alongside existing MITRE ATT&CK tagging
- Legacy Threat Intel rules renamed and their descriptions updated to identify them as legacy and note their pending deprecation in favor of the current threat intelligence rules using the hasThreatMatch operator.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Minor: this item (and the "Removed the Windows Defender SCCM grok parser..." item below) ends with a trailing period, but every other item in this list doesn't. Prior posts consistently omit trailing periods on these summary bullets — worth dropping both for consistency.

- Removed a redundant device IP mapping from the Cloudflare Logpush mapper so device and source device fields are no longer populated from the same input value
- Updated Check Point Firewall JSON parsing to fall back to the firewall subproduct field when the primary product field is absent, improving vendor and product identification
- Removed the Windows Defender SCCM grok parser and mapper as the parser was generating entirely false positive matches across Sumo Logic Cloud SIEM customers.
- Changes are enumerated below

## Rules
- [Updated] THRESHOLD-S00125 AWS Bedrock - Knowledge Base Mass Deletion
- [Updated] MATCH-S01151 AWS Bedrock - Privileged Permissions Granted
- [Updated] CHAIN-S00026 AWS Bedrock - Privileged Policy Created and Attached
- [Updated] MATCH-S00922 AWS Bedrock Agent Created
- [Updated] MATCH-S00924 AWS Bedrock Guardrail Deleted
- [Updated] MATCH-S00923 AWS Bedrock Model Invocation Denied for User
- [Updated] MATCH-S00921 AWS Bedrock Model Invocation Logging Configuration Change Observed
- [Updated] MATCH-S01155 Claude Compliance API Logging Disabled
- [Updated] FIRST-S00084 First Seen AWS Bedrock API Call from User
- [Updated] FIRST-S00081 First Seen Model ID in AWS Bedrock Put Entitlement by User
- [Updated] FIRST-S00085 First Seen Role Creating AWS Bedrock Agent
- [Updated] FIRST-S00082 First Seen User Enumerating AWS Bedrock Models
- [Updated] FIRST-S00100 First Seen User Enumerating Custom AWS Bedrock Models
- [Updated] MATCH-S00954 GitHub - Copilot Seat Cancelled by GitHub
- [Updated] LEGACY-S00110 Legacy Threat Intel - Device IP Matched Threat Intel Domain Name
- [Updated] LEGACY-S00111 Legacy Threat Intel - Device IP Matched Threat Intel URL
- [Updated] MATCH-S00555 Legacy Threat Intel - Inbound Traffic Context
- [Updated] LEGACY-S00109 Legacy Threat Intel - Matched Domain Name
- [Updated] LEGACY-S00108 Legacy Threat Intel - Matched File Hash
- [Updated] MATCH-S00815 Legacy Threat Intel - Successful Authentication from Threat IP
- [Updated] LEGACY-S00107 Legacy Threat Intel Match - IP Address
- [Updated] MATCH-S01163 Normalized Data Protection Detection
- [Updated] MATCH-S01159 Normalized Runtime Detection
- [Updated] OUTLIER-S00019 Outlier in AWS Bedrock API Calls from User
- [Updated] OUTLIER-S00022 Outlier in AWS Bedrock Foundation Model Enumeration Calls from User

## Log Mappers
- [Updated] Aqua Access Control
- [Updated] Aqua Runtime Policy Match
- [Updated] Azure Risky Users
- [Updated] Azure User Risk Events
- [Updated] Box - SHIELD_ALERT
- [Updated] Cloudflare - Logpush
- [Updated] Contrast Security ADR Default Mapping
- [Updated] CrowdStrike Falcon Host API IdpDetectionSummaryEvent
- [Updated] CrowdStrike Falcon Host API IdpDetectionSummaryEvent (CNC)
- [Updated] CrowdStrike Falcon Identity Protection
- [Updated] CrowdStrike Falcon Identity Protection (CNC)
- [Updated] DocuSign Monitor - Alert
- [Updated] Falco Detection JSON
- [Updated] Google Workspace Alert Center - AppMaker Editor
- [Updated] Google Workspace Alert Center - Google Operations
- [Updated] Google Workspace Alert Center - Google identity
- [Updated] Google Workspace Alert Center - Security Center rules
- [Updated] Google Workspace Alert Center - State Sponsored Attack
- [Updated] Microsoft Cloud App Security - Direct
- [Updated] Microsoft Graph Identity Protection API C2C - riskDetections
- [Updated] Microsoft Graph Identity Protection API C2C - riskyUsers
- [Updated] Microsoft Graph Security API C2C - Dynamic Vendor/Product - Azure Advanced Threat Protection
- [Updated] Microsoft Graph Security API C2C - Dynamic Vendor/Product - Microsoft Defender for Cloud Apps
- [Updated] Okta Security Threat Events
- [Updated] Salesforce Normalized Security Signal Passthrough
- [Updated] Slack Anomaly Event
- [Updated] Sysdig Policy Detection JSON
- [Updated] Twistlock Container Runtime Audit

## Parsers
- [Updated] /Parsers/System/Check Point/Check Point Firewall JSON

## Legacy Grok Parsers
- [Removed] /Parsers/System/Windows/Windows Defender SCCM
Loading