From 3bca4e7e6f09f1815ff0d89b38a61872e8585255 Mon Sep 17 00:00:00 2001 From: Julian Crowley Date: Wed, 5 Aug 2026 13:02:10 -0600 Subject: [PATCH 1/3] Update normalized-threat-rules.md Adds new detection passthrough classes and reflects current state of migration --- docs/cse/rules/normalized-threat-rules.md | 42 +++++++++++++++++++++-- 1 file changed, 40 insertions(+), 2 deletions(-) diff --git a/docs/cse/rules/normalized-threat-rules.md b/docs/cse/rules/normalized-threat-rules.md index 5324b82dfb2..45c27e0b4c7 100644 --- a/docs/cse/rules/normalized-threat-rules.md +++ b/docs/cse/rules/normalized-threat-rules.md @@ -30,7 +30,7 @@ For example, a normalized threat rule that looks for intrusions would work with * IPS/IDS Appliances * Microsoft Graph Security API -Ordinarily, rules define the log messages they’ll be applied to by specifying `metadata_vendor` and `metadata_product `in the rule expression. A normalized rule doesn’t specify these attributes. Instead, it looks at another attribute that is set during the log mapping process: `threat_ruleType`. In the log mapping process for a message type, the value of `threat_ruleType` is set  to a value that corresponds to a threat type, for example “intrusion”. Then, normalized threat rules can look for messages whose `threat_ruleType` field is “intrusion”, regardless of vendor or product. For information about mapping requirements for messages that describe security events, see [Field Mapping for Security Event Sources](/docs/cse/schema/field-mapping-security-event-sources). +Ordinarily, rules define the log messages they’ll be applied to by specifying `metadata_vendor` and `metadata_product `in the rule expression. A normalized rule doesn’t specify these attributes. Instead, it looks at another attribute that is set during the log mapping process: `threat_ruleType`. In the log mapping process for a message type, the value of `threat_ruleType` is set  to a value that corresponds to a threat type, for example “intrusion”. Then, normalized threat rules can look for messages whose `threat_ruleType` field is “intrusion”, regardless of vendor or product. For the full list of values, see [Types of normalized threat rules](#types-of-normalized-threat-rules). For information about mapping requirements for messages that describe security events, see [Field Mapping for Security Event Sources](/docs/cse/schema/field-mapping-security-event-sources). ## Types of normalized threat rules  @@ -99,6 +99,44 @@ Log sources that issue behavior-related messages include: * Varonis UBA * G Suite Alert Center   +Out-of-the-box log mappings for behavior-based detections are being migrated to six more granular classes. See [Behavioral detection classes](#behavioral-detection-classes). After migration, `direct` is retained for out-of-the-box mappings from generic sources that can't be assigned to a single class, such as the Microsoft Graph Security API catch-all mappings. + Cloud SIEM provides the following normalized direct rule: -* [Normalized Security Signal](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/rules/MATCH-S00402.md) - Passes through an alert from an endpoint security product and adjusts the severity accordingly based on the severity provided in the log. +* [Normalized Security Signal](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/rules/MATCH-S00402.md) - Passes through an alert from a security product and adjusts the severity accordingly based on the severity provided in the log. + +### Behavioral detection classes + +Cloud SIEM divides behavior-based detections into six classes, each with its own normalized rule, class-specific entity selectors, and summary expression. These classes give you more granular categories for tuning and more context from the underlying alert than the single [Normalized Security Signal](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/rules/MATCH-S00402.md) passthrough rule provides. All six rules pass through the [normalizedSeverity](/docs/cse/schema/schema-attributes) value from the log. + +| `threat_ruleType` | Rule | Primary asset field | Out-of-the-box mapping migration | +|---|---|---|---| +| `runtime` | [Normalized Runtime Detection](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/rules/MATCH-S01159.md) | `device_hostname` | Completed August 4, 2026 | +| `identity` | [Normalized Identity Detection](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/rules/MATCH-S01161.md) | `user_username` | Completed August 4, 2026 | +| `network` | [Normalized Network Detection](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/rules/MATCH-S01162.md) | `srcDevice_hostname` | Target: August 13, 2026 | +| `data_protection` | [Normalized Data Protection Detection](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/rules/MATCH-S01163.md) | `resource` | Target: August 13, 2026 | +| `cloud` | [Normalized Cloud Detection](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/rules/MATCH-S01160.md) | `resource` | Target: August 27, 2026 | +| `endpoint` | [Normalized Endpoint Detection](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/rules/MATCH-S01158.md) | `device_hostname` | Target: August 27, 2026 | + +:::note +All six rules are available now, but out-of-the-box log mappings are migrating in phases. The `runtime` and `identity` mappings have migrated. The remaining dates in the table are targets and may shift. For the actual dates that out-of-the-box mappings migrate, monitor the [Cloud SIEM content release notes](/release-notes-cse/). Until a source's out-of-the-box mappings are migrated, its records keep a `threat_ruleType` of `direct` and continue to fire [Normalized Security Signal](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/rules/MATCH-S00402.md). + +This migration changes only out-of-the-box log mappings. Your own log mappings aren't affected, and they keep whatever `threat_ruleType` value you set. To send records from your own mappings to one of the new rules, set `threat_ruleType` to that class. +::: + +Classes are assigned per log mapping, not per vendor, so a single security product can contribute to several classes. For example, out-of-the-box CrowdStrike log mappings are assigned to `endpoint`, `identity`, `network`, and `data_protection`. + +* **runtime**. Container and cloud-native runtime detections from workload security agents: Falco, Sysdig Secure, Twistlock (Prisma Cloud Compute), and Aqua Security. +* **identity**. Identity and access anomaly detections, such as risky sign-ins, impossible travel, and compromised credentials: Azure AD Identity Protection, Microsoft ATA, Microsoft Graph Identity API, MCAS/Defender for Cloud Apps, Google Workspace Alert Center, Slack Enterprise, Okta, DocuSign Monitor, Exabeam, Salesforce, Box, and CrowdStrike Identity Protection. +* **network**. Network-layer, NDR, and WAF detections, such as IDS/IPS alerts, command-and-control callbacks, and lateral movement indicators: Kemp LoadMaster WAF, Palo Alto Firewall, FortiGate, FireEye NX/CMS, Vectra AI, Claroty xDome, Darktrace, AlphaSOC, CrowdStrike FDR, Bitdefender, and Trend Micro. +* **data_protection**. DLP, email security, deception, and application security detections: Egnyte DLP, Varonis, Netskope, Akamai CPC, Noname API Security, Check Point Avanan, Proofpoint TRAP, Mimecast, Thinkst Canary, Contrast ADR, Qualys, IBM Guardium, Office 365 DLP, CrowdStrike DataProtection, Fortinet, and Google Workspace. +* **cloud**. Cloud posture, cloud threat, and cloud infrastructure detections: AWS GuardDuty, AWS Security Hub, Google Cloud SCC, GCP IDS, Orca Security, Wiz, Palo Alto Prisma Cloud, and Azure. +* **endpoint**. EDR and EPP behavioral detections from host-based security agents: CrowdStrike Falcon, SentinelOne, Carbon Black, Cylance, Cisco AMP, Cybereason, Endgame, Jamf Protect, Malwarebytes, McAfee, Palo Alto Cortex XDR, Sophos, Tanium, Trend Micro, Windows Defender, FireEye HX, Azure Defender for Endpoint, Google Workspace, and Bitdefender. + +#### Migrate custom content + +Custom content that depends on [Normalized Security Signal](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/rules/MATCH-S00402.md) won't apply to records once their out-of-the-box mappings are migrated. For sources that haven't migrated yet, make these updates before their target date: + +* Re-scope any [rule tuning expressions](/docs/cse/rules/rule-tuning-expressions) on `MATCH-S00402` to the new rule IDs for those sources. +* Update any [custom insights](/docs/cse/records-signals-entities-insights/configure-custom-insight) that reference `MATCH-S00402`. +* Update saved searches, dashboards, or automations that filter on `threat_ruleType = 'direct'`. From 2c4014550734409b1846e0590b04ecd52f5d2a35 Mon Sep 17 00:00:00 2001 From: Julian Crowley Date: Tue, 18 Aug 2026 16:18:16 -0600 Subject: [PATCH 2/3] Update normalized-threat-rules.md --- docs/cse/rules/normalized-threat-rules.md | 182 ++++++++++++++++++---- 1 file changed, 153 insertions(+), 29 deletions(-) diff --git a/docs/cse/rules/normalized-threat-rules.md b/docs/cse/rules/normalized-threat-rules.md index 45c27e0b4c7..d1ee23d3683 100644 --- a/docs/cse/rules/normalized-threat-rules.md +++ b/docs/cse/rules/normalized-threat-rules.md @@ -90,50 +90,174 @@ Cloud SIEM provides the following normalized malware rules: For messages that indicate suspicious or malicious activity based on behavior, rather than a signature. These messages don’t usually include a signature, instead might contain the command line arguments and other actions taken by the adversary. -Log sources that issue behavior-related messages include: +Behavior-based detections are divided among the six more specific types described below. The `direct` type is retained for out-of-the-box mappings from generic sources that can't be assigned to a single type, such as the Microsoft Graph Security API catch-all mappings, and for your own log mappings that set `threat_ruleType` to `direct`. + +Log sources that remain mapped to `direct` include: -* CrowdStrike Falcon * Symantec Endpoint Protection EDR -* Carbon Black Response +* Microsoft Graph Security API + +Cloud SIEM provides the following normalized direct rule: + +* [Normalized Security Signal](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/rules/MATCH-S00402.md) - Passes through an alert from a security product and adjusts the severity accordingly based on the severity provided in the log. + +### endpoint + +For messages from host-based security agents that detect suspicious or malicious behavior on an endpoint, such as EDR and EPP detections. + +Log sources that issue endpoint-related messages include: + +* CrowdStrike Falcon +* SentinelOne +* Carbon Black +* Palo Alto Cortex XDR +* Windows Defender and Azure Defender for Endpoint +* Sophos +* Trend Micro +* McAfee +* Cylance +* Cisco AMP +* Cybereason +* Endgame +* Jamf Protect +* Malwarebytes +* Tanium +* FireEye HX +* Bitdefender +* Google Workspace + +Cloud SIEM provides the following normalized endpoint rule: + +* [Normalized Endpoint Detection](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/rules/MATCH-S01158.md) - Passes through an alert from a host-based security agent and adjusts the severity accordingly based on the severity provided in the log. + +### runtime + +For messages from workload security agents that detect suspicious or malicious behavior in containers and other cloud-native runtimes. + +Log sources that issue runtime-related messages include: + +* Falco +* Sysdig Secure +* Twistlock (Prisma Cloud Compute) +* Aqua Security + +Cloud SIEM provides the following normalized runtime rule: + +* [Normalized Runtime Detection](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/rules/MATCH-S01159.md) - Passes through an alert from a workload security agent and adjusts the severity accordingly based on the severity provided in the log. + +### cloud + +For messages that indicate a cloud posture, cloud threat, or cloud infrastructure finding. + +Log sources that issue cloud-related messages include: + * AWS GuardDuty -* Varonis UBA -* G Suite Alert Center   +* AWS Security Hub +* Google Cloud SCC +* GCP IDS +* Orca Security +* Wiz +* Palo Alto Prisma Cloud +* Azure -Out-of-the-box log mappings for behavior-based detections are being migrated to six more granular classes. See [Behavioral detection classes](#behavioral-detection-classes). After migration, `direct` is retained for out-of-the-box mappings from generic sources that can't be assigned to a single class, such as the Microsoft Graph Security API catch-all mappings. +Cloud SIEM provides the following normalized cloud rule: -Cloud SIEM provides the following normalized direct rule: +* [Normalized Cloud Detection](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/rules/MATCH-S01160.md) - Passes through an alert from a cloud security product and adjusts the severity accordingly based on the severity provided in the log. -* [Normalized Security Signal](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/rules/MATCH-S00402.md) - Passes through an alert from a security product and adjusts the severity accordingly based on the severity provided in the log. +### identity + +For messages that indicate an identity or access anomaly, such as a risky sign-in, impossible travel, or compromised credentials. + +Log sources that issue identity-related messages include: + +* Azure AD Identity Protection +* Microsoft ATA +* Microsoft Graph Identity API +* MCAS/Defender for Cloud Apps +* Google Workspace Alert Center +* Okta +* Slack Enterprise +* DocuSign Monitor +* Exabeam +* Salesforce +* Box +* CrowdStrike Identity Protection + +Cloud SIEM provides the following normalized identity rule: + +* [Normalized Identity Detection](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/rules/MATCH-S01161.md) - Passes through an alert from an identity or access product and adjusts the severity accordingly based on the severity provided in the log. + +### network + +For messages that indicate a network-layer detection, such as an IDS/IPS alert, a command-and-control callback, or a lateral movement indicator. These include NDR and WAF detections. + +Log sources that issue network-related messages include: -### Behavioral detection classes +* Palo Alto Firewall +* FortiGate +* Kemp LoadMaster WAF +* FireEye NX/CMS +* Vectra AI +* Claroty xDome +* Darktrace +* AlphaSOC +* CrowdStrike FDR +* Bitdefender +* Trend Micro -Cloud SIEM divides behavior-based detections into six classes, each with its own normalized rule, class-specific entity selectors, and summary expression. These classes give you more granular categories for tuning and more context from the underlying alert than the single [Normalized Security Signal](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/rules/MATCH-S00402.md) passthrough rule provides. All six rules pass through the [normalizedSeverity](/docs/cse/schema/schema-attributes) value from the log. +Cloud SIEM provides the following normalized network rule: -| `threat_ruleType` | Rule | Primary asset field | Out-of-the-box mapping migration | -|---|---|---|---| -| `runtime` | [Normalized Runtime Detection](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/rules/MATCH-S01159.md) | `device_hostname` | Completed August 4, 2026 | -| `identity` | [Normalized Identity Detection](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/rules/MATCH-S01161.md) | `user_username` | Completed August 4, 2026 | -| `network` | [Normalized Network Detection](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/rules/MATCH-S01162.md) | `srcDevice_hostname` | Target: August 13, 2026 | -| `data_protection` | [Normalized Data Protection Detection](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/rules/MATCH-S01163.md) | `resource` | Target: August 13, 2026 | -| `cloud` | [Normalized Cloud Detection](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/rules/MATCH-S01160.md) | `resource` | Target: August 27, 2026 | -| `endpoint` | [Normalized Endpoint Detection](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/rules/MATCH-S01158.md) | `device_hostname` | Target: August 27, 2026 | +* [Normalized Network Detection](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/rules/MATCH-S01162.md) - Passes through an alert from a network security product and adjusts the severity accordingly based on the severity provided in the log. + +### data_protection + +For messages that indicate a data protection detection, such as a DLP violation, an email security detection, a deception alert, or an application security finding. + +Log sources that issue data protection-related messages include: + +* Netskope +* Varonis +* Egnyte DLP +* Office 365 DLP +* Proofpoint TRAP +* Mimecast +* Check Point Avanan +* Akamai CPC +* Noname API Security +* Thinkst Canary +* Contrast ADR +* Qualys +* IBM Guardium +* CrowdStrike DataProtection +* Fortinet +* Google Workspace + +Cloud SIEM provides the following normalized data protection rule: + +* [Normalized Data Protection Detection](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/rules/MATCH-S01163.md) - Passes through an alert from a data protection product and adjusts the severity accordingly based on the severity provided in the log. + +## Behavior-based log mapping migration + +The `endpoint`, `runtime`, `cloud`, `identity`, `network`, and `data_protection` types are new. Out-of-the-box log mappings that previously set `threat_ruleType` to `direct` are being reassigned to these types in phases, so that behavior-based detections are easier to tune and carry more context than the single [Normalized Security Signal](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/rules/MATCH-S00402.md) passthrough rule provides. + +| `threat_ruleType` | Out-of-the-box mapping migration | +|---|---| +| `runtime` | Completed August 4, 2026 | +| `identity` | Completed August 4, 2026 | +| `network` | Completed August 17, 2026 | +| `data_protection` | Completed August 17, 2026 | +| `cloud` | Target: August 27, 2026 | +| `endpoint` | Target: August 27, 2026 | :::note -All six rules are available now, but out-of-the-box log mappings are migrating in phases. The `runtime` and `identity` mappings have migrated. The remaining dates in the table are targets and may shift. For the actual dates that out-of-the-box mappings migrate, monitor the [Cloud SIEM content release notes](/release-notes-cse/). Until a source's out-of-the-box mappings are migrated, its records keep a `threat_ruleType` of `direct` and continue to fire [Normalized Security Signal](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/rules/MATCH-S00402.md). +All six rules are available now, but out-of-the-box log mappings are migrating in phases. The remaining dates in the table are targets and may shift. For the actual dates that out-of-the-box mappings migrate, monitor the [Cloud SIEM content release notes](/release-notes-cse/). Until a source's out-of-the-box mappings are migrated, its records keep a `threat_ruleType` of `direct` and continue to fire [Normalized Security Signal](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/rules/MATCH-S00402.md). -This migration changes only out-of-the-box log mappings. Your own log mappings aren't affected, and they keep whatever `threat_ruleType` value you set. To send records from your own mappings to one of the new rules, set `threat_ruleType` to that class. +This migration changes only out-of-the-box log mappings. Your own log mappings aren't affected, and they keep whatever `threat_ruleType` value you set. To send records from your own mappings to one of the new rules, set `threat_ruleType` to that type. ::: -Classes are assigned per log mapping, not per vendor, so a single security product can contribute to several classes. For example, out-of-the-box CrowdStrike log mappings are assigned to `endpoint`, `identity`, `network`, and `data_protection`. - -* **runtime**. Container and cloud-native runtime detections from workload security agents: Falco, Sysdig Secure, Twistlock (Prisma Cloud Compute), and Aqua Security. -* **identity**. Identity and access anomaly detections, such as risky sign-ins, impossible travel, and compromised credentials: Azure AD Identity Protection, Microsoft ATA, Microsoft Graph Identity API, MCAS/Defender for Cloud Apps, Google Workspace Alert Center, Slack Enterprise, Okta, DocuSign Monitor, Exabeam, Salesforce, Box, and CrowdStrike Identity Protection. -* **network**. Network-layer, NDR, and WAF detections, such as IDS/IPS alerts, command-and-control callbacks, and lateral movement indicators: Kemp LoadMaster WAF, Palo Alto Firewall, FortiGate, FireEye NX/CMS, Vectra AI, Claroty xDome, Darktrace, AlphaSOC, CrowdStrike FDR, Bitdefender, and Trend Micro. -* **data_protection**. DLP, email security, deception, and application security detections: Egnyte DLP, Varonis, Netskope, Akamai CPC, Noname API Security, Check Point Avanan, Proofpoint TRAP, Mimecast, Thinkst Canary, Contrast ADR, Qualys, IBM Guardium, Office 365 DLP, CrowdStrike DataProtection, Fortinet, and Google Workspace. -* **cloud**. Cloud posture, cloud threat, and cloud infrastructure detections: AWS GuardDuty, AWS Security Hub, Google Cloud SCC, GCP IDS, Orca Security, Wiz, Palo Alto Prisma Cloud, and Azure. -* **endpoint**. EDR and EPP behavioral detections from host-based security agents: CrowdStrike Falcon, SentinelOne, Carbon Black, Cylance, Cisco AMP, Cybereason, Endgame, Jamf Protect, Malwarebytes, McAfee, Palo Alto Cortex XDR, Sophos, Tanium, Trend Micro, Windows Defender, FireEye HX, Azure Defender for Endpoint, Google Workspace, and Bitdefender. +Types are assigned per log mapping, not per vendor, so a single security product can contribute to several types. For example, out-of-the-box CrowdStrike log mappings are assigned to `endpoint`, `identity`, `network`, and `data_protection`. -#### Migrate custom content +### Migrate custom content Custom content that depends on [Normalized Security Signal](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/rules/MATCH-S00402.md) won't apply to records once their out-of-the-box mappings are migrated. For sources that haven't migrated yet, make these updates before their target date: From 80abb856f1e8c250dbb083a86547a7b82a253b61 Mon Sep 17 00:00:00 2001 From: Julian Crowley Date: Fri, 21 Aug 2026 16:37:07 -0600 Subject: [PATCH 3/3] Update normalized-threat-rules.md --- docs/cse/rules/normalized-threat-rules.md | 59 ++++++++++++----------- 1 file changed, 31 insertions(+), 28 deletions(-) diff --git a/docs/cse/rules/normalized-threat-rules.md b/docs/cse/rules/normalized-threat-rules.md index d1ee23d3683..a2e967b789a 100644 --- a/docs/cse/rules/normalized-threat-rules.md +++ b/docs/cse/rules/normalized-threat-rules.md @@ -94,8 +94,11 @@ Behavior-based detections are divided among the six more specific types describe Log sources that remain mapped to `direct` include: -* Symantec Endpoint Protection EDR -* Microsoft Graph Security API +* Microsoft Graph Security API catch-all mappings +* Microsoft 365 Defender +* Microsoft Azure Advanced Threat Protection (standalone mapping) +* Exabeam +* Qualys Cloud SIEM provides the following normalized direct rule: @@ -103,7 +106,7 @@ Cloud SIEM provides the following normalized direct rule: ### endpoint -For messages from host-based security agents that detect suspicious or malicious behavior on an endpoint, such as EDR and EPP detections. +For messages from host-based security agents that detect suspicious or malicious behavior on an endpoint, such as EDR and EPP detections. Out-of-the-box mappings for these sources haven't migrated yet. Until they do, these sources set `threat_ruleType` to `direct`. See [Behavior-based log mapping migration](#behavior-based-log-mapping-migration). Log sources that issue endpoint-related messages include: @@ -140,6 +143,7 @@ Log sources that issue runtime-related messages include: * Sysdig Secure * Twistlock (Prisma Cloud Compute) * Aqua Security +* Contrast ADR Cloud SIEM provides the following normalized runtime rule: @@ -147,7 +151,7 @@ Cloud SIEM provides the following normalized runtime rule: ### cloud -For messages that indicate a cloud posture, cloud threat, or cloud infrastructure finding. +For messages that indicate a cloud posture, cloud threat, or cloud infrastructure finding. Out-of-the-box mappings for these sources haven't migrated yet. Until they do, these sources set `threat_ruleType` to `direct`. See [Behavior-based log mapping migration](#behavior-based-log-mapping-migration). Log sources that issue cloud-related messages include: @@ -170,18 +174,17 @@ For messages that indicate an identity or access anomaly, such as a risky sign-i Log sources that issue identity-related messages include: -* Azure AD Identity Protection -* Microsoft ATA -* Microsoft Graph Identity API -* MCAS/Defender for Cloud Apps +* Microsoft Azure AD Identity Protection +* Microsoft Azure Advanced Threat Protection +* Microsoft Defender for Cloud Apps (MCAS) +* Microsoft Graph Identity Protection API * Google Workspace Alert Center * Okta -* Slack Enterprise +* Slack +* Box * DocuSign Monitor -* Exabeam * Salesforce -* Box -* CrowdStrike Identity Protection +* CrowdStrike Falcon Identity Protection Cloud SIEM provides the following normalized identity rule: @@ -194,16 +197,16 @@ For messages that indicate a network-layer detection, such as an IDS/IPS alert, Log sources that issue network-related messages include: * Palo Alto Firewall -* FortiGate -* Kemp LoadMaster WAF -* FireEye NX/CMS -* Vectra AI +* Fortinet +* Kemp LoadMaster +* FireEye CMS +* Vectra AI and Vectra Cognito * Claroty xDome * Darktrace * AlphaSOC * CrowdStrike FDR -* Bitdefender -* Trend Micro +* Bitdefender GravityZone +* Trend Micro Control Manager Cloud SIEM provides the following normalized network rule: @@ -216,21 +219,20 @@ For messages that indicate a data protection detection, such as a DLP violation, Log sources that issue data protection-related messages include: * Netskope -* Varonis +* Varonis (DatAlert and DatAdvantage) * Egnyte DLP -* Office 365 DLP +* Microsoft Office 365 (DLP and compliance) +* Microsoft Graph Security API (Microsoft IPC and Office 365 Security and Compliance) * Proofpoint TRAP * Mimecast * Check Point Avanan * Akamai CPC -* Noname API Security +* Akamai Noname API Security * Thinkst Canary -* Contrast ADR -* Qualys * IBM Guardium -* CrowdStrike DataProtection -* Fortinet -* Google Workspace +* CrowdStrike Falcon data protection detections +* Fortinet DLP +* Google Workspace Alert Center (DLP) Cloud SIEM provides the following normalized data protection rule: @@ -246,8 +248,8 @@ The `endpoint`, `runtime`, `cloud`, `identity`, `network`, and `data_protection` | `identity` | Completed August 4, 2026 | | `network` | Completed August 17, 2026 | | `data_protection` | Completed August 17, 2026 | -| `cloud` | Target: August 27, 2026 | -| `endpoint` | Target: August 27, 2026 | +| `cloud` | Target: On Hold | +| `endpoint` | Target: On Hold | :::note All six rules are available now, but out-of-the-box log mappings are migrating in phases. The remaining dates in the table are targets and may shift. For the actual dates that out-of-the-box mappings migrate, monitor the [Cloud SIEM content release notes](/release-notes-cse/). Until a source's out-of-the-box mappings are migrated, its records keep a `threat_ruleType` of `direct` and continue to fire [Normalized Security Signal](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/rules/MATCH-S00402.md). @@ -262,5 +264,6 @@ Types are assigned per log mapping, not per vendor, so a single security product Custom content that depends on [Normalized Security Signal](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/rules/MATCH-S00402.md) won't apply to records once their out-of-the-box mappings are migrated. For sources that haven't migrated yet, make these updates before their target date: * Re-scope any [rule tuning expressions](/docs/cse/rules/rule-tuning-expressions) on `MATCH-S00402` to the new rule IDs for those sources. +* If there are custom rules based on `MATCH-S00402` or utilizing `threat_ruleType = 'direct'`, migrate expression logic to the new detection category rules as tuning expressions or modify those rules to use the new `threat_ruleType` values. For example, if you have a custom rule that looks for `threat_ruleType = 'direct'` and a specific signature, you can change it to look for `threat_ruleType = 'endpoint'` and the same signature once the source's out-of-the-box mappings are migrated. * Update any [custom insights](/docs/cse/records-signals-entities-insights/configure-custom-insight) that reference `MATCH-S00402`. * Update saved searches, dashboards, or automations that filter on `threat_ruleType = 'direct'`.