Change Logs

The Cyflare SOC Change Log Updates page comprehensively records all modifications and enhancements to the Cyflare Security Operations Center (SOC) platform. Stay informed about the latest improvements and changes that impact your cybersecurity strategy and SOC operations.

June 2026

###### Category ###### Completed Items
Alert Tuning - No changes
New Detections - No changes
New Features - No changes
Playbook Enhancement - mEDR (SentinelOne): Playbook Auto-Close for “No Action Needed” Alerts
- Added CEM determination block to auto-close SentinelOne alerts marked “No Action Needed”.
- mXDR (Stellar): SOAR Alert Deduplication Logic Adjustment
- Adjusted the deduplication logic to skip the deduplication when there is only one matched entity and it’s not a username. If the entity is a username, the deduplication logic will continue as there is confidenc the alerts are related.
Template Updates - No changes
Response Action - No changes
Other - No changes

May 2026

###### Category ###### Completed Items
Alert Tuning - Defender DigiCert False Positive
- Excluded Defender alerts from a false positive detections involving legitimate and signed DigiCert hashes
New Detections - No changes
New Features - No changes
Playbook Enhancement - mXDR (Stellar): Conditional Access Blocked Login Enrichment
- Adds recent successful source IPs (last 24h) and detailed geo (region/city) into tickets.
- mVSS (Vicarius): Escalation Policy Update (KEV-Only by Default)
- Default escalations now limited to Known Exploited Vulnerabilities; clients can opt in for all Vicarius alerts.
Template Updates - No changes
Response Action - No changes
Other - No changes

April 2026

###### Category ###### Completed Items
Alert Tuning - mXDR (Stellar): AWS – Create User added to Alert Preferences
- Informational Alert type AWS – Create User added to alert preferences, this is set by default to “Off” to prevent escalation.
- mEDR (SentinelOne): Excluding Dell’s SupportAssist Remediation Detections
- Dell’s SupportAssist Remediation component generates consistent low-fidelity noise; predominantly backup artifacts from standard Dell processes with no history of actionable detections.
- mEDR (SentinelOne): Office Click to Run
- Excluding certain versions of OfficeClickToRun for false positive detections
- mXDR (Stellar): Creation of Forwarding or Redirect Rule Query Update
- Improved alert query to increase the fidelity of suspicious inbox creation events for New-InboxRule operations
New Detections - mEDR (SentinelOne): Potential TrustConnect RAT Installed
- Detects activity related to the TrustConnect remote access trojan (RAT) masquerading as an RMM tool.
- mXDR (Stellar): Suspicious Download Via Certutil.exe
- Detects the execution of certutil with certain flags that allow the utility to download files.
- mXDR (Stellar): Rubeus Hacktool Execution
- Detects the execution of the hacktool Rubeus via PE information of command line parameters.
- mXDR (Stellar): Process Memory Dump Via Comsvcs
- Detects a process memory dump via “comsvcs.dll” using rundll32, covering multiple different techniques (ordinal, minidump function, etc.)
- mXDR (Stellar): Bypass UAC via Fodhelper
- Identifies use of Fodhelper.exe to bypass User Account Control. Adversaries use this technique to execute privileged processes.
- mXDR (Stellar): Suspicious Process Created by mshta.exe
- A suspicious process process has been created by mshta.exe. This can indicate an attacker is using built-in Windows functionality to perform malicious activity.
- mXDR (Stellar): Wscript Shell Run In CommandLine
- Detects the presence of the keywords “Wscript”, “Shell” and “Run” in the command, which could indicate a suspicious activity
New Features - No changes
Playbook Enhancement - No changes
Template Updates - Vicarius Ticket Escalation Updated to v2 Template
- Now will escalate Vicarius alerts using the v2 ticket template for consistent triage and handling.
Response Action - No changes
Other - No changes

March 2026

###### Category ###### Completed Items
Alert Tuning - No changes
New Detections - mES (CheckPoint): Checkpoint Harmony Email Connector (Shadow IT & Anomaly Alerts)
- Connector now ingests Shadow IT and Anomaly alerts when requested.
- mXDR (Stellar): Suspicious Process Created by mshta.exe
- A suspicious process process has been created by mshta.exe. This can indicate an attacker is using built-in Windows functionality to perform malicious activity.
- mXDR (Stellar): Wscript Shell Run In CommandLine
- Detects the presence of the keywords “Wscript”, “Shell” and “Run” in the command, which could indicate a suspicious activity
New Features - Compromised Account Ticket Disposition
- Added the ability to disposition tickets as “TP – Compromised Account”, allowing incidents of this nature to be categorized more accurately and improving reporting of account compromise events.
Playbook Enhancement - CrowdStrike Playbook Enhancement for Third-Party Alerts
- Added logic to parse third-party alert fields, preventing blank data and improving processing.
- SOAR Travel Advisory Normalization for Azure AD & JumpCloud Alerts
- Added logic to convert country codes to names, improving travel advisory matching for alerts.
- SOAR CrowdStrike Automated Leads Triage
- CrowdStrike Automated Leads alerts now triage by default when score is above 45 for all clients.
Template Updates - Visual redesign of SentinelOne EDR Singular Ticket Template
Response Action - No changes
Other - No changes

February 2026

###### Category ###### Completed Items
Alert Tuning - No changes
New Detections - mXDR (Stellar): Outbound Spam Anomaly
- Detects anomalous, high-volume, or malicious outbound email, often signaling compromised accounts indicated by “HygieneTenantEvents”.
- mXDR (Stellar): Notepad Updater DNS Query to Uncommon Domains
- Detects when the Notepad++ updater (gup.exe) makes DNS queries to domains that are not part of the known legitimate update infrastructure.
- mXDR (Stellar): Suspicious Child Process of Notepad Updater GUP.Exe
- Detects suspicious child process creation by the Notepad++ updater process (gup.exe).
- mXDR (Stellar): Uncommon File Created by Notepad Updater Gup.exe
- Detects when the Notepad++ updater (gup.exe) creates files in suspicious or uncommon locations.
- mXDR (Stellar): DNS TXT Answer with Possible Execution Strings
- Detects suspicious command strings that were detected in a DNS TXT response answer.
- mXDR (Stellar): Potential Teams Chat Phishing Attempt
- A suspicious external user created a Teams chat with a user in your organization, potentially imitating internal support to obtain credentials or gain remote access to the endpoint.
New Features - No changes
Playbook Enhancement - No changes
Template Updates - No changes
Response Action - No changes
Other - No changes

January 2026

###### Category ###### Completed Items
Alert Tuning - No changes
New Detections - mXDR (Stellar): Suspicious Script Dropped in Startup Location
- Detects scripts dropped in the AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ file path.
- mXDR (Stellar): Suspicious Rundll32 Activity Invoking Sys File
- Detects suspicious process related to rundll32 based on command line that includes a *.sys file.
- mXDR (Stellar): Sonicwall User Created
- Detects a new user was created on a Sonicwall device. Verify if this is expected and approved activity.
- mXDR (Stellar): Fortigate Firewall Local User Account Created
- This detection identifies the creation of a local user account on a FortiGate firewall by looking for log entries where the msg field contains “user.local” and the action is “Add” within FortiGate logs.
- mXDR (Stellar): Suspicious Fortigate Log Settings Modification
- The log settings on a FortiGate firewall have been modified. This may indicate potential unauthorized configuration changes.
New Features - No changes
Playbook Enhancement - mXDR (Stellar): Down Sensor Playbook
- Added the alert start time as an entity for sensor down alerts, and created and added the down sensor context value block to the playbook.
- mXDR (Stellar): User Impossible Travel Playbook
- Added an additional check under the IP Location and Verification block for the User Impossible Travel alert to ensure that each source IP (srcip1 and srcip2) is assigned the correct location, preventing mismatched locations in Impossible Travel Anomaly alerts.
- Correlation search now looks 5 min after the Impossible travel alert.
- Splunk Generic Playbook
- Added the “Splunk CTI Enrichment Block”. This will now bring OSINT results for alerts that have an IP address.
Template Updates - No changes
Response Action - No changes
Other - No changes

2025 Change Logs by Month

January 2025

###### Category ###### Completed Items
Playbook Enhancement - Microsoft Entra Changes to Privileged Account:
- The updated workflow logic now correlates the Azure AD default fields to correlate activity with the actual privilege user account
- Exploit Anomalies:
-  Added WinRM IDS signatures enrichment, it will do a lookup between the source IP, Destination IP, source port and event ID.
- Curated playbooks have been created for the following alert types. This improves threat hunting searches, ticket escalations and custom logic:
- WMI Backdoor Exchange Transport Agent
- Potentially Malicious Windows Activity
- M365 Valid Accounts – Initial Access
- Mimecast AV Phishing
- Potentially Malicious URL Clicked Alert types:
- Playbooks now have an additional lookup to XDR tool to grab additional context about the sender and the associated subject line.
- Potential Metaspoilt activity
- Due to the higher fidelity of this alert type, the SOC will now initiate IR and escalate this alert as a Critical priority.
- EDR: SentinelOne Escalations:
- AI is now utilized to generate alert snapshots, recommend remediation actions, and provide summaries of relevant processes and IPs when available.
- Azure AD Risk Detection
- CKB lookup has been enabled, and a new travel advisory block, “Azure AD Travel Advisory Check,” has been created. This block integrates the logic for the threat name “Unlikely Travel” and the overall Azure AD risk detection alert.
- O365 Potentially Malicious URL Was Clicked
- Added enrichment for email quarantine/block status.
New Detections - XDR: Potential Impacket execution
- XDR: Potential LDAP Nightmare exploitation
- XDR: Inbox rule Azure risk correlation
Template Update - Public to Private Exploit Anomaly
- New ticket section to include use case automation to improve visibility.

February 2025

###### Category ###### Completed Items
New Features - Upgraded version XDR: Stellar cyber
- Cyflare managed stellar instances have been upgraded to 5.4.0 bringing in a few newer detections that are currently
- New Service buildout: Vicarius (VrX)
- A new playbook has been developed to ingest high and critical alerts from Vicarius, escalating cases to customers to notify them of potential threats and vulnerabilities within their environment. Additionally, this playbook will incorporate several automated response actions, which are currently under development.
- To encourage customers and utilizing the automation use cases, the SOAR playbooks now include an additional section in all applicable alert types called “SOC Response Actions”. This section includes relevant information about the action taken by the SOC and whether it was successful or not.
Playbook Enhancement - New dedicated playbooks and escalation templates have been curated for the following XDR alert types:

- LastPass Master Password Changed
- LastPass Multiple failed login attempts
- Google Workspace Account Manipulation
- Box File Marked Malicious
- Mimecast Impersonation Protect Phishing
- Microsoft Entra ID Discovery Using AzureHound
- Fortigate FW Brute Force Attempt
- Microsoft Entra App Deleted
- Suspicious Azure Device Activity
- IP Location and Verification Block
- This block will check whether the source IPs for all login and conditional access alerts originate from the US. If they do, the case will be closed automatically. Additionally, the block will verify IP locations by comparing Stellar’s location data with OSINT findings from AlienVault TI and other sources. If both sources match, Stellar’s data will be used. If they differ, the OSINT data will take precedence.
New Detections - XDR: Consent to Suspicious Application
- Looking when consent to application is referenced across a database of suspicious applications.
- XDR: Sophos XG Firewall Brute Force Attempt
- When there is 5 or more failed login attempts within 30 minutes for a user.
- XDR: OneLogin BruteForce Attempts
- Detects 10 or more failed login attempts within 5 minutes
- XDR: OneLogin Not MFA Authenticated
- Detects login to OneLogin without applying MFA
- XDR: OneLogin Login Outside US
- Detects login from outside US for OneLogin
Template Updates - XDR: Multiple Users Deleted
- Updated template to add further clarification when a single account is deleted multiple times.
Alert Tuning - XDR: Potential Metasploit Activity
- Added in alert tuning when the source IP is a listed vulnerability scanner in ONE.
Other - New Documentation: Alert Test Triggers
- Created SOP documentation to guide clients through tasks to verify telemetry and accurately trigger alerts for SentinelOne and Stellar Cyber.
- Test Triggers in EDR: EICAR Test File
- Test Triggers in XDR: Multiple User Deletions
- Test Triggers in XDR: Office 365 MFA Disabled
- Test Triggers in XDR: Email Forwarding Rule Creation

March 2025

###### Category ###### Completed Items
New Features - AI Summarization 🤖 added to the following XDR Playbooks:
- 7 CrowdStrike Detection Playbooks
- 3 Google Workspace/GSuite Playbooks
- Fortinet Admin Configuration Change
- DUO User Bypass Update
- DUO Security Failed Authentication
- Domain Controller Spoofed Authentication
- DHCP Server Anomaly
- DHCP Lease Assigned to Unauthorized Host
- DGA Resolvable
- SonicWall SOAR Integration now available for Response Actions
- SonicWall SOAR integration is now compatible for all SonicOS versions. With version 7.x and higher.
Playbook Enhancement - mXDR (Stellar): “Office 365 Successful Login Outside the US” & “Impossible User Travel Anomaly”
- Added a search for username based on the actor ID is username is “00000000-0000-0000-0000-000000000000” to further enrich missing fields imported from O365.
- mXDR (Stellar): Internal/External IDS Signature Spike Alert
- Updated playbook to include additional automation and immediate escalation.
- mXDR (Stellar): Google Workspace Deny Access Request
- New dedicated playbook and alert template created for this alert type.
- mXDR (Stellar): Private to Public Exploit Anomaly
- Created branched logic when the source IP inaccurately reflects alert name and is public.
- mEDR (SentinelOne): SentinelOne Threats
- Updated playbook and turned some manually triaged S1 cases into AI enriched cases for automated escalations.
New Detections - mXDR (Stellar): Rar Usage with Password and Compression Level
- New detection where the use of rar.exe, on the command line, to create an archive with password protection or with a specific compression level.
- mXDR (Stellar): Potential FastHTTP Client Bruteforce Attempt
- New detection where a login attempt was detected utilizing the FastHTTP client, indicating a potential brute force attack against the account.
- mXDR (Stellar): Consent to Suspicious Application
- New Detection where a user granted consent to an application that is a known suspicious OAUTH client, indicating potential malicious activity.
Template Updates - mXDR (Stellar): Potential FastHTTP Client Bruteforce Attempt
- New dedicated playbook and alert template created for this alert type.
- mXDR (Stellar): Google Workspace Alert Exfiltration Over Web Service
- New dedicated playbook and alert template created for this alert type.
Response Action - Fortigate FW Brute Force Attempt
- Enabled Use Case 1 by default to automatically block malicious IPs when triggering this alert.
- The following alert types can now leverage Use Case 1 to automatically block IPs upon detection (available upon request):
- mXDR (Stellar): Bad Source Reputation
- mXDR (Stellar): SonicFW Brute Force Attempt
- mXDR (Stellar): Sophos XG Firewall Brute Force Attempt
- mXDR (Stellar): External Port Scan
- mXDR (Stellar): External Suspected Malicious User Agent
Alert Tuning - mXDR (Stellar): Cisco Umbrella Malicious Site Access
- Auto close as benign when total bytes transferred is 0 between IPs.

April 2025

###### Category ###### Completed Items
New Features - Delayed Ingestion Check
- Cyflare is improving our ingestion efforts and efficiency by adding monitorization mechanization to ensure of average time to ingest is minimized as much as possible, so that the SOAR playbooks are able to process all Client threats immediately.
- mXDR (Stellar): Azure AD Risk Detection
- Placeholder bugs within the template and additional AI enhancements have been added for this detection type when escalating.
Playbook Enhancement - Ticket Bundling – Enhanced alert consolidation mechanisms
- A ticket bundling block has been added to the “Azure AD Risk Detection” playbook.
- It checks for any open Zoho tickets with the same username related to “Potential Account Compromise Token Theft” or “Potential Account Compromise Axios User Agent”, and bundles them to prevent duplicate tickets.
- Similarly, the same logic has been added to both the “Potential Account Compromise Token Theft” and “Potential Account Compromise Axios User Agent” playbooks. These now check for any related open “Azure AD Risk Detection” tickets in our ticketing system and add them as a comment instead of a new ticket.
- Asset Monitoring Playbook
- This playbook is created and turned on for custom asset monitoring alerts that clients send in, and tickets escalated will be treated as critical severity followed by IR.
- Raw JSON Parser
- This action parses comma-separated parameters related to inbox rules received from Stellar and converts them into a cleaner, more readable format for easier client understanding.
- Azure AD Risk Detection
- Elevated severity for generic risk event types when OS and browser of O365 logs don’t match for the user/IP.
New Detections - mXDR (Stellar): FortiManager Jsconsole Privilege Escalation
- Detects Jsconsole login attempts on the FortiGate device.
- mXDR (Stellar): Potential PowerShell C2 with Dynamic Timestamp
- Detects PowerShell using IP address and timestamp-based URLs with in-memory execution via iex and irm.
- mXDR (Stellar): PowerShell Suspicious Payload Encoded and Compressed
- Identifies the use of .NET functionality for decompression and base64 decoding combined in PowerShell scripts, which malware and security tools heavily use to de-obfuscate payloads and load into memory.
- mXDR (Stellar): WMI Firewall Rule Enabled via Netsh
- Detects the use of netsh to enable Windows Management Instrumentation (WMI) firewall rules, which may be used for remote execution or lateral movement.
- mXDR (Stellar): Potential Medusa Ransomware Process Execution
- Potential execution of the known Gaze.exe Medusa Ransomware file was detected in the environment.
- mXDR (Stellar): Zip A Folder With PowerShell For Staging In Temp
- Detects the use of living off the land tools to zip a file and stage it in the Windows temporary folder for later exfiltration.
- mXDR (Stellar): Compress Data and Lock With Password for Exfiltration With 7zip
- Detects the use of 7zip to compress or encrypt data that is collected prior to exfiltration.
- mXDR (Stellar): Compress Data and Lock With Password for Exfiltration With WINZIP
- Detects the use of winzip to compress or encrypt data that is collected prior to exfiltration.
Template Updates - mXDR (Stellar): Connected SentinelOne Alerts
- Enhanced AI Summarization capabilities
- mEDR (SentinelOne): Lateral Movement Breach
- Updated template to better reflect reasons as to why/how an endpoint was isolated by SentinelOne or the SOC Playbook.
Response Action - Cisco Meraki Use Case 1 Integration
- An all-new firewall integration has been developed by the SOAR team to expand support for various vendors under the Firewall use case automation (Use Case #1).
- With Cisco Meraki added as a supported vendor too, customers can now use API integrations to connect their existing Meraki firewalls to the SOAR platform and enable auto-block for certain malicious IPs that are flagged by the SOC as part of response actions for investigated incidents.
- The SOC supports adding IPs to a pre-defined address group, which the customer can configure to block connections if any IP from the address group is seen by the firewall. For further information, please contact your customer success manager or send an email at socir@cyflare.com.
Alert Tuning - mXDR (Stellar): Public to Private Exploit Anomaly
- Close as benign if total in-bytes = 0 indicating no successful connections as well as an additional traffic check from blocked connections.
- mXDR (Stellar): Azure AD Risk Detection
- Before closing our generic Risk and Event types we will validate the OS and Browser of the Office 365 logs for the user and IP and if they don’t match then we will escalate.
- mXDR (Stellar) & VSS (CyRisma): Exploit Anomaly Detections from Stellar
- Block created that will look at CyRisma Scans in Stellar and auto close if endpoint is not vulnerable to CVE.

May 2025

###### Category ###### Completed Items
Alert Tuning - Duo User Login Outside the US
- Excluded unspecified IPv6 addresses with no location associated with the login attempt.
New Detections - mXDR (Stellar): RDP Port Opened via Netsh Firewall Command
- Detects use of netsh to allow inbound RDP (port 3389) through Windows Firewall.
- mXDR (Stellar): Suspicious CrushFTP Child Process
- Detects suspicious child processes spawned by the CrushFTP service that may indicate exploitation of remote code execution vulnerabilities.
- mXDR (Stellar): Potential Katz Stealer User Agent
- Detects network connections with a suspicious user-agent string containing “katz-ontop”, which may indicate Katz Stealer activity.
- mXDR (Stellar): DNS Query to Katz Stealer Domain
- Detects DNS queries to domains associated with Katz Stealer malware. Katz Stealer is a malware variant that is known to be used for stealing sensitive information from compromised systems.
- mXDR (Stellar): Duo User Marked as Fraud
- Stellar OOB: Detects reported Duo fraud attempts by the user.
- mXDR (Stellar): Cloud Drive Data Exfiltration Anomaly
- Stellar OOB: An account downloaded an atypical number of files over a 24-hour period. Check the user and the targeted files.
- mXDR (Stellar): Suspicious LDAP Search Request
- Stellar OOB: A suspicious LDAP search request was observed for the first time. This behavior indicates that an attacker might be attempting to collect information from the Active Directory (AD) service.
- mXDR (Stellar): BloodHound Enumeration Activity
- Stellar OOB: The BloodHound Enumeration Activity rules are used to identify potential domain enumeration activity from BloodHound or other Active Directory data collection tools. Any one or more of these will trigger the BloodHound Enumeration Activity alert type.
- mXDR (Stellar): DNS Query to Anonymous File Upload Domains
- Stellar OOB: The DNS Query to Anonymous File Upload Domains rules are used to identify DNS queries to anonymous file upload platform domains often used for malicious purposes. Any one or more of these will trigger the DNS Query to Anonymous File Upload Domains alert type.
- mXDR (Stellar): DNS Query to External Service Interaction Domains
- Stellar OOB: The DNS Query to External Service Interaction Domains rules are used to identify DNS queries to external service interaction domains often used for out-of-band interactions after successful RCE. Any one or more of these will trigger the DNS Query to External Service Interaction Domains alert type.
- mXDR (Stellar): DNS Query to Monero Crypto Coin Mining Pool Domains
- Stellar OOB: The DNS Query to Monero Crypto Coin Mining Pool Domains rules are used to identify DNS queries to Monero crypto coin mining pool domains. Any one or more of these will trigger the DNS Query to Monero Crypto Coin Mining Pool Domains alert type.
New Features - Cross-service Intelligence Enrichment
- Cross-Service Intelligence enrichment is an advanced enrichment feature available to all customers enrolled with multiple SOC-services. This functionality – also referred to internally as “Gluebooks” – intelligently consolidates and presents additional context from other active services whenever a security ticket or alert is generated.
- New Integration: Sonicwall (SonicOS v7.x)
- SOAR Development team has released a custom-built SOAR integration for Sonicwall firewall with SonicOS v7.0 and beyond. The prior versions of Sonicwall will continue to be supported with the legacy API integration. However, the newer custom built API takes advantage of the latest Sonicwall API features and aligns well with the current security standards for all Sonicwall firewall appliances. With the addition of this integration, customers can now take advantage of automation use case #1 (Auto-block IPs over firewall) as part of the existing XDR SOC services.
Playbook Enhancement - IP Validation and Location Check
- Enhanced IP location verification through new cross reference location block which incorporates multiple OSINT sources to enhance IP geolocation accuracy and VPN context.
- MFA Registration Azure Risk Correlation
- New dedicated playbook and alert template created for this alert type.
- Inbox Rule Azure Risk Correlation
- New dedicated playbook and alert template created for this alert type.
- Potential Account Compromise Axios User Agent
- New dedicated playbook and alert template created for this alert type.
- SentinelOne through XDR
- New dedicated playbook and alert template created for this alert type.
- Possible Impacket SecretDump Remote Activity
- New dedicated playbook and alert template created for this alert type.
- Potential Impacket Execution
- New dedicated playbook and alert template created for this alert type.
- Improved AI summarization
- Improved AI summarization has been added for the following playbooks:
- 9 M365 Detection Playbooks
- Defender M365 – Generic Playbook
- Possible Impacket SecretDump Remote Activity
Template Updates - Travel Advisory SOAR Logic
- Added reasoning within the ticket template when the user is listed in the CKB, but the IP is flagged as malicious.
Other - mEDR (SentinelOne): Online Authorization
- Enabled Online Authorization in all Sites and Groups due to the Bring Your Own Installer (BYOI) vulnerability.
- SOAR Infrastructure Upgrade
- As part of our ongoing commitment to innovation and performance, we’ve completed a major upgrade of our SOAR platform to the new Google SecOps environment. While this transition brings minimal changes to the user interface, it significantly enhances the platform’s infrastructure offering improved scalability, reliability, and tighter integration with the broader suite of Google services.

June 2025

###### Category ###### Completed Items
Alert Tuning - mXDR (Stellar): Microsoft 365 XDR Anomaly
- Excluded escalations when Spam, Phishing attempts, or known Malicious emails are blocked and quarantined by Microsoft.
- PUA – Potentially Unwanted Application
- To reduce noise from low-fidelity alerts, the playbook now automatically mutes External_PUA alerts when the ids.signature begins with “JA3 Hash”. These alerts are generally considered low severity, as they often flag benign or background traffic based solely on JA3 hash matches, which can produce a high rate of false positives.
- Microsoft 365: XDR Anomaly
- Excluded escalations when users are cleaning up files in the recycle bin or clearing cache without impacting mass deletions by users.
New Detections - mXDR (Stellar): Duo Fraud Impossible Travel Correlation
- Detects a correlation between Duo fraud events and impossible travel activity.
- mXDR (Stellar): Potential Luna Moth Domain
- Detects potential traffic connections to known Luna Moth ransomware domain naming conventions.
- mXDR (Stellar): Possible Defendnot Antivirus Manipulation
- Detects Defendnot activity which aims to replace existing Microsoft Defender protections.
- mXDR (Stellar): Multiple JumpCloud Admin Login Failures
- Detects multiple login failures form a JumpCloud admin account within a short period of time.
New Features - Stellar Cyber XDR Platform Upgrade
- Stellar Cyber Cyflare managed platform was upgraded to version 5.5.0.
- Detection Profiles allow for tuning and customized detections per tenant. Previous detection settings were configured globally, but with the introduction of profiles, these can now be specified at the tenant or tenant group levels.
- Resource-Intensive Query Warnings now appear when resource-intensive queries are constructed. The warnings raise awareness about the types of queries that consume an outsized amount of platform resources and offer suggestions on how to make them more efficient.
- Query builders embedded on feature pages now pop out to the full query editor with more screen real estate and testing functionality. The ability to test alert filters and case filters directly from the filter builder has been added as well.
- Cyflare Technical Operations will be performing a scheduled upgrade of all Stellar Cyber Windows/Linux Agents, Security Sensors, Network Sensors, and Modular Sensors to version 5.5.0 during the week of June 23, 2025. This upgrade is managed remotely by our team and requires no customer action or service interruptions.
- Checkpoint Harmony Email Security
- The SOAR development team have worked on a new action for Checkpoint Harmony ES SOAR integration called “Search for Security Events by Email”. With the addition of the new CSI (Cross-Service Intelligence) section in tickets, the SOC will use this action to perform searches against the flagged email from other XDR alerts and provide additional context around the user’s activity.
- Cross-Service Intelligence: XDR alerts with EDR Context
- Introduced Cross-Service Intelligence (CSI) to SOC tickets, providing enriched context for XDR alerts by pulling in relevant data from other subscribed services like EDR, Vulnerability Scanning (VSS), and Email Security (ES). This enhancement helps analysts quickly understand the broader impact of a given IOC, streamlining investigation and response across tools.
- The new CSI section now includes a lookup for EDR tools for the following playbooks:
- Potential Metasploit Activity
- Windows User Added to Security-Enabled Global Domain admins Group
- Potential Token Theft Correlation
- External Password Spraying
- Potential Account compromise Axios User Agent
- Malware Activity (both Internal/External)
- Trojan Activity (both Internal/External)
- For specific requests around adding these CSI sections, please reach out to the SOC.
Playbook Enhancement - Port Scan Anomaly
- An additional playbook workflow has been added to this alert type where if the customer utilizes SentinelOne’s network discovery feature within their environment, the workflow is able to identify the activity and consider network discovery scans as known authorized activity. This reduces noise and false positive escalation rates specific for this alert type.
- Internal Scanner Behavior Anomaly
- To address the known low fidelity of certain alerts, this playbook now includes an additional lookup to verify whether the escalated activity is associated with the “SCAN Behavioral Unusual Port” IDS signature. This signature is frequently noisy and typically considered low severity, as many customer environments use custom ports for in-house applications—often triggering alerts on normal activity.
- Vicarius Playbook Opt-in Logic Tuning
- To help customer teams manage the high volume of vulnerability alerts reported by Vicarius, the SOC has implemented a custom workflow that leverages CISA’s Known Exploited Vulnerabilities (KEV) catalog. This authoritative list identifies CVEs that are actively exploited in the wild and should be prioritized for remediation.
- Google Workspace Alert Exfiltration Over Web Service
- A large number of alerts were being generated when users shared private documents from their personal (non-shared/team) Google Drives. These instances typically involved expected behavior and did not represent a security concern or policy violation.
- A new playbook for the following alert types have been created along with a tailored escalation template:
- OneLogin BruteForce Attempts
- Possible Codefinger AWS Ransomware
- AWS Delete User
- Google Workspace Alert – XDR Policy Anomaly
- DHCP Pool Exhausted
- Duo User Marked as Fraud
- Consent to Suspicious Application
- CrowdStrike – Inhibit System Recovery
- CrowdStrike – EDR Detections
- Microsoft Entra Unusual Account Creation
- WindowsDefenderAntivirus User Execution
- External RDP Suspicious Outbound
- SoftPerfect Network Scanner Execution
- Internal SQL Anomaly
- New custom correlations and playbooks for RDP and Script-Based Remote Access alerts provide clearer context, improved automation, and more accurate escalation handling ensuring faster and more informed response to potential remote access threats:
- Login Time Anomaly RDP Correlation
- Suspicious Script Remote Access Correlation
- AI-powered summarization has been added to the following playbooks providing a concise, contextual summary of threat hunting search results, helping customers quickly understand key findings and accelerate decision-making:
- Inbox Rule Azure Risk Correlation
- Potential Account Compromise Token Theft
- Login Time Anomaly RDP Correlation

July 2025

###### Category ###### Completed Items
Alert Tuning - mXDR (Stellar): Emerging Threat Activity
- The malicious c2 domain related to the source IP 104.21.80.1 has been addressed and suspended by an INCANN lookup.
New Detections - mXDR (Stellar): Suspicious LDAP Search Request
- Detects a suspicious LDAP search request which was observed for the first time. This behavior indicates that an attacker might be attempting to collect information from the Active Directory (AD) service.
- mXDR (Stellar): BloodHound Enumeration Activity
- Detects potential domain enumeration activity from BloodHound or other Active Directory data collection tools.
- mXDR (Stellar): DNS Query to Anonymous File Upload Domains
- Detects DNS queries to anonymous file upload platform domains often used for malicious purposes.
- mXDR (Stellar): DNS Query to External Service Interaction Domains
- Detects DNS queries to external service interaction domains often used for out-of-band interactions after successful RCE.
- mXDR (Stellar): DNS Query to Monero Crypto Coin Mining Pool Domains
- Detects DNS queries to Monero crypto coin mining pool domains.
- mXDR (Stellar):Down Connector Monitoring
- Down Connector Alerts have been created for the following Stellar Connectors: Office 365, Entra (Azure), Active Directory, and Google Workspace.
- mEDR (SentinelOne): Detects potential On-Prem SharePoint CVE-2025-53770 traffic and windows events for compromised hosts:
- Web Shell Creation in LAYOUTS Directory
- Web Shell File Detected in LAYOUTS Directory
- Suspicious Process Spawned by SharePoint IIS Worker Process
- mXDR (Stellar): Potential SharePoint RCE Attempt
- Detects any inbound POST or GET requests from known malicious IPs associated with CVE-2025-53770, any beaconing out to the known malicious IPs, and any POST or GET requests to the known exploit attempted request URL paths.
- mXDR (Stellar): Potential SharePoint Post Exploitation Attempt
- Detects spinstall, ToolPane, or .aspx files that fall within a known path used for exploitation / exfiltration.
- mXDR (Stellar): Cloud Drive Data Exfiltration Anomaly
- Detects an account downloading an atypical number of files over a 24-hour period.
- mXDR (Stellar): Impacket PsExec Execution
- Detects suspicious SMB traffic related to Impacket PsExec execution.
- mXDR (Stellar): Possible Impacket SecretDump Remote Activity
- Detects suspicious SMB traffic related to credential dumping using Impacket.
- mXDR (Stellar): Protected Storage Service Access
- Detects suspicious SMB traffic accessing protected storage services.
- mXDR (Stellar): Possible PetitPotam Coerce Authentication Attempt
- Detects suspicious SMB traffic related to PetitPotam coerced authentication.
- mXDR (Stellar): Remote Task Creation via ATSVC Named Pipe
- Detects suspicious SMB traffic accessing ATSVC named pipes.
New Features - New Integration: Perception Point
- This new connector enables ingestion of malicious scan data directly from Perception Point, giving our SOC teams better visibility into email-borne threats.
- In addition to ingesting alerts, the integration supports actionable response capabilities. Analysts can now take remediation actions such as whitelisting or blocklisting specific Senders, Domains, or URLs based on threat intelligence surfaced from Perception Point.
- To activate this integration, customers will need to provide their Organization ID and API Key. This enhancement allows for tighter email security control, faster response, and better alignment across detection and remediation workflows.
- mXDR (Stellar): Unhealthy Connectors
- Introduced a new capability to improve visibility into connector health for critical integrations such as Office 365, Entra, and Google Workspace.
- Automated workflows now monitor these connector types and generate alerts when they enter an error state with a corresponding error message. This ensures the SOC can proactively notify customers when integrations are down or experiencing issues—helping prevent blind spots in detection and response.
- To reduce noise and avoid false positives, temporary downtimes (e.g., connector updates) and warning statuses are excluded from alerting. This targeted approach ensures alerts are meaningful and actionable.
- Cross-Service Intelligence: XDR alerts with Vulnerability Scanning Service (VSS) Context
- The CSI (Cross-Service Intelligence) section now includes a correlation search that checks whether the endpoint involved in an XDR alert—and all systems it communicated with in the past 6 hours—are vulnerable to the CVE referenced in the alert.
- If none of the systems are found to be vulnerable, the case is auto-closed. This behavior is consistent with the CSI lookups previously implemented for EDR alerts.
- This CVE-focused CSI logic has now been integrated into the following ADR playbooks:
- ADR – IDS Signature Spike Alert
- ADR – Public to Private Exploit Anomaly
- ADR – Private to Public Exploit Anomaly
- ADR – Private to Private Exploit Anomaly
- ADR – Exploit Attempt Correlation
- For requests regarding further CSI enhancements, please contact the SOC team.
- Cross-Service Intelligence: XDR alerts with Email Security (ES) Context
- We’ve expanded Cross-Service Intelligence (CSI) support within XDR alerts to include enhanced lookups in Check Point Harmony Email Security.
- As part of CSI enrichment, the system now performs email searches in Check Point to provide additional context for user activity in the following Google Workspace alert types:
- Assign Role
- Unassign Role
- Move User to Organizational Unit
- This integration helps analysts quickly determine if affected users were involved in any suspicious email activity around the time of the alert, improving situational awareness and response effectiveness.
- Stellar Cyber Platform Upgrade
- Stellar Cyber Cyflare Gov Cloud platform was upgraded to version 6.0.0.
- Released a new UI for general availability, delivering a more intuitive navigation structure and an updated theme engine with light and dark modes to enhance flexibility and usability.
- Introduced Saved Views to preserve customized table layouts across sessions.
- Introduced an alert type for dormant user accounts with inactivity alerts.
Playbook Enhancement - A new playbook for the following alert types have been created along with a tailored escalation template:
- Sophos Impair Defenses
- Azure Single Factor Authentication
- AI-powered summarization has been added to the following playbooks providing a concise, contextual summary of threat hunting search results, helping customers quickly understand key findings and accelerate decision-making:
- Potential Metasploit Activity
- Cloud Drive Data Exfiltration Anomaly
- Unusual Volume of External File Sharing
- AWS GuardDuty Exfiltration Over Web Service
- M365 Internal Spear Phishing
- Google Workspace Super Admin Password Reset
- Google Workspace Assign Role
- Google Workspace Unassign Role
- Google Workspace Move User to Organizational Unit
- Azure Sentinel Playbooks
- Enhanced playbook logic for Azure Sentinel alerts to better handle scenarios where multiple alerts are combined before ingestion into SOAR.
- Previously, ticket links could be incorrect or incomplete when multiple alerts were grouped at the source.
- With the updated workflow, the system now correctly detects and includes all relevant alert links in the ticket, ensuring analysts have complete visibility into the original Sentinel events.
- This improvement enhances investigation accuracy and reduces confusion in multi-alert scenarios.
- mXDR (Stellar): Azure AD Risk Detection
- New correlation logic was added to the playbook for Azure AD Risk Detection alerts.
- When triggered, the playbook now checks for any related User Impossible Travel alerts involving the same user.
- If a match is found, key details—including IP addresses from the Impossible Travel event—are automatically included in the SOC Findings section of the ticket to provide deeper context.
- If no related alert is found, the ticket will clearly state that no correlating activity was identified.
- This enhancement helps analysts assess risk more accurately and streamline investigation.
Template Updates - No Changes
Response Action - No Changes
Other - No Changes

August 2025

###### Category ###### Completed Items
Alert Tuning - mXDR (Stellar): Ingestion update for DLP associated alerts
- The following alert types have been tuned out of ingestion when associated with DLP alerts:
- Microsoft 365: Exfiltration Over Web Service
- Microsoft 365: XDR Anomaly
- Microsoft 365: Valid Accounts (Privilege Escalation)
- Microsoft 365: Data Transfer Size Limits
- mEDR (SentinelOne): Account Policy Update
- Created an account level policy override regarding Google Chrome offline browser extensions triggering after a recent logic update.
New Detections - mXDR (Stellar): SonicWall VPN Potential Suspicious Activity
- Detects suspicious IPs linked to current threats and message IDs related to VPN usage, including 238 (successful WAN remote user login), 1080 (VPN zone remote login), and 5 (firewall logs deleted).
- mEDR (SentinelOne): Browser Executing PuTTY and Launching Rundll32
- Detects the execution of rundll32.exe by PuTTY.exe, a behavior that may suggest the misuse of legitimate software to execute unauthorized or malicious code.
- mEDR (SentinelOne): Clear Windows RDP Event Log via Wevtutil Command Execution
- Detects the execution of the wevtutil command to clear the Microsoft-Windows-TerminalServices-RDPClient/Operational event log on Windows endpoints.
- mEDR (SentinelOne): Bloodhound Tool Execution
- Detects the execution of Bloodhound, a tool commonly used for mapping Active Directory (AD) trust relationships and identifying potential attack paths.
- mEDR (SentinelOne): Potential Web Shell Creation in LAYOUTS Directory
- Detects a command script containing indicators of a web shell being written to a sensitive SharePoint system directory.
- mEDR (SentinelOne): Web Shell File Detected in LAYOUTS Directory
- Detects the creation or modification of a suspicious aspx file, within the critical SharePoint LAYOUTS directory.
- mEDR (SentinelOne): Suspicious Process Spawned by SharePoint IIS Worker Process
- Detects the creation of a suspicious child process, such as a command shell or common reconnaissance tool, by the Internet Information Services (IIS) worker process (w3wp.exe) running a SharePoint application pool.
- mEDR (SentinelOne): Base64 Decode and Execute Memory Dump Python Script
- Detects the use of base64 decoding followed by the execution of a Python script designed to perform memory dumping operations.
- mEDR (SentinelOne): AMSI Disabled via Registry Modification
- Detects changes to the Windows registry that disable the Antimalware Scan Interface (AMSI) by setting the AmsiEnable value to 0.
- mEDR (SentinelOne): APDS XSS Redirection
- Detects the creation of malicious Microsoft Management Console (MMC) files crafted to exploit a known XSS vulnerability in the apds.dll library for arbitrary code execution.
New Features - Stellar Cyber Platform Upgrade
- Stellar Cyber Cyflare platform was upgraded to version 6.0.0.
- Released a new UI for general availability, delivering a more intuitive navigation structure and an updated theme engine with light and dark modes to enhance flexibility and usability.
- Introduced Saved Views to preserve customized table layouts across sessions.
- Introduced an alert type for dormant user accounts with inactivity alerts.
Playbook Enhancement - mXDR (Stellar): XDR: AWS Security Hub Findings Evasion
- AI-powered summarization has been added to this playbook providing a concise, contextual summary of threat hunting search results, helping customers quickly understand key findings and accelerate decision-making.
- mXDR (Stellar): Down Sensor Playbook
- The SOAR team has enhanced the Down Sensor workflow by introducing a new playbook that is fully automated, requiring no analyst interaction, and is designed to improve escalation speed and accuracy.
- mXDR (Stellar): Optimization of Stellar Searches in Top Playbooks
- The SOAR team has optimized Stellar searches across several of the most frequently used playbooks to improve efficiency and reduce unnecessary resource consumption.
- These updates address a known issue on the XDR platform where large open-ended searches over API calls were impacting server performance.
- mXDR (Stellar): Updated Correlation Logic – Conditional Access Alert Priority
- The SOAR team updated correlation logic for the following playbooks:
- O365 Successful Login Outside the US
- Azure XDR Successful Login Outside the US
Template Updates - No Changes
Response Action - No Changes
Other - mEDR (SentinelOne): Client Facing Detections Board
- Added an additional filter status called “SentinelOne EDR” that lists out STAR rules.

September 2025

###### Category ###### Completed Items
Alert Tuning - mXDR (Stellar): Account Created and Deleted in Short Time Frame
- Excluded escalations when the initiating user is Microsoft Substrate Management, a background account for Exchange Online and Entra. This activity targets sync operations, guest account creation, and Teams group changes. It automatically attempts to create a User Principal Name for the account which typically does not complete and rolls back the email account creation triggering the alert.
New Detections - mXDR (Stellar): Jumpcloud MFA Push Failure
- Detects a failed MFA push attempt for a user in your environment.
- mXDR (Stellar): Suspicious Notepad Activity on Domain Controller
- Detects files located within ProgramData which were accessed via Notepad on a Domain Controller. This could indicate potential Discovery efforts by a malicious actor.
- mXDR (Stellar): Anydesk Remote Access Software Service Installation
- Detects the installation of the anydesk software service. Which could be an indication of anydesk abuse if you the software isn’t already used.
- mXDR (Stellar): Sonicwall Smurf Amplification Attack Dropped
- Detects a smurf amplification attack and dropped by Sonicwall indicating potential denial of service.
- mXDR (Stellar): Suspicious SonicWall VPN Login Attempt
- Detects multiple login attempts from multiple public IP’s within a short time frame.
- mXDR (Stellar): Potential EDR Freeze Attempt
- Detects attempts to freeze a process, likely an EDR or an antimalware service process, through EDR-Freeze that abuses the WerFaultSecure.exe process to suspend security software.
New Features - New Integration: Portnox API
- Portnox provides network access control (NAC) and device visibility, helping organizations ensure only trusted devices connect to their networks.
- The integration in SOAR enhances SOC operations by enabling automated actions such as device lookups and site visibility, streamlining investigations and improving response efficiency.
- Available Actions (with more to come):
- Ping – Test connections.
- Get Device List – Retrieve a list of devices in the sites.
- Get a Device – Return data for a specific device by ID.
- Get Network Sites – List all sites within a given network.
- Model Enhancement: SOC AI
- The AI model powering SOC escalations has been upgraded to deliver faster, more accurate, and context-aware responses.
- This enhancement improves the quality of analysis, reduces false positives, and helps SOC analysts focus on high-priority threats with greater efficiency.
- AI Use Case Playbooks Enhancement
- To improve resilience in our SOAR playbooks, we’ve implemented a fallback mechanism for all AI-driven use cases. In the event of an AI vendor outage, playbooks will now automatically switch to pre-defined SOC escalation templates, ensuring tickets continue to be created without delays or missing critical details.
- While these templates are less enriched than AI-generated content, they still include all the necessary information for effective review and investigation, preventing backlog and maintaining smooth SOC operations.
Playbook Enhancement - AI-powered summarization has been added to the following mXDR (Stellar) playbooks providing a concise, contextual summary of threat hunting search results, helping customers quickly understand key findings and accelerate decision-making:
- Mimikatz Credential Dump
- Internal Password Spray
- Potential Katz Stealer User Agent
- DNS Query to Anonymous File Upload Domains
- DNS Query to External Service Interaction Domains
- DNS Query to Katz Stealer Domain
- DNS Query to Monero Crypto Coin Mining Pool Domains
- AWS GuardDuty Non-Standard Port
- M365 – Suspected Identity Theft – Pass the Ticket
- mXDR (Stellar): Microsoft 365 – XDR Anomaly
- A new correlation check has been added for the threat “Mail Forwarding Rule Created.” When triggered, SOAR will automatically search any open tickets related to the alert “Creation of Forwarding or Redirect Rule” with the same username in the past day. If a match is found, a comment is added to provide additional context for the investigation. This avoids unnecessary duplicates and keeps similar activity grouped together.
Template Updates - No changes
Response Action - No changes
Other - CrowdStrike – API Integration Upgrade
- We’ve updated this playbook to align with the latest CrowdStrike API changes and address deprecation requirements:
- Updated all CrowdStrike connectors from Detection Connector to Alerts Connector and enabled them.
- Replaced “Add comment” actions with “Add alert comment”, now referencing the composite_id.
- Enhanced field handling by using the “Get Original Alert JSON” action instead of relying on default Event JSON fields.

October 2025

###### Category ###### Completed Items
Alert Tuning - No Changes
New Detections - mXDR (Stellar): Potential Amatera Stealer Activity
- Monitors traffic logs for connections to known IPs associated with the Amatera Stealer where there is a GET method attempt to known URLs.
- mXDR (Stellar): Anydesk Remote Access Software Service Installation
- Detects the installation of the Anydesk software service, which could be an indication of Anydesk abuse if the software isn’t already used.
- mXDR (Stellar): Potential Windows Server Update Services Remote Code Execution
- Detects suspicious child process activity associated with CVE-2025-59287. Successful exploitation of this vulnerability can allow malicious actors to remotely execute malicious code with SYSTEM privileges.
- mEDR (SentinelOne): IP Console Routing Activity
- Monitors command line activity in SentinelOne for attempts to route network connections away from the console IP.
New Features - Managed Stellar Instance version upgrade to 6.1.0
- Stellar Cyber Cyflare managed platform was upgraded to version 6.1.0.
- There were no major changes associated with this upgrade.
Playbook Enhancement - The following SOAR playbooks have been enhanced for faster triage time and the ticket template has been improved for better detailed analysis:
- Anomalous DC Sync 
- Attempt to Deactivate Okta Policy
- Attempt to Modify Okta Policy
- Gsuite Account Security Settings Disabling
- Google Workspace Role Privilege Deleted
- Google Workspace Granted Domain API Access
- Google Workspace Role Modified or Deleted
- Google Workspace Application Removed
- LastPass Deactivated User
- LastPass Deleted Sites
- LastPass Employee Account Deleted
- LastPass Master Password Changed
- Microsoft Entra Domain Federation Settings Modified
- Microsoft Entra Changes to Device Registration Policy
- O365 – Elevation of Exchange admin privilege
- WS Access Key Created
Template Updates - mEDR (SentinelOne)
- Updated ticket template to include insight on additional endpoints the file has been found on.
Response Action - Use Case 3 Updates
- Use case 3 block has been updated so customers can now opt-in on a per alert basis, in addition to a per client basis. All use case 3 alerts will be opted-in by default except for the following which will be opted-out by default:
- custom_potential_account_compromise_axios_user_agent
- custom_conditional_access_blocked_login
- custom_o365_successful_login_outside_the_us
- custom_azure_ad_risk_detection
- custom_potential_account_compromise_token_theft
- custom_azure_successful_login_outside_the_us
Other - No Changes

November 2025

###### Category ###### Completed Items
Alert Tuning - No changes
New Detections - mXDR (Stellar): AWS Create User
- A new user was created in an AWS account. Verify if this is expected and approved activity.
- mXDR (Stellar): Suspicious FortiGate Log Settings Modification
- The log settings on a FortiGate firewall have been modified. This may indicate potential unauthorized configuration changes.
- mXDR (Stellar): FortiGate Firewall Local User Account Created
- This detection identifies the creation of a local user account on a FortiGate firewall by looking for log entries where the msg field contains “user.local” and the action is “Add” within FortiGate logs.
- mXDR (Stellar): FortiGate FW System Admin Account Created
- This detection identifies the creation of a system administrator user on a FortiGate firewall by looking for a msg field that starts with “Add” and contains “system.admin” within FortiGate logs.
New Features - mXDR (Stellar): Mass IP Blocking Capabilities
- Launched a workflow that will take an MSP name and other details via a form, find their sub-tenants, and use their Stellar firewall connectors to block inbound and outbound traffic via IPv4, IPv6 or CIDR.
- mEDR (SentinelOne): Mass Exclusion / Blocklist Capabilities
- Created a workflow that will use input from a form of required information and allow analysts to block a SHA256 Hash or exclude SHA256 Hash, Publisher, file or file path in bulk provided an MSP name. Sites will be found by the MSP name and the appropriate bulk actions will be performed.
Playbook Enhancement - mEDR (Crowdstrike): Generic Playbook
- Added an additional branch for when the product is NGSIEM. Since it provides very little host/process detail and mostly metadata about the rule and users, adjusted the ticket template, Zoho ticket search, Zoho comment, and the subject line to accommodate it.
- SOAR playbooks have been enhanced to add context for specific IOCs:
- Created an IOC Context Enrichment block to make customer context data (like known subnets) available in the ONE platform, allowing SOAR playbooks to automatically retrieve and attach relevant IOC details to escalated tickets.
Template Updates - No changes
Response Action - Use Case 3 Updates
- Before trying to add a user into the disable group, the playbook will check to see if the user is already in the group. This will avoid unnecessary Critical cases.
- Wording has been updated in the notification to make it more clear why the playbook failed to add the user to the disable group.
Other - mEDR (SentinelOne): Revamped SentinelOne Playbook
- Reduced the time frame of correlated Stellar searches from 24 hours to 5 hours.
- mXDR (Stellar): Cyrisma Scan Searches
- Reduced the time frame of Stellar searches from 1 month to 1 week.

December 2025

###### Category ###### Completed Items
Alert Tuning - No changes
New Detections - mXDR (Stellar): Fortiweb AuthBypass
- This query detects exploitation attempts of CVE-2025-64446 (FortiWeb Auth Bypass) by searching for POST requests to the signature path ./cgi-bin/fwbcgi. We skip a direct status_code == 200 filter to keep the query robust: some logs may lack the status code field. By excluding known failure codes (403/404) and retaining entries with missing codes, we prevent false negatives due to incomplete logging.
- mXDR (Stellar): Bitter APT Q37 – WinRAR Normal.dotm Overwrite
- Detects archives exploiting path traversal to overwrite Normal.dotm.
- mXDR (Stellar): IIS Webshell Recon Activity
- Detects when the IIS APPPOOL subject executes a Windows event that ends with whoami.exe.
- mXDR (Stellar): Persistence Via TypedPaths
- Detects modification addition to the ‘TypedPaths’ key in the user or admin registry via the commandline.
- mXDR (Stellar): Potential Brickstorm Malware Activity
- BRICKSTORM is a sophisticated backdoor for VMware vSphere (specifically VMware vCenter servers and VMware ESXI) and Windows environments. Once compromised, the cyber actors can use their access to the vCenter management console to steal cloned virtual machine (VM) snapshots for credential extraction and create hidden, rogue VMs.
New Features - Managed Stellar Instance version upgrade to 6.2.0
- The Stellar Cyber Cyflare managed platform was successfully upgraded to version 6.2.0. No major changes were introduced with this upgrade.
Playbook Enhancement - mES (Checkpoint): Generic Playbook
- Added a verification step to check whether the email has already been quarantined.
- CoroSiem Generic Playbook
- CoroSiem is a SIEM solution in which logs can be ingested, alerts triaged, and tickets generated without having to manage multiple tools or across platforms. The broader Coro platform also offers endpoint protection with EDR-like capabilities, endpoint monitoring, and event correlation.
- mEDR (SentinelOne): Revamped Playbook
- Added a check to verify whether the mitigation status exists in the events and adjusted the ticket templates accordingly.
- Changed the NOT first alert logic to run earlier in the playbook. This helps resolve grouped cases that close out earlier than expected when the first case closes out as a comment added onto an existing ticket.
Template Updates - No changes
Response Action - Use Case 3 – Ansible
- Updated the codebase to improve input validation and error handling. The action now properly evaluates different input scenarios and returns clear, descriptive error messages when malformed input is provided. This change fixes an issue where Ansible playbooks were previously executing against empty or invalid usernames and still returning a successful result, even when an error had occurred.
Other - mEDR (SentinelOne): Mass Exclusion/Blocklist by MSP
- Updated the workflow that will allow excluding or blocking both SHA1 and SHA256 hashes.

2024 Change Logs by Month

January 2024

###### Date of Update ###### Completed Items
01/03/2024 Alert Tuning: Public to Private Exploit Anomaly
- The ticket template for this alarm type has been modified to now include a sub-bullet mentioning internal source IPs associated with the detection.
- If blocked / dropped connections / no bytes transferred, the playbook will not escalate the event.
01/04/2024 New Feature: Temporary Suppression per Entity
- Customers can now provide certain entities for the SOC to mute alerting due to expected activity, authorized testing activity or other scenarios leading to a known flood of alerts from a specific source.
- Customers can reach out to the SOC and provide usernames/IPs that need this mute along with start or end date.
01/06/2024 Playbook Enhancement: Okta Login Outside the US
- This alarm type has now been upgraded to use newer playbook features like Travel advisory lookup making it more efficient and reliable when triaging.
- As a result this will result in less false positives or expected activity to be alerted on.
01/10/2024 Alert Tuning: Malware Activity & Exploit Anomaly Logic
- External Malware Activity and Public to Private Exploit Anomaly Playbooks, will now feature a condition where automated logic will close out the case as a false positive if it meets certain criteria.
- The criteria includes validation of successful or failed connection attempts, as well as amount of bytes exchanged related tot he incident.
01/11/2024 Alert Tuning: Exploited Command and Control Connection Logic
- If the IDS signature reported by XDR is “GPL VOIP SIP INVITE message flooding” and both flagged IPs are internal only, the SOC has deemed this scenario to be non-actionable.
- The alert is still leveraged for correlative activity with other alerts/playbooks.
01/12/2024 Playbook Enhancement: External Malware Activity
- All DNS-related alarm types now focus the investigation strictly on the DNS detected within the evidence information.
- This helps improve escalation quality and provide consistent investigations.
01/16/2024 New Feature: Alert Grouping for SentinelOne Threats
- Alert grouping is now being leveraged within our playbooks for SentinelOne Threats based on the file hash of a threat.
- This will avoid the creation of duplicate tickets of the same threat when playbooks get ran concurrently.
01/25/2024 Playbook Enhancement: User Success Brute-Forcer CKB Lookup
- This alarm type now utilizes the Client Knowledge Base data by automatically closing detections as false positives if they originate from a known Vulnerability Scanner within your environment.
01/25/2024 Playbook Enhancement: SentinelOne Playbook Logic Re-Vamped
- The Playbook improvement has a focus on the logic around applying a more appropriate priority level based on other threats or related IOCs observed within your environment.
01/28/2024 Alert Tuning: Azure AD Risk Detection
- Playbook modifications to account for scenarios where alerts were generated with no known successful logins from the flagged source/user.
- This adjustment should make escalation higher in fidelity and accuracy moving forward.
01/29/2024 Alert Tuning: Password Spray Playbook
- This alarm type now has a newly updated playbook functionality in order to filter out any scenarios where reported number of unique users are less than 5.
- This change will make the alarm type more reliable to report actual password spray activity.
01/30/2024 New Feature: Entity Hunter (Beta)
- New feature within our SOAR platform that helps us increase visibility over a certain entity through an automated watchlist functionality.
- Due to any recent security incident like a user compromise, they can reach out to the SOC and have the specific username added to our Entity Hunter.
- Once added in, every case monitored by the SOC will raise to a HIGH severity if it matches any entity present within our watchlist.

February 2024

###### Date of Update ###### Completed Items
02/02/2024 Alert Tuning: Multiple Users Deleted
- Client Knowledge Base defined service accounts that are flagged deleting users through our custom ATH rule “Multiple Users Deleted” will be auto-closed as Muted Operational detections.
02/03/2024 Alert Tuning: Exploit Anomalies | Malware/Trojan Activity
- Alert tuning complete for IDS signature based detections, if firewall decision is listed as blocked the detection is excluded preventing unnecessary alerting.
02/05/2024 Playbook Enhancement: Potential Shell Shock User Agent Request
- If the alert contains a certain stellar field, that will be included as the source IP as this is the actual source of the request.
02/07/2024 Alert Tuning: Anomalous DC Sync
- If the Anomalous DC Sync is from a known service account listed in the CKB then it will not result in an escalation.
02/08/2024 New Detection: Azure User Added to Global Admin Group
- Looking for modified properties new value field to contain “Global Administrator” from the activity display name of “Add member to role” in Azure AD logs.
02/12/2024 New Feature: Indicators of Compromise now Non-Clickable
- To avoid our clients from mistakenly clicking on IPs, URLs or other IOCs that can be potentially harmful, we have made these IOCs non-clickable.
- This action will take in an IOC, or list of IOCs (comma delaminated) and return a JSON of the IOCs with their “.” surrounded by brackets ([]).
02/14/2024 Alert Tuning: User Impossible Travel
- Alert tuning for User Impossible Travel alerts if the user and country pair are listed in CKB.
02/21/2024 Alert Tuning: Malware Activity Flagged from Microsoft Updates
- Stellar Detections related to malware were being frequently raised when related to routine Microsoft Updates.
- This alert will no longer be escalated moving forward.
02/21/2024 Alert Tuning: Trojan Activity Benign Signatures
- Muted some IDS Signatures that the SOC does not deem as critical or actionable for a client.
- The signatures are related to non-existent domain responses that pose minimal risk and low fidelity.
02/26/2024 Template Update: The following template updates were implemented to reflect our improved formatting:
01. AWS Malicious Host Access
02. AWS Not MFA Authenticated
03. AWS Root Logon Detected
04. Azure AD Add App Multitenant
05. Azure AD Change Domain
06. Azure AD Risk Detection
07. Azure Domain Policy Modification
08. Azure Failed Login Outside the US
09. Azure XDR Location Anomaly
10. Bad Destination Reputation
11. Bad Reputation Login
12. Bad Source Reputation Anomaly
13. BlueKeep
14. Cisco Login Failed
15. CrowdStrike – Command and Scripting Interpreter
16. CrowdStrike – Data Encrypted for Impact
02/27/2024 New Detection: Potential ScreenConnect Vulnerability
- Detection made in response to recent ScreenConnect Vulnerability, hunting for file names used in initial compromise.
- Reference our “Screen Connect Security Advisory” posted on February 28th, which addresses “CVE-2024-1708” and “CVE-2024-1709”.

March 2024

###### Date of Update ###### Completed Items
03/14/2024 New Detection: Exfiltration and Tunneling Tools Execution
- Custom built alert Utilizing Windows Sysmon.
- Tracks well known tools use of data exfiltration over alternative protocols from user accounts.
03/14/2024 New Detection: Data Exfiltration to Text Storage Sites and Cloud Storage
- Custom logic built around the Stellar alert Outbytes Anomaly.
- The detection is looking for anomalously high volume being transferred to a destination host used for external storage.
03/14/2024 New Detection: DNS Exfiltration Tools Execution Detected
- Custom built alert Utilizing Windows Sysmon.
- This alert is looking for the execution of tools used for Application Layer Protocol and DNS Exfiltration.
03/14/2024 Alert Tuning: Malware Activity – Microsoft related Activity
- Added more logic to not alert around Microsoft related activity like Windows Updates.
- This was also implemented last month, but logic was further enhanced to not alert around this activity.
03/15/2024 Alert Tuning: Public to Private Exploit Anomaly
- More logic implemented within the playbook to account for activity that is already being blocked by a client’s firewall.
03/18/2024 Template Update – The following template updates were implemented to reflect our improved formatting:
01. Default – Generic Alarm
02. DGA Resolvable
03. DHCP Server Anomaly
04. DNS Tunneling Anomaly
05. Domain Controller Spoofed Authentication
06. DPAPI Domain Backup Key Extraction
07. Exploited Command and Control Connection
08. Fortinet Admin Configuration Change
09. G Suite – Account Security Settings Disabled
10. G Suite – User Suspended
11. Google Workspace Alert – XDR Anomaly
12. Honey Account Login Failure
13. Kerberoasting
14. Kerberos Silver Ticket
15. Known Malicious User Agent Detected
16. M365 – Exfiltration Over Web Service
17. M365 – User Added to Privilege Group
18. Malware Activity
19. Malware on Disk
20. Metasploit Download

Microsoft Defender ATP
21. Microsoft Teams Vulnerability
22. Mimikatz Credential Dump
03/28/2024 Playbook Enhancement: Bad Reputation Anomaly
- Playbook has been re-evaluated and adjusted prioritization levels for certain criteria to meet up to Critical Severity.
- Also added automation to this playbook and this will result in much faster escalations of potentially critical events.
03/29/2024 New Detection: Potential APT29 Related Scheduled Tasks
- Custom detection that hunts for Scheduled Task Names that have been utilized by APT29 via GraphicalProton Backdoor.
03/29/2024 New Detection: Potential Raspberry Robin CPL Execution Activity
- Custom detection to hunt for behavior observed in multiple Raspberry-Robin variants.

April 2024

###### Date of Update ###### Completed Items
04/01/2024 New Detection: Google Workspace – 7 New Detections
1. Application Access Level Modified
- Detects when an access level is changed for a Google Workspace application.
2. Application Removed
- Detects when an application is removed from Google Workspace.
3. Granted Domain API Access
- Detects when an API access service account is granted domain authority within a Workspace environment.
4. Role Modified or Deleted
- Detects when a role is modified or deleted within Google Workspace.
5. Role Privilege Deleted
- Detects when a role privilege is deleted within Google Workspace.
6. User Granted Admin Privileges
- Detects when a Google Workspace user is granted admin privileges.
7. Multi-Factor Authentication Disabled
- Detects when multi-factor authentication (MFA) is disabled.
04/02/2024 Playbook Enhancement: Conditional Access Blocked Login
- Revamped logic around alert de-duplication within SOAR playbooks and avoid creating duplicate tickets about the same entities.
04/03/2024 New Feature: Improved metrics around Critical alerts
- The SOC improved internal processes that track and measure metrics around Critical alerts initiated for various customers.
04/03/2024 New Feature: Recorded Future connector
- The SOC now supports a new vendor “Recorded Future” and also have custom playbooks built around the same. This includes default Recorded Future alerts as well as custom built playbook alerting from the customer’s environment.
04/05/2024 Other: Upgraded XDR Integration with SOAR
- This enhancement effectively resolves previously identified challenges with ingestion latency and introduces additional advanced features to the SOAR infrastructure. Our XDR system now ensures prompt and comprehensive alert ingestion, eliminating gaps and offering a suite of sophisticated authentication methods tailored to diverse platform settings.
04/08/2024 Playbook Enhancement: Revamped SentinelOne playbook
- The SentinelOne playbook has been comprehensively updated, offering enhanced features for more effective security operations management. The key improvements include:
- The integration of Gen-AI technology to summarize threat indicators identified by SentinelOne for each escalated threat, aiding customers in understanding the potential impact.
- Refined alert prioritization mechanisms that more accurately categorize the severity of detected threats, ensuring that SOC investigations align with the associated risks.
- An upgrade to the latest version of the SentinelOne API, enriching the data with additional details, an expanded feature set, and the full suite of capabilities available in the new API iteration.
04/09/2024 Playbook Enhancement: Improved logic for SSH Brute-force activity
- The playbook has been refined to augment the information presented during ticket escalations. This includes the incorporation of alert-specific look-ups that contribute valuable insights and present a comprehensive narrative of the events leading up to the alert being triggered.
04/15/2024 Playbook Enhancement: Improved logic for multiple XDR alert types
- The playbook has been updated to refine the alert escalation process, and the ticket template has been augmented to include more comprehensive information enriched by XDR. The enhancements address the following alert types:
- Internal/External Trojan Activity
- AWS login without No Multi-factor authenticated (MFA) detected
04/19/2024 Playbook Enhancement: Improved logic for Azure AD Risk Detection
- The playbook has been extensively redesigned to incorporate a hybrid approach, having the nosier alert types have automatic escalation, while retaining manual options for others.
04/23/2024 New Detection: Google Workspace – 6 New Detections
1. AWS Identity Center Identity Provider Change
2. AWS Config Disabling Channel/Recorder
3. AWS CloudTrail Important Change
4. AWS IAM S3Browser User or AccessKey Creation
5. Restore Public AWS RDS Instance
6. AWS SecurityHub Findings Evasion

May 2024

###### Date of Update ###### Completed Items
05/01/2024 New Feature: CISA Vulnerability Scanners
- We have developed and implemented a new automated playbook action within our SOAR platform that retrieves the list of recognized external scanner IP addresses from the Cybersecurity and Infrastructure Security Agency (CISA). Consequently, any alerts generated by XDR systems that are attributed to authorized scanning activities from these IP addresses will be automatically resolved. This ensures that such benign alerts are not unnecessarily escalated as tickets to our clients.
05/06/2024 Alert Tuning: Suspicious User Agent Detection
- We have tuned out known benign user agents within our Stellar Cyber platform that are involved with ZoneAlarm, Nessus Scanners, Kaspersky Updates and DuckDuckGo web crawling.
05/08/2024 New Detection: User Impossible Travel Anomaly
- Enabled User Impossible Travel globally this detection triggers when a user logged in from locations that are geographically impossible to travel between in the time frame. The new rule takes the default XDR alert and correlates them to other high fidelity geo-location based alerts in order to improve the overall actionable items within each escalation.
05/08/2024 Playbook Enhancement: Google Workspace Phishing
- This playbook has been updated to add enrichment for Google Workspace Phishing detections for clients who also utilize Proofpoint, this additional enrichment provides additional information from the initial sender.
05/14/2024 Playbook Enhancement: Creation of forwarding and redirect rule
- This alert has been updated with improved information enriched from the original log events. This results in accurate ticketing information that can be used to either tune or take actions within the customer’s environment.
05/17/2024 New Detection: Google Workspace Suspicious Login
- A new threat hunting rule for our clients that have GSuite integration within stellar which alerts on “Suspicious Login” event activity. This alert utilizes GSuites logic for detections.
05/20/2024 Other: Improved Client knowledge base category for Vulnerability Scanners
- This change allows end-users to add both IPs and Hostnames within the Vulnerability scanner category for the CKB records. The playbooks on SOAR have been improved to accomodate both data types allowing users slightly improved flexibility in adding new records.

June 2024

###### Date of Update ###### Completed Items
06/03/2024 New Detections: XDR Rules
01. AWS Suspicious IAM Activity
02. AWS Suspicious Root Account Activity
03. AWS Suspicious Route 53 Activity
04. AWS Suspicious Bucket Enumeration
05. AWS Suspicious modification of Route table
06. AWS Suspicious VPC flow logs modification
07. AWS Malicious Activity
08. AWS Suspicious RDS event
09. AWS Suspicious EC2 Activity
10. AWS Suspicious modification of S3 bucket
11. AWS Suspicious EBS Activity
06/04/2024 Playbook Enhancement:
1. XDR: External User Success Brute-forcer Anomaly
- Improved ticket escalations specifically around the Okta login type.
2. XDR: Azure AD Risk Detections
- Improved playbook logic such that similar/duplicate alerts are grouped together while ensuring that alerts qualifying critical escalations are not missed/delayed.
3. XDR: GSuite Login outside the US
- In addition to creating this new alert type for customers who have compatible log sources, the playbook has also been enhanced to incorporate the existing “Travel Advisory” feature from Cyflare ONE portal.
06/09/2024 Alert Tuning:
- XDR: Outbytes Anomaly
- Improved alert fidelity by excluding default Microsoft IPs since they get flagged by the XDR tool as known false positives.
06/10/2024 New Detection:
1. XDR: Jump Cloud Command Run
- This new alert looks for the command_run event type in Jump Cloud logs for any commands that are run through the console and provides additional context around whether the activity is authorized or not.
2. XDR: Jump Cloud login outside the US
- This new alert looks for login activity based on geo-location and flags any anomalous behavior from users that are not expected to login from a certain country beyond the norm.
- Playbooks for this alert type have also been implemented to include travel advisories from the ONE portal to avoid known authorized travel activity.
06/12/2024 New Detection:
- XDR: Duo User Bypass Status Update
- This new alert will query for logs indicating that a user is put into bypass status in Duo portal which are known adversarial methods used by malicious actors to bypass multi-factor authentication and compromise user accounts.
06/14/2024 New Playbook:
- XDR: Microsoft 365 Data Destruction
- Playbook for this alert type has been improved with threat hunting queries curated specifically to provide context around this activity and giving accurate enrichment information about included entities.
- XDR: RDP Settings Hijacking
- Playbook for this alert type has been improved with threat hunting queries curated specifically to provide context around this activity. This also includes adding contextual lookups for known RDP servers from Client knowledge base in ONE portal.
06/16/2024 New Detection:
- XDR: AWS Console login outside the US
06/18/2024 Playbook Enhancement:
- XDR: AWS Console login outside the US
- Improved playbook logic around escalation with curated ticket template and improved fidelity by adding travel advisory look up from the ONE platform.
06/19/2024 Playbook Enhancement:
- XDR: Multiple Users deleted
- The playbook has been refined to augment the information presented during ticket escalations. This includes the incorporation of alert-specific look-ups that contribute valuable insights and present a comprehensive narrative of the events leading up to the alert being triggered.
New Detection:
- XDR: Potential Exploitation of CVE-2022-42475
- This detection was implemented to alert on any of the known indicators of compromise for CVE-2022-42475 for customers that forward FortiOS logs.
06/24/2024 Playbook Enhancement:
- XDR: Office365 and Azure login outside the US
- Activity flagged between Azure and Office365 are usually around the same time due to the fact that users access both of these resources while being outside the country. Anomalous behavior that correlates to the same user from both log sources will now get matched as duplicates and avoid creating additional tickets for customers.
06/27/2024 New Playbook:
1. SentinelOne: Inhibit System Recovery
2. Google Workspace: Suspicious Login

July 2024

###### Date of Update ###### Completed Items
07/01/2024 New Detections: XDR Rules
01. Azure Sign-in failures
02. Azure Discovery using Azurehound
03. Azure changes to Privileged role assignment
04. Azure PIN setting changed
05. Azure application configuration changes
06. Azure Unusual Account creation
07. Azure suspicious changes to conditional access policy
08. Azure guest user invited by non-approved invitees
09. Azure federation modified
10. Azure privileged account assignment or elevation
11. Azure changes to privileged account
12. Azure Bitlocker key retrieval
13. Azure changes to device registration policy
07/01/2024 Playbook Enhancement:
- EDR: Microsoft365 Defender
- This playbook now has additional improved enrichment queries specific to alert type “Activity from Anonymous Proxy” which makes the escalated ticket include improved contextual details around the activity.
07/02/2024 Playbook Enhancement:
1. XDR: Windows User Added/Removed from Local/Domain Admin Group
- These playbooks have been modified with additional look-ups to cover missing usernames from the original alert. A curated threat hunting query is used to fetch the user with the SID provided in windows events.
07/03/2024 New Playbooks: XDR
1. Windows Audit Log Cleared
2. Suspicious AWS EC2 Activity
3. Potentially Malicious AWS Activity
4. Remote Access Team Viewer
5. Multiple Administrator Account Lockouts
6. Suspicious AWS RDS Event
7. McAfee ESM Failed Login
07/04/2024 Playbook Enhancement:
- XDR: Private to Public Exploit Anomaly
- The ticket template has been improved with added details focusing on the original application responsible for triggering the external connection.
07/09/2024 Playbook Enhancement:
- Windows User Added to Local Administrator
- For certain alerts that don’t come with user information, playbook now accounts for those scenarios and runs additional lookup queries to XDR tool in order to fetch the user associated with the SID information.
07/15/2024 New Playbook: Microsoft 365
1. Password Spray
2. Antimalware Action Failed
3. Connection to adversary-in-the-middle AiTM phishing site
4. Malware Detection
5. Unfamiliar Sign-In Properties
6. Anomalous Token
7. Malware Was Detected in a CAB Archive File
07/16/2024 Playbook Enhancement:
- Suspicious PowerShell Script Detection
- This playbook now collects all pieces of the script that was flagged as suspicious and gives the analyst a better view of the purpose of the script and judge it potential malicious nature.
07/19/2024 Playbook Enhancement:
- AI Summarization
- XDR: Private to Public Exploit alerts now have this feature included where IDs signatures are interpreted by AI and an alert snapshot is generated to better explain what triggered and flagged the activity in the ticket.
- The information given to gen-AI is not confidential to any specific entity/company/user. All information provided by Gen-AI is still being reviewed by the SOC and still under beta-testing phase.
07/25/2024 New Playbook:
- XDR: Exploit attempt correlation
- This playbook was built from ground up using custom logic that correlates activity based on a previously seen exploit attempt alerts and adds further context when necessary.
- XDR: Potential User Compromise via Axios user agent
- This playbook now caters specifically for activity around axios user agent and auto-escalates cases to Critical when successful login attempts are observed by the SOC.
- XDR: M365 User added to privileged group
- The playbook now contains a tailored ticket template that includes threat hunting queries giving more context around the user’s activity around the time of this alert.

August 2024

###### Update Category ###### Completed Items
New Features New Automation Use Case:
- The SOC is now enabled with response actions associated with CrowdStrike EDR tool. Any customers utilizing CrowdStrike as their Endpoint security solution can reach out to their CSM and ask about further details on how we can integrate with the SOC’s response actions.
AI use-case within SOC incidents:
- The SOC playbooks are now beginning to get integrated with AI-capabilities to enhance our incidence response. Our playbooks seamlessly integrate with our custom built AI models and assist in summarizing and providing remediation steps for end-users.
- The use case is currently being leveraged by select few playbooks and SOC escalations will now feature an appropriate disclaimer when such integrations are present in the tickets.
Exempt Sites for EDR customers:
- To provide additional customization for automation use-cases catered for EDR tools, customers can now reach out to the SOC and provide specific site names to exempt from being considered for automated response actions permanently or for a specific period of time. This allows for unnecessary operational overhead in case an authorized activity is expected for certain endpoints/sites.
New Detections 1. XDR: Potential APT FIN7 Exploitation Activity
- This detection will alert on any of the known process chains seen associated with FIN7 as reported by Google. Rdpinit.exe spawning notepad++.exe or Notepad++.exe spawning cmd.exe
2. XDR: File Integrity Monitoring
- This detection will alert on a creation, modification, or deletion of files in the following file paths: C:\autoexec.bat, C:\boot.ini, C:\Windows\system.ini, C:\Windows\win.ini, C:\Windows\regedit.exe

C:\Windows\explorer.exe, C:\Windows\System32\userinit.exe, C:\Program Files\Microsoft Security Client\msseces.exe
New Playbooks XDR Alert types that now have a dedicated playbook for each detection making the triage and escalation workflow catered towards the type of activity:
01. SentinelOne – Virtualization Sandbox Evasion
02. Google Workspace Alert – XDR Login Anomaly
03. Suspicious AWS IAM Activity
04. Proofpoint Outbound Email Spike
05. DUO User Update Bypass
06. AWS Suspicious Root Activity
07. Microsoft Entra Sign-In Failure
08. Suspicious Modification of AWS CloudTrail Logs
09. Suspicious Modification of S3 Bucket
10. Azure changes to device registration policy
11. JumpCloud MFA Push Failure
12. Jumpcloud login outside the US
13. McAfee ESM failed login activity
14. Windows Domain policy changed
15. Suspicious AWS Route 53 activity
16. Microsoft Entra Suspicious changes to conditional access policy
17. Microsoft Entra application configuration changes
Playbook Enhancement 1. XDR: IDS Signature Spike
- The playbook now correlates already escalated exploit anomalies and automatically adds comments. For new anomalies, the playbook automatically resolves them to a new SOC escalation.
2. XDR: Duo login outside the US
- The SOC escalation template now includes correlated threat hunting searches that present contextual information around the flagged entities. Additionally, the playbook is also equipped with Customer Knowledge Base (CKB) lookup for known travel advisories for the user.
3. XDR: Multiple login from one workstation/Source IP/Destination IP
- The playbook was updated with specific threat hunting queries to provide entity-specific information and add reason to an alert being triggered.
4. XDR: GoFile Room User login failure
- It now include tailored threat hunting search queries via Stellar API and provides comprehensive context about the reported activity in the ticket escalated
5. AI use cases enabled for the following playbooks
- XDR: Office365 Content policy filter changed
- XDR: Azure user added to global admin group
- XDR: Malware Activity
- The SOC escalation template now includes Gen-AI use case integrated within The alert snapshot as well as catered remediation actions

All ticket templates will include an AI emoji indicating that corresponding text has been generated using Gen-AI.
6. Microsoft Defender Playbooks
- These playbooks now include an additional lookup for DNS hostnames and correlate the IP associated with known vulnerability scanner to improve alert fidelity and avoid obvious false positives.
7. XDR: User Impossible Travel Anomaly
- This playbook has built-in correlation for various alerts to ensure standalone alerts are not generated due to them being very sensitive. These now also include Azure AD (Entra) Risk Detection alerts as a correlated alert type.
8. XDR: Azure/Office365 Login outside the US
- As part of continuous improvement with playbook logic, the SOC has decided to implement an additional check for customers that have this alert type as muted. Moving forward, if the IP used to login has been marked malicious by OSINT, it will ignore the mute and continue to escalate as potential risky sign-in for that user.

September 2024

###### Update Category ###### Completed Items
New Playbook 01. Microsoft Entra changes to Privileged account
02. External Password Spraying Anomaly
03. Microsoft Entra Bitlocker Key Retrieval
04. Microsoft Entra PIM Setting changed
05. AWS Access Key created
06. Salesforce login outside the US
07. Potentially Malicious Windows activity
08. AWS Create User
09. Suspicious AWS EBS Activity
10. Internal DLP Rule Match
Playbook Enhancement Gen-AI use cases were implemented for the following playbooks:
- The SOC escalation template now includes Gen-AI use case integrated within The alert snapshot as well as catered rememdiation actions

All ticket templates will include an AI emoji indicating that corresponding text has been generated using Gen-AI
- XDR: Trojan Activity
- Darktrace detections
- XDR: Public to Private exploit anomaly
- Azure AD Risk detections
- Bad Reputation Anomaly
- Microsoft Entra Suspicious Changes to Conditional Access Policy
- User Impossible Travel Anomaly
- FIM – Created, Deleted, Modified
- Exploit Attempt Correlation
- Office365 detections
- Google Workspace detections
- Emerging Threat
- All login outside the US alerts – Office365, Azure, Duo, G-Suite, JumpCloud, etc
- DNS Tunneling Anomaly
Alert Tuning - XDR: Exploit Anomalies
- This alert type has recently been updated to trigger on a sub-event type identified as an IPS traffic anomaly. This event type is highly sensitive to traffic that has already been blocked by the firewall, which may result in a higher incidence of false positive alerts due to its lower fidelity.
- Additionally, the alert type “private to public exploit anomaly” will now auto-close all alerts that are triggered based on a known “ms-update” activity considering the IPs associated with alerts are clean on OSINT.
- Mimecast Detections
- Mimecast alerts types usually trigger from source tool even when mimecast has already handled the entity by marking them as rejected. The playbooks are now modified to validate if action is rejected and mark those as false positives.
New Detections 1. XDR: Google Workspace detections
- Google Workspace Deny Access Request
- Google Workspace Unassign Role
- Google Workspace Assign Role
- Google Workspace Password Edit
- Google Workspace Revoke 3LO Token
- Google Workspace Move User To Organizational Unit
- Google Workspace Create User

October 2024

###### Update Category ###### Completed Items
New Features Alfie Insights
- We’re excited to introduce a new feature designed to provide greater transparency and visibility in the ticket escalation process. Many clients have expressed interest in understanding the checks and queries run by our playbooks when they are not all fully detailed in the ticket notes. Alfie Insights will address this need by making that information visible across all escalations.
- The purpose of this feature is for our customers to review and provide feedback on how our playbooks are operating and to be vocal about issues with the logic that we have in place. This new feature, Alfie Insights, is now available in Beta and can be found at the bottom of all escalated tickets.
Playbook Enhancement - The SOC has improved the following playbooks to contain higher enrichment-related information and improved automation around threat hunting by creating custom search queries on the XDR tool.
- Salesforce Login outside the US
- Potential Token Theft anomaly
- Multiple Login Failures from One Source IP
- O365 Multi Factor Authentication Disabled
- Microsoft Entra Changes to Privileged Account
- Google Workspace User Deleted
- Microsoft Entra Custom Domains Changed
- Jumpcloud MFA Push Failure
- Microsoft Entra Suspicious Changes to Conditional Access Policy
- The follow playbooks among others now include AI summarization helping overall ticket quality while highlighting key details, addressing main issues flagged by the source tools:
- O365 Multi Factor Authentication Disabled
- Potential Token Theft
- Google Workspace User Deleted
- Jumpcloud MFA Push Failure
- Potentially Malicious AWS Activity
- All Suspicious AWS Activity alerts
New Detection The following custom detections were built by the SOC as part of our continuous alert coverage improvement:
1. Potential Pass the hash Asset Access Anomaly
2. LastPass Detections:
1. Multiple Failed login attempts
2. Master Password changed
3. Suspicious User-specific activity
4. Access-control related activity
3. Forti Manager Potential Vulnerability
1. Activity related to exploitation of CVE-2024-47575, was detected. This may indicate potential RCE attempts from the source host.
4. Potential JumpCloud Radius Brute-force attempt
5. Box – File Marked Malicious
Alert Tuning 1. Microsoft 365 – XDR UBA Anomaly
- If the Mail was blocked or quarantined, auto-close the alert.
2. Potentially Malicious Windows Activity
- Alert priority is elevated to a High is the event ID is 5001
3. AWS Malicious Host Access
- Due to low fidelity, this alert will be muted if contains no malicious IOCs based on OSINT lookups
4. IDS Signature Based Alerts
- Since these can be pretty noisy and mostly handled by firewall ACLs – when IDS severity is set to Low and contains no malicious IOCs, the alert will be muted with as no further action necessary.
Other The SOC has also enabled and built custom integrations for the following Cyflare Services offerings:
1. Vicarius – Vulnerability Scanning Service (VSS)
2. Checkpoint Harmony Email Security – Managed Email Security (mESS)
3. CrowdStrike – Managed EDR (mEDR)
-  These Services are now SOC-enabled with appropriate playbooks/integrations built within the SOAR. Please reach out to your CSM for further information about SOC use cases.

November 2024

###### Update Category ###### Completed Items
New Features SentinelOne Lateral Movement Playbook Workflow
- When SentinelOne identifies a suspicious lateral movement to an endpoint, it is typically detected on the destination host, where the lateral movement is received. The SOC then investigates and prevents the lateral movement from spreading by isolating the destination host using the SentinelOne endpoint agent.
- However, with enhancements to the workflow logic, the automated playbooks can now also identify the source of the flagged lateral movement. This allows for a similar response to be executed on the source host, provided it also has the SentinelOne agent installed. This proactive approach ensures that threats are contained more effectively at both ends of the lateral movement.
Stellar Cyber XDR platform Upgrade
- Stellar Cyber platform was upgrade to version 5.3.0. Introduced Detection Management in Stellar Cyber Open XDR 5.3.0. Detection Management enhances SOC teams’ control over detection rules, providing customizable alert settings, real-time insights, and improved visibility for optimized threat detection.
- Supplemented the existing query builder and alert filter builder with a new, unified interface for creating and testing queries and creating alert filters: the Query and Filter Manager. You can now create queries and alert filters through a cohesive experience.
Alert Tuning - Azure AD Risk Detection
- Prior the change, the SOC was checking AbuseIP for enriching entities before applying tuning logic for auto-closing low priority alerts. After this change, the SOC enriches both VirusTotal and AbuseIP as a criteria for checking if the IP is malicious.
Playbook Enhancement - External Password Spray
- The SOC updated logic for these alerts where escalation will be raised to a Critical due to the nature of the activity.
- The logic workflow also considers OSINT enrichment to further validate criticality of the escalation
- Microsoft Entra Changes to Privileged Account
- The updated logic now mutes when sub-rule “Password reset by User Account” since this activity is reporting a regular password update by the user instead of any privileged activity.
- Windows User Added to Local Administrators Group
- Updated searches involving Member SID to populate additional usernames that are usually unavailable.
- Following playbooks have been modified and updated with specific threat hunting queries that are being used within the ticket escalation and enhancing overall quality of tickets:
- Microsoft Entra Sign-in Failures
- Bad Source reputation Anomaly
- Delete conditional-access policy
- Internal/External Port Scan anomalies
- Internal Password spray

December 2024

###### Update Category ###### Completed Items
New Features Use Case #2 – Automated Notification System
- As part of our ongoing commitment to enhancing SOC services and fostering automation with intelligent workflows, we are excited to introduce the updated Automated Notification System under Use Case #2.
- This automation is uniquely designed to notify customers about time-sensitive events being monitored or triaged by the SOC. Unlike other SOC automation use cases, this system focuses on delivering real-time alerts in critical scenarios, such as when the SOC takes response actions to block specific IOCs within the environment.
- By integrating with tools such as Slack, Microsoft Teams, and xMatters, the system ensures that brief, relevant notifications are automatically sent to designated user groups. This enables timely reviews of SOC ticket updates and facilitates seamless progression through the incident response plan without unnecessary delays.
- Additionally, enhanced workflow logic now allows automated playbooks to identify the source of flagged lateral movement. If the source host is protected by a SentinelOne agent, the system can execute a similar containment response on that host. This proactive capability significantly improves the SOC’s ability to contain threats at both ends of a lateral movement, ensuring a more robust and effective response.
New Action: Fetch Events by ID (mEDR SentinelOne)
- This action retrieves events for a given Threat ID, filtered by optional Event Types (e.g., process, ip,dns,url). This will provide more context to a given case to enhance an investigation or decision making. This will further be used in improving prompts for AI usage within the ticket escalations.
Playbook Enhancement - AI Summarization 🤖 was added to the following playbooks:
- Cloud Account Login Failure Anomaly
- External Malware Activity
- External/Internal User Success Brute-Forcer
- User Login Failure Anomaly

Defender M365 – File shared with personal emails
- Possible Shadow Credentials
- All Exploit Anomalies
- Trojan Activity
- The SOC has improved the following playbooks to contain higher enrichment-related information and improved automation around threat hunting by creating custom search queries on the XDR tool.
- Possible Shadow Credentials
- Potentially Malicious Windows Activity
- M365 Valid Accounts – Initial Access
- Mimecast AV Phishing
- Okta – Attempt to Deactivate Okta Application
- Multiple Failed Logins to SQL Server
- Improved Use Case #6 – Auto-isolate Endpoint for EDR
- For SentinelOne customers, the “Disconnect Agent From Network” action now disconnects agents using hostname or IP address by Site ID. This prevents account-wide disconnections that affected multiple agents with the same name or address.
- Improved SentinelOne workflow to clean up straggling threats that appear to be untouched by the SOC
- With the added steps in the workflow, the playbooks now close and mark threats in SentinelOne UI with appropriate reasoning when they’re grouped to a single case within the SOAR platform. This will avoid various duplicate threats appear as unmitigated threat on the endpoint.
New Detections - XDR: ProofPoint TAP Permitted Clicks
- New global detection looking for clicks that are allowed before a threat is identified in scenarios where user has already interreacted with the threat and Proofpoint flagged it as a threat after the fact.
Alert Tuning - Mimecast AV: Phishing
- The SOC is now muting when Sender Domain is related to the testing site psm.knowbe4.com.
- All types of Successful Login outside the US
- Playbooks have been adjusted to ensure different username fields from source tools are accounted for workflow logic like travel advisories.
- Additionally, all outside US login alert types have a custom workflow for Malicious entities. Moving forward, because of this workflow, regardless of being muted, the SOC will escalate scenarios where the login has been observed from a known malicious source IP.
Other - mXDR Connect – Cortex XDR
- The SOC is now able to consume alerts from PaloAlto’s SIEM platform called Cortex XDR. With playbooks built and integrations ready to use within the SOAR platform, customers can enable SOC monitoring for their existing Cortex XDR instances.
- mXDR Connect – Cisco XDR
- Similar to Cortex, the SOC has custom built an integration with the tool to ingest incidents, and triage them with other relevant API integrations.

2023 Change Logs by Month

September 2023

###### Date of Update ###### Completed Items
9/4/2023 Alert Tuning: Abnormal Parent-Child Process
- Increased fidelity and threshold of escalation, more used for correlative behavior, analytics, and investigations now. Other detections are enabled in response to this change.
9/4/2023 Playbook Enhancement: O365 – Malicious URL Clicked
- Modified playbook logic and updated ticket template
9/4/2023 Alert Tuning: Suspicious User Agent Detection
- Muting of low fidelity IOCs related to this detection that are not actionable, data will still exist within analytics and can be correlated with other detections/activity.
9/4/2023 Alert Tuning: Cold Fusion Vulnerability
- Updated the Stellar custom ATH rule to run every 10 minutes and will also combine the result of every detection per tenant rather than multiple detections at once.
9/5/2023 New Detection: Suspicious Process Creation Commandline Detection
- Enabled new ATH Rule for all tenants that includes the following types of detections:
01. Empire PowerShell UAC Bypass
02. Emotet Process Creation
03. LockerGoga Ransomware
04. CrackMapExec Command Execution
05. Suspicious Use of Procdump on LSASS
06. Unidentified Attacker November 2018
07. Winnti Pipemon Characteristics
08. PowerShell Base64 Encoded Shellcode
09. Ryuk Ransomware
10. DTRACK Process Creation
11. ShimCache Flush
12. Snatch Ransomware
13. TropicTrooper Campaign November 2018
9/5/2023 Template Update: CrowdStrike: Disable or Modify Tools
- Template modification to enhance the quality of escalated tickets and analyst triage process
9/6/2023 Playbook Enhancement: Azure AD Risk Detections
- Modified playbook logic and updated ticket template
9/6/2023 Playbook Enhancement: Azure Login Outside the US
- Modified playbook logic and updated ticket template
9/6/2023 Playbook Enhancement: Custom Sophos EDR Detections in Stellar
- Modified playbook logic and updated ticket template
9/12/2023 Template Update: Applied a Fix for Critical IR Cases
- Fix was applied to all Critical cases where the ticket did not reflect a critical priority
9/14/2023 Playbook Enhancement: Office365 and Azure – Successful Login outside the US
- Modified ticket template to include a link for Travel Advisory that can be added for known authorized travel.
- Travel Advisory lets clients let the SOC know when a user in their environment travels. The SOC will then see this activity is authorized and not escalate the action.
9/21/2023 Playbook Enhancement: Modified External User Success Brute-force Anomaly
- Upon identifying IP addresses flagged as malicious due to OSINT findings and SSH login attempts, the SOC will promptly initiate Incident Response procedures and notify customers using the available information.
9/25/2023 Playbook Enhancement: Google Workspace Phishing Alert
- Added glue book functionality where if the customer has Proofpoint integration, the information from the same Proofpoint log event can be added within ticket details.
- Modified playbook logic and updated ticket template.
9/25/2023 Playbook Enhancement: SentinelOne (Endpoint Isolation)
- Depending on the defined policy, SentinelOne may isolate an endpoint from the network as a remediation step when detecting suspicious or malicious threats. In the future, the SOC will proactively initiate Incident Response procedures whenever SentinelOne isolates an endpoint based on the policy configuration.
9/25/2023 New Feature: Critical Incident Handler Emails
- Clients can now update their Critical IH plan with different emails, such as the Primary and Secondary Contacts within tickets.
- Please reach out to your Assigned CSM to get this updated.
9/27/2023 New Detection: Suspicious PowerShell Script Detection
- Enabled new ATH Rule for all tenants that includes the following types of detections:
01. PowerShell Mailbox Collection Script
02. Suspicious Portable Executable Encoded in Powershell Script
03. PowerShell Suspicious Script with Screenshot Capabilities
04. PowerShell Script with Token Impersonation Capabilities
05. PowerShell Invoke-NinjaCopy script
06. PowerShell Suspicious Script with Audio Capture Capabilities
07. PowerShell Suspicious Script with Clipboard Retrieval Capabilities
08. PowerShell Share Enumeration Script
09. PowerShell Script with Encryption/Decryption Capabilities
10. PowerShell MiniDump Script
11. PowerShell PSReflect Script
12. PowerShell PSAttack
13. Computer Discovery And Export Via Get-ADComputer Cmdlet – PowerShell
14. Access to Browser Login Data
15. Invoke-Obfuscation CLIP+ Launcher – PowerShell
16. PowerShell ICMP Exfiltration
17. Powershell Directory Enumeration
18. Suspicious Hyper-V Cmdlets
19. Change User Agents with WebRequest
20. Suspicious Get-ADReplAccount
9/27/2023 New Detection: Kerberos Replay Attack Detected
- Looking for relevant Windows Event IDS if a request was received twice with identical information.
9/27/2023 New Detection: SoftPerfect Network Scanner Execution
- Looking for any activity related to the SoftPerfect Network Scanner Product via Process Name/Command Line Activity
9/29/2023 Playbook Enhancement: Malware Activity
- The SOC identified significant tuning opportunities with this specific alarm type.
- Utilizing firewall responses to ignore alerts when the firewall has already blocked them
- Auto-closing certain low-priority IDS Signatures based on the lack of network traffic observed between the flagged domain and the internal host.
9/29/2023 Playbook Enhancement: Possible Impacket SecretDump Remote Activity
- The playbook was created with updated logic and modifications for the observed remote activity.

October 2023

###### Date of Update ###### Completed Items
10/02/2023 Playbook Enhancement: DPAPI Domain Backup Key Extraction
- Modified playbook logic and updated ticket template.
10/03/2023 Response Action: Microsoft Defender
- The SOC has enabled response actions for Microsoft Defender within playbooks.
- Customers who choose this option will empower the SOC to promptly initiate incident response upon detecting critical Defender events, without unnecessary delays while waiting for customer input to identify actions.
- The SOC is well-equipped to execute specific response actions and deliver comprehensive details during escalations, ensuring timely and informed incident handling.
1. Initiate AV scan on the endpoint
2. Stop and Quarantine file
3. Isolated endpoint from network
10/04/2023 Playbook Enhancement: Suspicious PowerShell Script Detection
- Modified the ticket template to include additional information about the rule and query that was observed within the detection.
10/04/2023 Playbook Enhancement: Office365 Successful Login outside the US
- Modified the playbook to handle multiple instances where usernames are either not available or have different field names from XDR tool.
- These are now being normalized and handled accordingly.
10/05/2023 New Detection: Multiple Users Deleted
- A detection focused on detecting an abnormal number of users deleted in a short amount of time via Windows Events.
10/09/2023 Playbook Enhancement: Azure XDR Successful Login outside the US
- Modified playbook logic and updated ticket template.
- SOC Response actions were added as part of playbook automation where the SOC has the ability to take response actions when an anomalous login from an unfamiliar location is observed.
- These actions can be from the following:
1. Revoke user session
2. Force password update
3. Reset password
4. Disable user account
10/10/2023 New Detection: Multiple Failed Login Attempts from One Source/Destination/Workstation
- To be able to continue monitor and cover any potential brute-force attempts, excessive login failures, password spraying, etc.
- The SOC implemented a custom detection that can catch multiple logins failures from a singular source/destination/workstation.
- This improves fidelity and reduces noise from the usual login failure alarms that are triggered in XDR platforms.
10/11/2023 Playbook Enhancement: Get Hash from String
- Added a new functionality within SOAR that allows playbooks to hash any larger text and compare to already defined hashes in order ensure known entities are excluded accurately.
- For example, if certain PowerShell scripts are known to run, the SOC can hash the script text and validate any future detections for suspicious PowerShell scripts.
10/12/2023 Playbook Enhancement: External Malware Activity
- Modified playbook logic and updated ticket template.
- Our logic now looks into firewall actions as well as IDS signatures.
- For domain specific IDS signatures, domain query searches are now included within escalation details.
10/13/2023 New Detection: Azure AD Sign in from AzureHound
- Detects AzureHound (A BloodHound data collector for Microsoft Azure) activity via the default User-Agent.
10/19/2023 Revamped Ticket Templates
- The new template enhances readability and provides convenient access to relevant information. This change marks a significant step toward the upcoming ONE v2.0 platform, which will further elevate the user experience and streamline SOC communication.

- The following detections were improved:

01. RDP Brute Force Attack

02. RDP Reverse Tunnel

03. RDP Suspicious Logon Attempt

04. RDP Suspicious Logon

05. Windows User Added to Domain Admins Group – Global

06. Windows User Added to Enterprise Admins Group – Global

07. Windows User Added to Local Administrators Group – Global

08. Windows User Added to Schema Admins Group – Global

09. Windows User Removed from Domain Admin Group

10. Windows User Removed from Local Admin Group
10/23/2023 Playbook Enhancement: Improvement to Sophos Escalation
- Modified Sophos ticket templates within playbooks to individually highlight various detections from operational to malicious hits.
10/25/2023 SLA Change
- With the release of our new offerings in “SOC Support Program & SLA Overview” we have made adjustments to SLA plans for all previous “Essential” Tenants.
- With this change all clients who were “Essential” or “Enhanced” have been moved to an “Advanced” SLA Plan.
- All previous “Premiere” level clients will remain at this level.
- For more information please refer to the following link: https://cyflare.com/wp-content/uploads/SOC-Support-and-SLA-Overview-REV04_1023_FINAL.pdf
- Alternatively you can reach out to your Assigned CSM to get more information.
10/26/2023 Revamped Ticket Templates (Continued)
- This is a continuation of our ticket template enhancement process, these will be ongoing throughout the rest of the month and November.
- The following detections were improved:
01. Command and Control Reputation
02. Credential Stuffing
03. Emerging Threat
04. Sophos EDR
05. Windows Account Lockout Event
06. Windows Domain Policy Changed
07. Windows Security-Enabled Global Group Created
08. Windows Security-Enabled Local Group Created
09. Windows Security-Enabled Universal Group Created
10. Windows Unauthorized Password Reset
10/27/2023 Alert Tuning: Suspicious PowerShell Script – SentinelOne Related Detections
- Logic adjusted to no longer escalate SentinelOne related processes for clients utilizing our MDR solutions.

November 2023

###### Date of Update ###### Completed Items
11/03/2023 New Feature: SOAR monitoring for XDR log ingestion
- The SOC has now enabled a new features where all XDR instances will be monitored for their log ingestion every 6 hours. If no logs were ingested in the time period, an investigation will be initiated by the SOC.
11/06/2023 Gen AI: Launched within SOAR
- At Cyflare, all analysts now benefit from the integration of Generative AI into their case investigations. This advanced feature facilitates the provision of historical context for received alerts and offers comprehensive recommendations for potential remediation actions.
11/07/2023 Ticket Templates Revamped: Project Update
- The SOC has been working towards making all the ticket escalations more cohesive and easy to read. As part of this project, the SOC completed over 90% of the tickets being escalated.
11/08/2023 Playbook Enhancement: Improved utilization of Client Knowledge Base
- The SOC has refined all playbooks designed for network traffic-related alerts to exclude known vulnerability scanners from the Client knowledge base, resulting in their automatic closure. This enhancement is expected to enhance the accuracy and reliability of cases escalated by the SOC.
- Added “Potential Shell Shock” lookup for Vulnerability scanners to avoid escalating False Positives for known scanners in the environment.
11/16/2023 Template Update: Ticket Template updated for Exploit Anomalies
- For all exploit anomalies related to DNS queries, the SOC has updated ticket templates so we are including investigation details associated with the specific domain flagged in network events.
11/16/2023 New Playbook: M365 Defender
- For customers having dedicated M365 Defender integrated with SOAR, the SOC is now equipped with a dedicated playbook custom built to investigate and manage Defender alerts. Some features of the playbook includes: Threat hunting queries for defender, incident management, glue book functionality for correlating other events from XDR platform.
11/21/2023 Playbook Enhancement: External User Success Brute-force Anomaly
- In the event that a flagged user has a history of successful logins, the SOC performs a validation check within the last hour to identify any events with error code 70044. This error code signifies instances where the session has either expired or become invalid due to sign-in frequency checks imposed by conditional access. To mitigate the occurrence of false positives, playbooks will be automatically closed when the specified condition is fulfilled.
11/22/2023 Template Updates: New Ticket Templates
- Duo Security Failed Authentication
- Terry Server External outbound Traffic
- Microsoft 365 – XDR NBA Rule Violation
- Custom Darktrace detection
- Suspicious Scan Loop on Network
- Multiple Login failures from one Source IP
- Duo Security Failed login
- Multiple User Deleted
- Windows User Account Changed
- Box Shield Alert
11/23/2023 Playbook Enhancement: Change to Login Outside the US Alerts
- Our playbook now closes these detections from escalation if the following error codes are generated:
- 53003 – Access has been blocked due to conditional access policies
- 50126 – Invalid username or password or Invalid on-premises username or password, automatically close as benign.
11/24/2023 Template Update: Change to Subject Line for Escalated Tickets
- Moving forward, all tickets will have alert priority mentioned towards the end of the subject line. This is mainly to assist with customers to prioritize certain tickets before informational/low alarms.
11/28/2023 Playbook Enhancement: M365 Defender using GlueBook Functionality
- Adding glue book functionality to “Internal User success brute-forced login anomaly” playbook with Defender threat hunting queries.
- This will add value to investigations done by the SOC for customers that have defender API functionality. For known mananged devices based on AzureAD records in Defender, we will auto-close these alerts as they give little to no security implication.

December 2023

###### Date of Update ###### Completed Items
12/04/2023 Playbook Enhancement: Vulnerability Scanners in Exploit Attempt Detections
- Now have logic to mute all Exploit Attempts from being escalated when triggered by a Vulnerability Scanner that is in a client’s CKB.
12/05/2023 Playbook Enhancement: IP Location Lookup
- For any playbook involving an IP Location as the reason for escalation we have added logic to verify the IPs location within the playbook prior to escalation.
12/08/2023 Playbook Enhancement: CISA Vulnerability Management IPs
- The Cybersecurity and Infrastructure Security Agency (CISA) regularly release known public IPs they utilize for external scanning.
- Cyflare has leveraged this list and will not escalate any detections to clients if it matches a CISA defined IP Address.
- Find the list here: https://rules.ncats.cyber.dhs.gov/
12/08/2023 Playbook Enhancement: Successful Logins Outside the US
- Any Successful Login Outside the US will be checked to see if there is an open ticket in the past 24 hours for it, if yes then close the repeat alert.
- This was done in an effort to eliminate spam on an already escalated ticket that a client should already have on their radar.
- If the activity resurfaces after 24 hours, we will comment on the already escalated ticket.
12/13/2023 Playbook Enhancement: User Success Brute-Forcer (IPv6 Check)
- If the Source IP is an IPv6 formatted IP the SOC will perform extra checks to ensure the tickets gets the necessary information.
12/13/2023 Playbook Enhancement: Multiple Login Failures from One Source IP
- This playbook now has a CKB Lookup for Vulnerability Scanners as we noticed scanners had frequently been triggering this Custom ATH Rule.
- If the IP involved is a Vulnerability Scanner it will not get escalated as a ticket.
12/15/2023 New Detection: Password Spray
- Alert introduced in a recent Stellar Update.
- The detection is looking for an anomalously large number of failed logins with multiple different user names involved and failures originating from One IP.
12/15/2023 New Detection: Port Scan TSA
- Alert introduced in a recent Stellar Update.
- This is a new variation of port scanning by Stellar that leverages “Time Series Analytics (TSA) Model”.
- TSA model based detections involve three different types of detections:
- Spike detection
- Continuous low detection
- Rare detection
12/15/2023 New Detection: IDS Signature Spike
- Alert introduced in a recent Stellar Update.
- Detection looking for a source IP address that has transmitted an anomalous number of different IDS signatures.
12/19/2023 New Detection: DarkTrace Stellar Integration
- Detection for clients who utilize DarkTrace within their Stellar Environment.
- We are only tracking DarkTrace Detections with a severity of 7 or higher.
- Any client who would like a lower threshold will have to request this with the Cyflare SOC.
12/19/2023 Playbook Enhancement: Device Management and Condition Check
- Logins outside the US no check if the device is managed and if the Conditional Access status is successful.
12/21/2023 Playbook Enhancement: Office 365 Content Filtering Policy Changed
- This alarm type had a issues associated with the data fields being provided from Office 365 API Source.
- The playbook is now accommodating for the lack of details provided, or too many details provided.
- The new template will addjust accordingly to maintain readability and effective formatting.
12/24/2023 New Feature: Custom Python Functions
- Within SOAR playbooks, the SOC has the ability to create custom python-based actions on the data fields that are ingested from various source tools.
- This helps us create conditional criteria based on certain fields that are not always available via Stellar connector logs.
- This is only applicable for those who request something unique to be done via a Python Function and if we have a connector within SOAR.

© 2026 Cyflare