<?xml version="1.0" encoding="UTF-8"?>
<!-- AUTOGENERATED FILE. DO NOT EDIT. -->
<feed xmlns="http://www.w3.org/2005/Atom">
  <id>tag:google.com,2016:chronicle-soar-marketplace-release-notes</id>
  <title>Google SecOps Marketplace - Release notes</title>
  <link rel="self" href="https://docs.cloud.google.com/feeds/chronicle-soar-marketplace-release-notes.xml"/>
  <author>
    <name>Google Cloud Platform</name>
  </author>
  <updated>2026-07-22T00:00:00-07:00</updated>

  <entry>
    <title>July 22, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-marketplace-release-notes#July_22_2026</id>
    <updated>2026-07-22T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/marketplace-integrations/release-notes#July_22_2026"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p><strong>Wiz</strong>: Version 14.0</p>
<ul>
<li><p>Added the following action:</p>
<ul>
<li><strong>Get Blue Agent Analysis</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Azure Monitor</strong>: Version 5.0</p>
<ul>
<li>Updated integration documentation links in the integration configuration.</li>
</ul>
<h3>Change</h3>
<p><strong>QRadar</strong>: Version 69.0</p>
<ul>
<li><p>Updated timestamp filtering to use <code>last_persisted_time</code> for tracking
modifications in the following connector:</p>
<ul>
<li><strong>Qradar Offenses Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Jira</strong>: Version 60.0</p>
<ul>
<li><p>Added support for the <code>Created Before</code> date filter and <code>Custom JQL</code> query
parameter in the following action:</p>
<ul>
<li><strong>List Issues</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Chronicle</strong>: Version 90.0</p>
<ul>
<li><p>Updated handling of Wiz Defend detections and ontology mapping in the
following connector:</p>
<ul>
<li><strong>Chronicle Alerts Connector</strong></li>
</ul></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>July 15, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-marketplace-release-notes#July_15_2026</id>
    <updated>2026-07-15T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/marketplace-integrations/release-notes#July_15_2026"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<p><strong>AWS GuardDuty</strong>: Version 14.0</p>
<ul>
<li>Added support for Google Cloud Web Identity (OIDC) Federation authentication.</li>
</ul>
<h3>Change</h3>
<p><strong>SCC Enterprise</strong>: Version 22.0</p>
<ul>
<li>Refactored integration code to optimize underlying execution performance.</li>
</ul>
<h3>Change</h3>
<p><strong>Google Threat Intelligence</strong>: Version 18.0</p>
<ul>
<li><p>Added an optional <code>Active Group</code> parameter to support multi-tenant 
organization context routing in the integration configuration and the following 
connector:</p>
<ul>
<li><strong>ASM Issues Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Chronicle</strong>: Version 88.0</p>
<ul>
<li><p>Added <code>api_root</code> parameter to alert extensions to expand normalization 
metadata options in the following connector:</p>
<ul>
<li><strong>Chronicle Alerts Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Defender ATP</strong>: Version 33.0</p>
<ul>
<li><p>Updated execution processing logic to improve backend tracking stability in
the following action:</p>
<ul>
<li><strong>Execute Live Response Command</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>ServiceNow</strong>: Version 68.0</p>
<ul>
<li><p>Updated affected CIs processing logic to handle missing reference keys
smoothly in the following job:</p>
<ul>
<li><strong>Sync Incidents Job</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>CrowdStrike Falcon</strong>: Version 78.0</p>
<ul>
<li><p>Fixed pagination loop logic to prevent infinite timeouts during high-volume
sweeps in the following action:</p>
<ul>
<li><strong>Get Host Information</strong></li>
</ul></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>July 08, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-marketplace-release-notes#July_08_2026</id>
    <updated>2026-07-08T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/marketplace-integrations/release-notes#July_08_2026"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<p><strong>FileUtilities</strong>: Version 27.0</p>
<ul>
<li><p>Added support for extracting files from .7z archives in the following action:</p>
<ul>
<li><strong>Extract Zip Files</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Threat Intelligence</strong>: Version 17.0</p>
<ul>
<li><p>Fixed widget rendering failures by escaping raw HTML script tags within
<code>extended_response_body</code> in the following action:</p>
<ul>
<li><strong>Get ASM Entity Details</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Chronicle</strong>: Version 87.0</p>
<ul>
<li><p>Improved case and alert synchronization logic by fixing the verification
handling of valid external ID values in the following job:</p>
<ul>
<li><strong>Google Chronicle Sync Job</strong></li>
</ul></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>July 01, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-marketplace-release-notes#July_01_2026</id>
    <updated>2026-07-01T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/marketplace-integrations/release-notes#July_01_2026"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p><strong>Proofpoint Email Protection</strong>: Version 8.0</p>
<ul>
<li><p>The following new actions have been added to support searching and 
programmatically managing quarantined emails:</p>
<ul>
<li><p><strong>Search Quarantined Emails</strong></p></li>
<li><p><strong>Delete Quarantined Email</strong></p></li>
<li><p><strong>Resubmit Quarantined Email</strong></p></li>
<li><p><strong>Move Quarantined Email</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Proofpoint Email Protection</strong>: Version 8.0</p>
<ul>
<li><p>Updated backend script implementation to support the new framework for the 
following actions:</p>
<ul>
<li><p><strong>Enrich Entities</strong></p></li>
<li><p><strong>Ping</strong></p></li>
</ul></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>June 25, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-marketplace-release-notes#June_25_2026</id>
    <updated>2026-06-25T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/marketplace-integrations/release-notes#June_25_2026"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p><strong>Palo Alto Cortex XDR</strong>: Version 30.0</p>
<ul>
<li><p>The following new action has been added:</p>
<ul>
<li><strong>Download File</strong></li>
</ul></li>
</ul>
<h3>Feature</h3>
<p><strong>CyberArk PAM</strong>: Version 11.0</p>
<ul>
<li><p>The following new action has been added:</p>
<ul>
<li><strong>Change Account Password</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Siemplify</strong>: Version 110.0</p>
<ul>
<li><p>Updated results processing logic to cleanly escape backslashes in the 
following action:</p>
<ul>
<li><strong>Create Gemini Case Summary</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Secret Manager</strong>: Version 2.0</p>
<ul>
<li><p>Updated action description in the following action:</p>
<ul>
<li><strong>Ping</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>CrowdStrike Falcon</strong>: Version 77.0</p>
<ul>
<li><p>Updated syncing logic to support multiple CrowdStrike alert IDs mapped to a 
single SecOps alert and improved error handling for alert ID context values in 
the following connector:</p>
<ul>
<li><strong>Sync Alerts</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Azure Active Directory</strong>: Version 29.0</p>
<ul>
<li><p>Updated error handling for sign-in activity retrieval in the following action:</p>
<ul>
<li><strong>Enrich User</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Cloud Compute</strong>: Version 19.0</p>
<ul>
<li><p>Refactored action code in the following actions:</p>
<ul>
<li><p><strong>Add IP To Firewall Rule</strong></p></li>
<li><p><strong>Remove external IP addresses</strong></p></li>
<li><p><strong>Execute VM Patch Job</strong></p></li>
<li><p><strong>Update Firewall Rule</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>VirusTotalV3</strong>: Version 41.0</p>
<ul>
<li><p>Updated Predefined Widgets to fix cached fallback rendering in the following 
actions:</p>
<ul>
<li><p><strong>Enrich Hash</strong></p></li>
<li><p><strong>Enrich IOC</strong></p></li>
<li><p><strong>Enrich IP</strong></p></li>
<li><p><strong>Enrich URL</strong></p></li>
<li><p><strong>Get Domain Details</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Threat Intelligence</strong>: Version 16.0</p>
<ul>
<li><p>Updated Predefined Widgets to optimize loading performance and aligned layouts 
to prevent visual shifts in the following actions:</p>
<ul>
<li><p><strong>Enrich Entities</strong></p></li>
<li><p><strong>Enrich IOCs</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>EmailV2</strong>: Version 42.0</p>
<ul>
<li><p>Updated default values for IMAP server address, port, username, and password 
for the following connector:</p>
<ul>
<li><strong>Generic IMAP Email Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>FireEye Helix</strong>: Version 20.0</p>
<ul>
<li>Added Trellix IAM OAuth authentication support.</li>
</ul>
<h3>Change</h3>
<p><strong>FireEye ETP</strong>: Version 9.0</p>
<ul>
<li>Added Trellix OAuth support, updated public API endpoints to v2, and removed 
legacy V1 API support.</li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>June 17, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-marketplace-release-notes#June_17_2026</id>
    <updated>2026-06-17T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/marketplace-integrations/release-notes#June_17_2026"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p><strong>Secret Manager</strong>: Version 1.0</p>
<ul>
<li>New <strong>Secret Manager</strong> integration.</li>
</ul>
<h3>Change</h3>
<p>Source code is now publicly available on <a href="https://github.com/chronicle/content-hub">GitHub</a>
for the following integrations:</p>
<ul>
<li><p><strong>AlienVault USM Appliance</strong>: Version 29.0</p></li>
<li><p><strong>AlienVaultTI</strong>: Version 15.0</p></li>
<li><p><strong>Arcsight</strong>: Version 46.0</p></li>
<li><p><strong>Axonius</strong>: Version 8.0</p></li>
<li><p><strong>BMC Helix Remedyforce</strong>: Version 18.0</p></li>
<li><p><strong>Cisco AMP</strong>: Version 24.0</p></li>
<li><p><strong>EasyVista</strong>: Version 8.0</p></li>
<li><p><strong>Mandiant</strong>: Version 10.0</p></li>
<li><p><strong>Office 365 Management API</strong>: Version 11.0</p></li>
<li><p><strong>SCCM</strong>: Version 22.0</p></li>
<li><p><strong>SonicWall-Beta</strong>: Version 9.0</p></li>
<li><p><strong>Stellar Cyber Starlight</strong>: Version 19.0</p></li>
<li><p><strong>Symantec Email Security.Cloud</strong>: Version 6.0</p></li>
<li><p><strong>Twilio</strong>: Version 16.0</p></li>
<li><p><strong>XForce</strong>: Version 20.0</p></li>
<li><p><strong>Zabbix</strong>: Version 17.0</p></li>
</ul>
<h3>Change</h3>
<p><strong>Google Chronicle</strong>: Version 86.0</p>
<ul>
<li><p>Fixed an issue where the connector would idle or hang on heartbeats instead of 
breaking early when <code>nextPageToken</code> or <code>nextPageStartTime</code> is received, and 
updated ontology mapping in the following connector:</p>
<ul>
<li><strong>Chronicle Alerts Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Palo Alto Cortex XDR</strong>: Version 29.0</p>
<ul>
<li><p>Updated host name extraction logic in the raw payload in the following 
connector:</p>
<ul>
<li><strong>Palo Alto Cortex XDR Connector</strong></li>
</ul></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>June 11, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-marketplace-release-notes#June_11_2026</id>
    <updated>2026-06-11T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/marketplace-integrations/release-notes#June_11_2026"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<p><strong>Siemplify</strong>: Version 109.0</p>
<ul>
<li><p>Refactored the code in the following action:</p>
<ul>
<li><strong>Attach Playbook to Alert</strong></li>
</ul></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>June 10, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-marketplace-release-notes#June_10_2026</id>
    <updated>2026-06-10T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/marketplace-integrations/release-notes#June_10_2026"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<p><strong>Azure Security Center</strong>: Version 17.0</p>
<ul>
<li><p>Announced deprecation notice. Connector will be deprecated on 30th March 2027. 
Only critical bug fixes will be considered. For more information refer to the 
documentation of individual connectors in the following connector:</p>
<ul>
<li><strong>Azure Security Center - Security Alerts Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Chronicle</strong>: Version 85.0</p>
<ul>
<li><p>Updated partial batch handling and added dynamic batch sizing to prevent 
timeout loops, refactored logging and added monitoring signals for process 
health, and pipeline states, and improved detections batch parsing and 
processing efficiency in the following connector:</p>
<ul>
<li><strong>Chronicle Alerts Connector</strong></li>
</ul></li>
<li><p><strong>Integration</strong>: Updated authentication flow mechanism.</p></li>
</ul>
<h3>Change</h3>
<p><strong>Google Cloud IAM</strong>: Version 20.0</p>
<ul>
<li><p>Updated Predefined Widgets in the following widgets:</p>
<ul>
<li><p><strong>List Roles</strong></p></li>
<li><p><strong>List Service Accounts</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Azure Sentinel</strong>: Version 64.0</p>
<ul>
<li><p>Announced deprecation notice. Connector will be deprecated on 30th March 2027. 
Only critical bug fixes will be considered. For more information refer to the 
documentation of individual connectors in the following connectors:</p>
<ul>
<li><p><strong>Microsoft Azure Sentinel Incident Connector v2</strong></p></li>
<li><p><strong>Microsoft Sentinel Incident Tracking Connector</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Defender ATP</strong>: Version 32.0</p>
<ul>
<li><p>Announced deprecation notice. Connector will be deprecated on 30th March 2027. 
Only critical bug fixes will be considered. For more information refer to the 
documentation of individual connectors in the following connectors:</p>
<ul>
<li><p><strong>Microsoft Defender ATP Connector</strong></p></li>
<li><p><strong>Microsoft Defender ATP Connector V2</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Graph Mail</strong>: Version 42.0</p>
<ul>
<li><p>Updated the logic for robust handling of transient upstream API errors and 
connection issues in the following connector:</p>
<ul>
<li><strong>Microsoft Graph Mail Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Graph Mail Delegated</strong>: Version 19.0</p>
<ul>
<li><p>Updated the logic for robust handling of transient upstream API errors and 
connection issues in the following connector:</p>
<ul>
<li><strong>Microsoft Graph Mail Delegated Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Graph Security</strong>: Version 27.0</p>
<ul>
<li><p>Announced deprecation notice. Connector will be deprecated on 30th March 2027. 
Only critical bug fixes will be considered. For more information refer to the 
documentation of individual connectors in the following connectors:</p>
<ul>
<li><p><strong>Microsoft Graph Office 365 Security and Compliance Connector</strong></p></li>
<li><p><strong>Microsoft Graph Security Connector</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Protectwise</strong>: Version 7.0</p>
<ul>
<li><p>Refactored the code in the following action:</p>
<ul>
<li><strong>Get Pcap</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Qualys VM</strong>: Version 28.0</p>
<ul>
<li><p>Fixed AttributeError during parsing of multiple host lists and added fallback 
hostname matching in the following actions:</p>
<ul>
<li><p><strong>List Endpoint Detections</strong></p></li>
<li><p><strong>Enrich Host</strong></p></li>
</ul></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>June 03, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-marketplace-release-notes#June_03_2026</id>
    <updated>2026-06-03T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/marketplace-integrations/release-notes#June_03_2026"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<p><strong>AlienVault USM Appliance</strong>: Version 28.0</p>
<ul>
<li>Refactored the code for the following action:
<ul>
<li><strong>Get PCAP Files For Events</strong></li></ul></li></ul>
<h3>Change</h3>
<p><strong>ConnectWise</strong>: Version 23.0</p>
<ul>
<li>Refactored the code for the following action:
<ul>
<li><strong>Create Alerts Ticket</strong></li></ul></li></ul>
<h3>Change</h3>
<p><strong>Google Chronicle</strong>: Version 84.0</p>
<ul>
<li>Refactored the code for the following action:
<ul>
<li><strong>Get Detection Details</strong></li></ul></li></ul>
<h3>Change</h3>
<p><strong>Jira</strong>: Version 58.0</p>
<ul>
<li>Refactored the code for the following action:
<ul>
<li><strong>Create Alert Issue</strong></li></ul></li></ul>
<h3>Change</h3>
<p><strong>ServiceDesk Plus</strong>: Version 10.0</p>
<ul>
<li>Refactored the code for the following action:
<ul>
<li><strong>Create Alert Request</strong></li></ul></li></ul>
<h3>Change</h3>
<p><strong>ServiceDesk PlusV3</strong>: Version 10.0</p>
<ul>
<li>Refactored the code for the following action:
<ul>
<li><strong>Create Alert Request</strong></li></ul></li></ul>
<h3>Change</h3>
<p><strong>ServiceNow</strong>: Version 67.0</p>
<ul>
<li>Refactored the code for the following action:
<ul>
<li><strong>Create Alert Incident</strong></li></ul></li></ul>
<h3>Change</h3>
<p><strong>Siemplify</strong>: Version 245.0</p>
<ul>
<li>Refactored internal code execution logic for the platform integration.</li></ul>
<h3>Change</h3>
<p><strong>MISP</strong>: Version 275.6</p>
<ul>
<li>Refactored internal code execution logic and optimized core integration components.</li></ul>
<h3>Change</h3>
<p><strong>Microsoft Sentinel Incident Tracking Connector</strong>: Version 29.0</p>
<ul>
<li>Added the <code>Incident Creation Time Filter (days)</code> advanced parameter and optimized error handling logic.</li></ul>
]]>
    </content>
  </entry>

  <entry>
    <title>May 27, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-marketplace-release-notes#May_27_2026</id>
    <updated>2026-05-27T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/marketplace-integrations/release-notes#May_27_2026"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p>New <strong>Cloud Identity</strong> integration</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 20, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-marketplace-release-notes#May_20_2026</id>
    <updated>2026-05-20T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/marketplace-integrations/release-notes#May_20_2026"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<p><strong>AlienVault USM Appliance</strong>: Version 27.0</p>
<ul>
<li>Refactored the code for the following action:
<ul>
<li><strong>Get PCAP Files For Events</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Protectwise</strong>: Version 6.0</p>
<ul>
<li>Refactored the code for the following action:
<ul>
<li><strong>Get Pcap</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Service Desk Plus</strong>: Version 9.0</p>
<ul>
<li>Refactored the code for the following action:
<ul>
<li><strong>Create Alert Request</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Service Desk Plus V3</strong>: Version 9.0</p>
<ul>
<li>Refactored the code for the following action:
<ul>
<li><strong>Create Alert Request</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>ServiceNow</strong>: Version 66.0</p>
<ul>
<li>Updated the code for the following action:
<ul>
<li><strong>Update Incident</strong>: Added support for updating reference fields.</li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Chronicle</strong>: Version 83.0</p>
<ul>
<li>Added support for filtering alerts by rule type to the following connector:
<ul>
<li><strong>Google Chronicle - Chronicle Alerts Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Tanium</strong>: Version 20.0</p>
<ul>
<li><strong>Integration</strong>: Added a partner header to all API requests.</li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>May 13, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-marketplace-release-notes#May_13_2026</id>
    <updated>2026-05-13T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/marketplace-integrations/release-notes#May_13_2026"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<p><strong>Azure Active Directory</strong>: Version 28.0</p>
<ul>
<li><strong>Integration</strong>: Updated TIPCommon to 2.3.8.</li>
</ul>
<h3>Change</h3>
<p><strong>ConnectWise</strong>: Version 22.0</p>
<ul>
<li>Refactored the code for the following action:
<ul>
<li><strong>Create Alerts Ticket</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>EmailV2</strong>: Version 41.0</p>
<ul>
<li><strong>Integration</strong>: Updated TIPCommon to 2.3.8 and migrated <code>EnvironmentCommon</code> imports to <code>TIPCommon.envcommon</code>.</li>
</ul>
<h3>Change</h3>
<p><strong>Google Chronicle</strong>: Version 82.0</p>
<ul>
<li><strong>Integration</strong>: Improved memory efficiency to prevent OOM crashes when querying large timeframes for <strong>Lookup Similar Alerts</strong>.</li>
<li>Updated the code for the following action:
<ul>
<li><strong>Get Detection Details</strong></li>
</ul></li>
<li>Improved Dynamic List filter validation, logging, and added the <code>Validate Dynamic List Entries</code> parameter for the following connector:
<ul>
<li><strong>Google Chronicle - Chronicle Alerts Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Jira</strong>: Version 57.0</p>
<ul>
<li>Refactored the code for the following action:
<ul>
<li><strong>Create Alert Issue</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>MITRE ATT&amp;CK</strong>: Version 19.0</p>
<ul>
<li><strong>Integration</strong>: Updated TIPCommon to 2.3.8.</li>
</ul>
<h3>Change</h3>
<p><strong>ServiceNow</strong>: Version 65.0</p>
<ul>
<li>Refactored the code for the following action:
<ul>
<li><strong>Create Alert Incident</strong></li>
</ul></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>May 06, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-marketplace-release-notes#May_06_2026</id>
    <updated>2026-05-06T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/marketplace-integrations/release-notes#May_06_2026"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<p><strong>Tenable.io</strong>: Version 18.0</p>
<ul>
<li><p>Improved the handling of concurrent requests and API rate limits in the
following action:</p>
<ul>
<li><strong>Enrich Entities</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>SiemplifyUtilities</strong>: Version 30.0</p>
<ul>
<li><p>Added support for backticks to the following action:</p>
<ul>
<li><strong>Query Joiner</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Azure Active Directory</strong>: Version 27.0</p>
<ul>
<li><p>Updated enrichment logic to ensure <code>id</code> is fetched when
<code>Include Last Sign In Details</code> is enabled in the following action:</p>
<ul>
<li><strong>Enrich User</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Palo Alto Next Gen Firewall</strong>: Version 29.0</p>
<ul>
<li><strong>Integration</strong>: Updated Manager to reuse the API token instead of generating
a new one.</li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>April 29, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-marketplace-release-notes#April_29_2026</id>
    <updated>2026-04-29T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/marketplace-integrations/release-notes#April_29_2026"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<p><strong>UrlScan.io</strong>: Version 30.0</p>
<ul>
<li><p>Added <code>is_risky</code> handling to the following action:</p>
<ul>
<li><strong>Url Check</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Siemplify</strong>: Version 107.0</p>
<ul>
<li><strong>Integration</strong>: Updated TIPCommon dependency.</li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Graph Mail</strong>: Version 41.0</p>
<ul>
<li><p>Updated MSG attachments processing logic in the following connector:</p>
<ul>
<li><strong>Microsoft Graph Mail Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Zerofox</strong>: Version 4.0</p>
<ul>
<li><strong>Integration</strong>: Updated documentation link.</li>
</ul>
<h3>Change</h3>
<p><strong>MISP</strong>: Version 39.0</p>
<ul>
<li><p>Updated tag retrieval logic in the following actions:</p>
<ul>
<li><p><strong>Add Tag to an Attribute</strong></p></li>
<li><p><strong>Add Tag to an Event</strong></p></li>
<li><p><strong>Remove Tag from an Attribute</strong></p></li>
<li><p><strong>Remove Tag from an Event</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Anomali ThreatStream</strong>: Version 16.0</p>
<ul>
<li><p>Added <code>is_risky</code> handling to the following action:</p>
<ul>
<li><strong>Enrich Entities</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Graph Mail Delegated</strong>: Version 18.0</p>
<ul>
<li><p>Updated MSG attachments processing logic in the following connector:</p>
<ul>
<li><strong>Microsoft Graph Mail Delegated Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Palo Alto Cortex XDR</strong>: Version 28.0</p>
<ul>
<li><p>Added the ability to ignore specific artifact types to the following
connector:</p>
<ul>
<li><strong>Palo Alto Cortex XDR Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p>Source code is now publicly available on <a href="https://github.com/chronicle/content-hub">GitHub</a>
for the following integrations:</p>
<ul>
<li><p><strong>Cisco Orbital</strong>: Version 9.0</p></li>
<li><p><strong>F5 Big IQ</strong>: Version 8.0</p></li>
<li><p><strong>FireEye EX</strong>: Version 14.0</p></li>
<li><p><strong>HCL BigFix Inventory</strong>: Version 6.0</p></li>
<li><p><strong>Illusive Networks</strong>: Version 8.0</p></li>
<li><p><strong>Lastline</strong>: Version 10.0</p></li>
<li><p><strong>McAfee ATD</strong>: Version 18.0</p></li>
<li><p><strong>McAfee Active Response</strong>: Version 10.0</p></li>
<li><p><strong>ObserveIT</strong>: Version 6.0</p></li>
<li><p><strong>Outpost24</strong>: Version 9.0</p></li>
<li><p><strong>Site24x7</strong>: Version 7.0</p></li>
<li><p><strong>Splash</strong>: Version 8.0</p></li>
<li><p><strong>Websense</strong>: Version 15.0</p></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>April 22, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-marketplace-release-notes#April_22_2026</id>
    <updated>2026-04-22T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/marketplace-integrations/release-notes#April_22_2026"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p><strong>Netskope</strong>: Version 17.0</p>
<ul>
<li><p>The following new actions have been added:</p>
<ul>
<li><p><strong>Add Entities to URL List</strong></p></li>
<li><p><strong>Deploy URL List Changes</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Netskope</strong>: Version 17.0</p>
<ul>
<li><p>Added a new <code>Use V2 API</code> parameter to the following actions:</p>
<ul>
<li><p><strong>List Clients</strong></p></li>
<li><p><strong>List Quarantined Files</strong></p></li>
</ul></li>
<li><p><strong>Integration</strong>: Added support for V2 API endpoints and OAuth 2.0
authentication.</p></li>
</ul>
<h3>Change</h3>
<p><strong>Qualys VM</strong>: Version 26.0</p>
<ul>
<li><strong>Integration</strong>: Migrated to the latest Qualys API endpoints.</li>
</ul>
<h3>Change</h3>
<p><strong>SCC Enterprise</strong>: Version 21.0</p>
<ul>
<li><p>Updated ticket synchronization logic in the following job:</p>
<ul>
<li><strong>Sync SCC Jira Tickets</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>McAfee Mvision EDR</strong>: Version 12.0</p>
<ul>
<li><strong>Integration</strong>: Added support for configuring the <code>Login API Root</code> as a
customizable parameter.</li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>April 15, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-marketplace-release-notes#April_15_2026</id>
    <updated>2026-04-15T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/marketplace-integrations/release-notes#April_15_2026"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p><strong>SentinelOneV2</strong>: Version 50.0</p>
<ul>
<li><p>The following new job has been added:</p>
<ul>
<li><strong>Sync Threats</strong></li>
</ul></li>
</ul>
<h3>Feature</h3>
<p><strong>CrowdStrike Falcon</strong>: Version 76.0</p>
<ul>
<li><p>The following new job has been added:</p>
<ul>
<li><strong>Sync Alerts</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>ServiceNow</strong>: Version 64.0</p>
<ul>
<li><p>Added support for disabling overflow settings and updated ticket processing
and environment mapping logic in the following connector:</p>
<ul>
<li><strong>ServiceNow Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Zscaler</strong>: Version 14.0</p>
<ul>
<li><p>Added the ability to provide IOCs using input parameters to the following
actions:</p>
<ul>
<li><p><strong>Add To Blacklist</strong></p></li>
<li><p><strong>Add To Whitelist</strong></p></li>
<li><p><strong>Remove From Blacklist</strong></p></li>
<li><p><strong>Remove From Whitelist</strong></p></li>
</ul></li>
<li><p><strong>Integration</strong>: Added support for OAuth authentication.</p></li>
</ul>
<h3>Change</h3>
<p><strong>Mandiant Threat Intelligence</strong>: Version 17.0</p>
<ul>
<li><p>Optimized execution performance and entity processing logic in the following
action:</p>
<ul>
<li><strong>Enrich Entities</strong></li>
</ul></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>April 10, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-marketplace-release-notes#April_10_2026</id>
    <updated>2026-04-10T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/marketplace-integrations/release-notes#April_10_2026"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p><strong>Gmail</strong>: Version 9.0</p>
<ul>
<li><p>A new predefined widget has been added to the following action:</p>
<ul>
<li><strong>Delete Email</strong></li>
</ul></li>
</ul>
<h3>Feature</h3>
<p><strong>Tanium</strong>: Version 19.0</p>
<ul>
<li><p>A new predefined widget has been added to the following action:</p>
<ul>
<li><strong>Create Connection</strong></li>
</ul></li>
</ul>
<h3>Feature</h3>
<p><strong>Cynet</strong>: Version 13.0</p>
<ul>
<li><p>New predefined widgets have been added to the following actions:</p>
<ul>
<li><p><strong>Delete Hash In Hosts</strong></p></li>
<li><p><strong>Kill Hash In Hosts</strong></p></li>
<li><p><strong>Quarantine Hash In Hosts</strong></p></li>
</ul></li>
</ul>
<h3>Feature</h3>
<p><strong>Area1</strong>: Version 9.0</p>
<ul>
<li><p>A new predefined widget has been added to the following action:</p>
<ul>
<li><strong>Search Indicator</strong></li>
</ul></li>
</ul>
<h3>Feature</h3>
<p><strong>Azure Active Directory</strong>: Version 26.0</p>
<ul>
<li><p>A new predefined widget has been added to the following action:</p>
<ul>
<li><strong>Is User In a Group</strong></li>
</ul></li>
</ul>
<h3>Feature</h3>
<p><strong>MX ToolBox</strong>: Version 14.0</p>
<ul>
<li><p>A new predefined widget has been added to the following action:</p>
<ul>
<li><strong>SPF Lookup</strong></li>
</ul></li>
</ul>
<h3>Feature</h3>
<p><strong>Active Directory</strong>: Version 41.0</p>
<ul>
<li><p>New predefined widgets have been added to the following actions:</p>
<ul>
<li><p><strong>Is User In Group</strong></p></li>
<li><p><strong>List User Groups</strong></p></li>
</ul></li>
</ul>
<h3>Feature</h3>
<p><strong>Cisco Threat Grid</strong>: Version 18.0</p>
<ul>
<li><p>New predefined widgets have been added to the following actions:</p>
<ul>
<li><p><strong>Get Hash Associated Domains</strong></p></li>
<li><p><strong>Get Hash Associated IPs</strong></p></li>
</ul></li>
</ul>
<h3>Feature</h3>
<p><strong>Google Chronicle</strong>: Version 81.0</p>
<ul>
<li><p>The following new action has been added:</p>
<ul>
<li><strong>Is CIDR In Data Table</strong></li>
</ul></li>
</ul>
<h3>Feature</h3>
<p><strong>Endgame</strong>: Version 15.0</p>
<ul>
<li><p>New predefined widgets have been added to the following actions:</p>
<ul>
<li><p><strong>Collect Autoruns</strong></p></li>
<li><p><strong>Drivers Survey</strong> (Windows only)</p></li>
<li><p><strong>Firewall Survey</strong> (Windows only)</p></li>
<li><p><strong>Process Survey</strong></p></li>
<li><p><strong>Removable Media Survey</strong> (Windows only)</p></li>
<li><p><strong>Software Survey</strong> (Windows only)</p></li>
<li><p><strong>User Sessions Survey</strong></p></li>
</ul></li>
</ul>
<h3>Feature</h3>
<p><strong>AWS Identity and Access Management (IAM)</strong>: Version 10.0</p>
<ul>
<li><p>A new predefined widget has been added to the following action:</p>
<ul>
<li><strong>Disable User Access</strong></li>
</ul></li>
</ul>
<h3>Feature</h3>
<p><strong>Carbon Black Response</strong>: Version 39.0</p>
<ul>
<li><p>A new predefined widget has been added to the following action:</p>
<ul>
<li><strong>Download Binary</strong></li>
</ul></li>
</ul>
<h3>Feature</h3>
<p><strong>Carbon Black Protection</strong>: Version 13.0</p>
<ul>
<li><p>A new predefined widget has been added to the following action:</p>
<ul>
<li><strong>Get Computers By File</strong></li>
</ul></li>
</ul>
<h3>Feature</h3>
<p><strong>McAfee ATD</strong>: Version 17.0</p>
<ul>
<li><p>A new predefined widget has been added to the following action:</p>
<ul>
<li><strong>Check Hash</strong></li>
</ul></li>
</ul>
<h3>Feature</h3>
<p><strong>UnshortenMe</strong>: Version 9.0</p>
<ul>
<li><p>A new predefined widget has been added to the following action:</p>
<ul>
<li><strong>Unshorten URL</strong></li>
</ul></li>
</ul>
<h3>Feature</h3>
<p><strong>CiscoUmbrella</strong>: Version 19.0</p>
<ul>
<li><p>A new predefined widget has been added to the following action:</p>
<ul>
<li><strong>Get Associated Domains</strong></li>
</ul></li>
</ul>
<h3>Feature</h3>
<p><strong>Microsoft Graph Mail</strong>: Version 40.0</p>
<ul>
<li><p>A new predefined widget has been added to the following action:</p>
<ul>
<li><strong>Get Mailbox Account Out Of Facility Settings</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Exabeam Advanced Analytics</strong>: Version 10.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Enrich Entities</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Check Point SandBlast</strong>: Version 8.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Query</strong></p></li>
<li><p><strong>Upload File</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Palo Alto AutoFocus</strong>: Version 12.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Hunt Domain</strong></p></li>
<li><p><strong>Hunt File</strong></p></li>
<li><p><strong>Hunt Ip</strong></p></li>
<li><p><strong>Hunt Url</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>XForce</strong>: Version 19.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Hash Info</strong></p></li>
<li><p><strong>Get IP Info</strong></p></li>
<li><p><strong>Get IP malware</strong></p></li>
<li><p><strong>Get Url Info</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Trend Micro Apex Central</strong>: Version 7.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Create Entity UDSO</strong></p></li>
<li><p><strong>Create File UDSO</strong></p></li>
<li><p><strong>Enrich Entities</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>BulkWhoIs</strong>: Version 18.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>WhoIs Details</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Any.Run</strong>: Version 12.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get Report</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Siemplify ThreatFuse</strong>: Version 19.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Enrich Entities</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Cloud Policy Intelligence</strong>: Version 7.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Search Service Account Activity</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>MISP</strong>: Version 38.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Enrich Entities</strong></p></li>
<li><p><strong>Get Event Details</strong></p></li>
<li><p><strong>Get Related Events</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>ReversingLabs Titanium</strong>: Version 12.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get Malware Details</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>MX ToolBox</strong>: Version 14.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>A Record Lookup</strong></p></li>
<li><p><strong>Blacklist Check</strong></p></li>
<li><p><strong>MX Record Lookup</strong></p></li>
<li><p><strong>Reverse DNS Lookup</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Rapid Response (GRR)</strong>: Version 11.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Client Details</strong></p></li>
<li><p><strong>List Clients</strong></p></li>
<li><p><strong>List Launched Flows</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Armis</strong>: Version 15.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Enrich Entities</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Lastline</strong>: Version 9.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get Analysis Results</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>McAfee Mvision EPO</strong>: Version 11.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Enrich Endpoint</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Office 365 Cloud App Security</strong>: Version 26.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get IP related activities</strong></p></li>
<li><p><strong>Get User related activities</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>SSL Labs</strong>: Version 11.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Analyse Entity</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Qualys VM</strong>: Version 25.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Enrich Host</strong></p></li>
<li><p><strong>List Endpoint Detections</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Exchange</strong>: Version 123.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Account Out Of Facility Settings</strong></p></li>
<li><p><strong>Send Email And Wait</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Defender ATP</strong>: Version 31.0</p>
<ul>
<li><p>Added Graph API V2 version support to the following actions:</p>
<ul>
<li><p><strong>Get User Related Alerts</strong></p></li>
<li><p><strong>List Alerts</strong></p></li>
<li><p><strong>Ping</strong></p></li>
<li><p><strong>Update Alert</strong></p></li>
</ul></li>
<li><p>Deprecated the following actions:</p>
<ul>
<li><p><strong>Get File Related Alerts</strong></p></li>
<li><p><strong>Get Machine Related Alerts</strong></p></li>
</ul></li>
<li><p>Added Graph API V2 version support to the following connector:</p>
<p>(REGRESSIVE) The connector must be updated by April 10, 2026.</p>
<aside class="note"><strong>Note:</strong><span> You must update ontology mapping. Alerts created with the new API have a different
structure and require additional permissions. We recommend using
<strong>Microsoft 365 Defender - Incidents Connector</strong> as a replacement.</span></aside>
<ul>
<li><strong>Microsoft Defender ATP Connector V2</strong></li>
</ul></li>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Enrich Entities</strong></p></li>
<li><p><strong>Execute Live Response Command</strong></p></li>
<li><p><strong>Get File Related Alerts</strong></p></li>
<li><p><strong>Get File Related Machines</strong></p></li>
<li><p><strong>Get Machine Logon Users</strong></p></li>
<li><p><strong>Get Machine Recommendations</strong></p></li>
<li><p><strong>Get Machine Related Alerts</strong></p></li>
<li><p><strong>Get Machine Vulnerabilities</strong></p></li>
<li><p><strong>Get User Related Alerts</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Cisco AMP</strong>: Version 23.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Computer Info</strong></p></li>
<li><p><strong>Get Computers By File Hash</strong></p></li>
<li><p><strong>Get Computers By File Name</strong></p></li>
<li><p><strong>Get Computers By Network Activity (Ip)</strong></p></li>
<li><p><strong>Get Computers By Network Activity (URL)</strong></p></li>
<li><p><strong>Isolate Machine</strong></p></li>
<li><p><strong>Unisolate Machine</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>HaveIBeenPwned</strong>: Version 10.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Check Account</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Symantec Blue Coat ProxySG</strong>: Version 7.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Block Entities</strong></p></li>
<li><p><strong>Enrich Entities</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Cybereason</strong>: Version 25.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Enrich Entities</strong></p></li>
<li><p><strong>Get Sensor Details</strong></p></li>
<li><p><strong>Is Probe Connected</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Cofense Triage</strong>: Version 21.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>EnrichURL</strong></p></li>
<li><p><strong>Get Domain Details</strong></p></li>
<li><p><strong>Get Threat Indicator Details</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Slack</strong>: Version 30.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Send Advanced Message</strong></p></li>
<li><p><strong>Send Message</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>IPVoid</strong>: Version 12.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get Ip Reputation</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>RSA NetWitness EDR</strong>: Version 9.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Enrich Endpoint</strong></p></li>
<li><p><strong>Get IOC Details</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Intune</strong>: Version 8.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get Managed Device</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Trend Micro DDAN</strong>: Version 6.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Submit File</strong></p></li>
<li><p><strong>Submit File URL</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Tenable.io</strong>: Version 17.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Enrich Entities</strong></p></li>
<li><p><strong>List Endpoint Vulnerabilities</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>JoeSandbox</strong>: Version 11.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Search Hash</strong></p></li>
<li><p><strong>Search Url</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Endgame</strong>: Version 15.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Enrich Entities</strong></p></li>
<li><p><strong>Network Survey</strong></p></li>
<li><p><strong>System Survey</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>ThreatQ</strong>: Version 19.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Enrich CVE</strong></p></li>
<li><p><strong>Enrich Email</strong></p></li>
<li><p><strong>Enrich Hash</strong></p></li>
<li><p><strong>Enrich IP</strong></p></li>
<li><p><strong>Enrich URL</strong></p></li>
<li><p><strong>Get Indicator Details</strong></p></li>
<li><p><strong>Get Malware Details</strong></p></li>
<li><p><strong>Link Entities</strong></p></li>
<li><p><strong>Link Entities To Object</strong></p></li>
<li><p><strong>List Entity Related Objects</strong></p></li>
<li><p><strong>Update Indicator Score</strong></p></li>
<li><p><strong>Update Indicator Status</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>RSA NetWitness Platform</strong>: Version 17.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Enrich Endpoint</strong></p></li>
<li><p><strong>Enrich File</strong></p></li>
<li><p><strong>Query NetWitness For Events Around Host</strong></p></li>
<li><p><strong>Query NetWitness For Events Around IP</strong></p></li>
<li><p><strong>Query NetWitness For Events Around User</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>McAfee TIEDXL</strong>: Version 9.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get File Reputation</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Symantec Endpoint Protection 14</strong>: Version 21.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>GetSystemInfo</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>FireEye AX</strong>: Version 9.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Submit URL</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Splash</strong>: Version 7.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Enrich Entities</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>MalShare</strong>: Version 11.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Enrich Hash</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Elastica CloudSOC</strong>: Version 8.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get User Activities</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Amazon Macie</strong>: Version 10.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get Findings</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>CiscoUmbrella</strong>: Version 19.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Domain Security Info</strong></p></li>
<li><p><strong>Get Domain Status</strong></p></li>
<li><p><strong>Get Whois</strong></p></li>
<li><p><strong>Is Domain In Cisco Popularity List</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>SCCM</strong>: Version 21.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Enrich Entities</strong></p></li>
<li><p><strong>Get Computer Properties</strong></p></li>
<li><p><strong>Get Login History</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Web Risk</strong>: Version 4.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Enrich Entities</strong></p></li>
<li><p><strong>Submit Entities</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>DShield</strong>: Version 8.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get Ip Info</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Tenable Security Center</strong>: Version 22.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Enrich IP</strong></p></li>
<li><p><strong>Get Related Assets</strong></p></li>
<li><p><strong>Get Vulnerabilities for IP</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>ServiceNow</strong>: Version 63.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>List Records Related To User</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>McAfee EPO</strong>: Version 37.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Compare Server and Agent DAT</strong></p></li>
<li><p><strong>Get Agent Information</strong></p></li>
<li><p><strong>Get Dat Version</strong></p></li>
<li><p><strong>Get Endpoint Events</strong></p></li>
<li><p><strong>Get Events For Hash</strong></p></li>
<li><p><strong>Get Host IPS Status</strong></p></li>
<li><p><strong>Get Host Network IPS Status</strong></p></li>
<li><p><strong>Get Last Communication Time</strong></p></li>
<li><p><strong>Get McAfee Epo Agent Version</strong></p></li>
<li><p><strong>Get System Information</strong></p></li>
<li><p><strong>Get Virus Engine Agent Version</strong></p></li>
<li><p><strong>Run Full Scan</strong></p></li>
<li><p><strong>Update Mcafee Agent</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>RSA NetWitness</strong>: Version 20.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Query NetWitness For Events Around Host</strong></p></li>
<li><p><strong>Query NetWitness For Events Around IP</strong></p></li>
<li><p><strong>Query NetWitness For Events Around User</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Axonius</strong>: Version 7.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Add Note</strong></p></li>
<li><p><strong>Enrich Entities</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Automox</strong>: Version 8.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Enrich Entities</strong></p></li>
<li><p><strong>Execute Device Command</strong></p></li>
<li><p><strong>Execute Policy</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Cylance</strong>: Version 19.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Enrich Entities</strong></p></li>
<li><p><strong>Get Threat</strong></p></li>
<li><p><strong>Get Threat Devices</strong></p></li>
<li><p><strong>Get Threat Download Link</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Anomali</strong>: Version 15.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>GetThreatInfo</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>TruSTAR</strong>: Version 9.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Enrich Entities</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>PhishingInitiative</strong>: Version 12.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get Url Status</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Digital Shadows</strong>: Version 12.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>EnrichCVE</strong></p></li>
<li><p><strong>EnrichHash</strong></p></li>
<li><p><strong>EnrichIP</strong></p></li>
<li><p><strong>EnrichURL</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>iBoss</strong>: Version 14.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>URL Lookup</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Cloud IAM</strong>: Version 19.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Enrich Entities</strong></p></li>
<li><p><strong>Get Service Account IAM Policy</strong></p></li>
<li><p><strong>Rotate Service Account Keys</strong></p></li>
<li><p><strong>Set Service Account IAM Policy</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Sumo Logic Cloud SIEM</strong>: Version 13.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Enrich Entities</strong></p></li>
<li><p><strong>Search Entity Signals</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Teams</strong>: Version 37.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Create Chat</strong></p></li>
<li><p><strong>Send User Message</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>FortiAnalyzer</strong>: Version 12.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Enrich Entities</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Sophos</strong>: Version 21.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Enrich Entities</strong></p></li>
<li><p><strong>Get Events Log</strong></p></li>
<li><p><strong>Get Services Status</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Palo Alto Cortex XDR</strong>: Version 27.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Enrich Entities</strong></p></li>
<li><p><strong>Scan Endpoint</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Cisco Threat Grid</strong>: Version 18.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get Submissions</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Intezer</strong>: Version 14.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Submit Hash</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Recorded Future</strong>: Version 22.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Enrich CVE</strong></p></li>
<li><p><strong>Enrich Hash</strong></p></li>
<li><p><strong>Enrich Host</strong></p></li>
<li><p><strong>Enrich IP</strong></p></li>
<li><p><strong>Enrich IOC</strong></p></li>
<li><p><strong>Enrich URL</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Gmail</strong>: Version 9.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Search For Emails</strong></p></li>
<li><p><strong>Wait For Thread Reply</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Illusive Networks</strong>: Version 7.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Enrich Entities</strong></p></li>
<li><p><strong>Run Forensic Scan</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>VirusTotal</strong>: Version 42.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Domain Report</strong></p></li>
<li><p><strong>Scan Hash</strong></p></li>
<li><p><strong>Scan IP</strong></p></li>
<li><p><strong>Scan URL</strong></p></li>
<li><p><strong>Upload And Scan Files</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Anomali ThreatStream</strong>: Version 15.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Enrich Entities</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>ThreatConnect</strong>: Version 17.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Enrich Entities</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Azure Active Directory</strong>: Version 26.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Enrich Host</strong></p></li>
<li><p><strong>Enrich User</strong></p></li>
<li><p><strong>Get Manager Contact Details</strong></p></li>
<li><p><strong>List Users</strong></p></li>
<li><p><strong>List User's Groups Membership</strong></p></li>
<li><p><strong>Revoke User Session</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Splunk</strong>: Version 65.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get Host Events</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Attivo</strong>: Version 10.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Enrich Entities</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Cisco ISE</strong>: Version 16.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Add Endpoint To Endpoint Identity Group</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>DeepSight</strong>: Version 11.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Scan Domain</strong></p></li>
<li><p><strong>Scan Email</strong></p></li>
<li><p><strong>Scan File Name</strong></p></li>
<li><p><strong>Scan Hash</strong></p></li>
<li><p><strong>Scan IP</strong></p></li>
<li><p><strong>Scan URL</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Symantec Email Security Cloud</strong>: Version 5.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Block Entities</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>GSuite</strong>: Version 26.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Enrich Entities</strong></p></li>
<li><p><strong>Get Extension Details</strong></p></li>
<li><p><strong>Get Group Details</strong></p></li>
<li><p><strong>Get Host Browser Details</strong></p></li>
<li><p><strong>List Group Privileges</strong></p></li>
<li><p><strong>List User Privileges</strong></p></li>
<li><p><strong>Revoke User Session</strong></p></li>
<li><p><strong>Search User Activity Events</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>SymantecESCC</strong>: Version 9.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Enrich Entities</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Cloud Compute</strong>: Version 17.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Enrich Entities</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>FireEye HX</strong>: Version 23.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Host Alert Groups</strong></p></li>
<li><p><strong>Get Host Info</strong></p></li>
<li><p><strong>Get List of File Acquisitions For Host</strong></p></li>
<li><p><strong>Is Contain Malware Alerts</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Rapid7 InsightVm</strong>: Version 16.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Enrich Asset</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>McAfee Mvision EDRV2</strong>: Version 5.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Create Investigation</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>HCL BigFix Inventory</strong>: Version 5.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Enrich Entities</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>SiemplifyUtilities</strong>: Version 29.0</p>
<ul>
<li><p>Added support for a custom delimiter in the following action:</p>
<ul>
<li><strong>Query Joiner</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Nmap</strong>: Version 4.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Scan Entities</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>VMware Carbon Black Enterprise EDR</strong>: Version 10.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Enrich Hash</strong></p></li>
<li><p><strong>Get Events Associated With Process by Process Guide</strong></p></li>
<li><p><strong>Process Search</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Outpost24</strong>: Version 8.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Enrich Entities</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>PassiveTotal</strong>: Version 14.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>WhoIs Address Reputation</strong></p></li>
<li><p><strong>Whois Host Reputation</strong></p></li>
<li><p><strong>WhoIs Scan Address</strong></p></li>
<li><p><strong>WhoIs Scan Domain</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Carbon Black Defense</strong>: Version 12.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Device Info</strong></p></li>
<li><p><strong>Get Events</strong></p></li>
<li><p><strong>Get Processes</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>QRadar</strong>: Version 67.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Similar Events Query</strong></p></li>
<li><p><strong>Similar Flows Query</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>SentinelOneV2</strong>: Version 49.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Create Hash Blacklist Record</strong></p></li>
<li><p><strong>Create Hash Exclusion Record</strong></p></li>
<li><p><strong>Get Agent Status</strong></p></li>
<li><p><strong>Get Application List For Endpoint</strong></p></li>
<li><p><strong>Get Events For Endpoint Hours Back</strong></p></li>
<li><p><strong>Get Group Details</strong></p></li>
<li><p><strong>Get Hash Reputation</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Zscaler</strong>: Version 13.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Sandbox Report</strong></p></li>
<li><p><strong>Lookup Entity</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>McAfee Mvision EDR</strong>: Version 11.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Enrich Endpoint</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Tanium</strong>: Version 19.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Delete File</strong></p></li>
<li><p><strong>Enrich Entities</strong></p></li>
<li><p><strong>List Endpoint Events</strong></p></li>
<li><p><strong>Quarantine Endpoint</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>VMware Carbon Black Endpoint Standard Live Response</strong>: Version 10.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Create Memdump</strong></p></li>
<li><p><strong>Delete File</strong></p></li>
<li><p><strong>Delete File from Cloud Storage</strong></p></li>
<li><p><strong>Download File</strong></p></li>
<li><p><strong>Execute File</strong></p></li>
<li><p><strong>Kill Process</strong></p></li>
<li><p><strong>List Files</strong></p></li>
<li><p><strong>List Files in Cloud Storage</strong></p></li>
<li><p><strong>List Processes</strong></p></li>
<li><p><strong>Put File</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>VSphere</strong>: Version 12.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get Vm By Ip</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Nozomi Networks</strong>: Version 10.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Enrich Entities</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Active Directory</strong>: Version 41.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Enrich entities</strong></p></li>
<li><p><strong>Get Manager Contact Details</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Talos</strong>: Version 20.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Reputation</strong></p></li>
<li><p><strong>WhoIs</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Check Point Threat Reputation</strong>: Version 8.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get File Hash Reputation</strong></p></li>
<li><p><strong>Get Host Reputation</strong></p></li>
<li><p><strong>Get IP Reputation</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Zabbix</strong>: Version 16.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Execute Script</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>FireEye Helix</strong>: Version 19.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Add Entities To a List</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Malware Domain List</strong>: Version 11.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Check URL</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>AlienVault USM Appliance</strong>: Version 26.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Enrich Assets</strong></p></li>
<li><p><strong>Enrich Vulnerabilities</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Alexa</strong>: Version 9.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get URL Rank</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>AWS GuardDuty</strong>: Version 12.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get a Trusted IP List</strong></p></li>
<li><p><strong>Get Detector Details</strong></p></li>
<li><p><strong>Get Threat Intelligence Set Details</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>HTTP</strong>: Version 15.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get URL Data</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>BlueLiv</strong>: Version 13.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Enrich Entities</strong></p></li>
<li><p><strong>List Entity Threats</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Azure AD Identity Protection</strong>: Version 9.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Enrich Entities</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Carbon Black Response</strong>: Version 39.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Enrich Binary</strong></p></li>
<li><p><strong>Enrich Process</strong></p></li>
<li><p><strong>Get System Info</strong></p></li>
<li><p><strong>Hosts By Process</strong></p></li>
<li><p><strong>List Processes</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Falcon Sandbox</strong>: Version 21.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Hash Scan Report</strong></p></li>
<li><p><strong>Scan URL</strong></p></li>
<li><p><strong>Submit File</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>CSV</strong>: Version 41.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>CSV Search by Entity</strong></p></li>
<li><p><strong>CSV Search by String</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>URLVoid</strong>: Version 14.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get domain reputation</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Harmony Mobile</strong>: Version 7.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Enrich Entities</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Cloudflare</strong>: Version 8.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Add URL To Rule List</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Carbon Black Protection</strong>: Version 13.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Analyze File</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Jira</strong>: Version 56.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Search Users</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Graph Mail Delegated</strong>: Version 17.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get Mailbox Account Out Of Facility Settings</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Trend Vision One</strong>: Version 9.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Enrich Entities</strong></p></li>
<li><p><strong>Execute Custom Script</strong></p></li>
<li><p><strong>Isolate Endpoint</strong></p></li>
<li><p><strong>Submit File</strong></p></li>
<li><p><strong>Submit URL</strong></p></li>
<li><p><strong>Unisolate Endpoint</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Internet Storm Center</strong>: Version 6.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Enrich Entities</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>AlienVaultTI</strong>: Version 14.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Enriches Entities</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Threat Intelligence</strong>: Version 14.0</p>
<ul>
<li><p>Migrated the following connector to new API endpoints:</p>
<aside class="note"><strong>Note:</strong><span> Duplicate notifications may occur temporarily during the transition.</span></aside>
<ul>
<li><strong>Google Threat Intelligence - Livehunt Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Shodan</strong>: Version 17.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get Ip Info</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Cisco Vulnerability Management</strong>: Version 3.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Enrich Entities</strong></p></li>
<li><p><strong>List Asset Vulnerabilities</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>ForeScout CounterACT</strong>: Version 6.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Enrich Entities</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>McAfee ESM</strong>: Version 46.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Similar Events</strong></p></li>
<li><p><strong>Send Entity Query To ESM</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>LogRhythm</strong>: Version 23.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Enrich Entities</strong></p></li>
<li><p><strong>List Entity Events</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Mandiant ASM</strong>: Version 13.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Search ASM Entities</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Ivanti Endpoint Manager</strong>: Version 10.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Enrich Entities</strong></p></li>
<li><p><strong>List Endpoint Vulnerabilities</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Cuckoo</strong>: Version 14.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Detonate Url</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>IntSights</strong>: Version 27.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Search IOCs</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Vectra</strong>: Version 13.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Enrich Endpoint</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>McAfee ATD</strong>: Version 17.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Submit URL</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>FortinetFortiSIEM</strong>: Version 10.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Enrich Entities</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>ThreatCrowd</strong>: Version 9.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>EnrichEntities</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>APIVoid</strong>: Version 14.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get domain reputation</strong></p></li>
<li><p><strong>Get Ip Reputation</strong></p></li>
<li><p><strong>Get Screenshot</strong></p></li>
<li><p><strong>Get URL Reputation</strong></p></li>
<li><p><strong>Verify Email</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>McAfee Mvision EPOV2</strong>: Version 8.0</p>
<ul>
<li><p>Introduced light theme support for the predefined widget of the following
action:</p>
<ul>
<li><strong>Enrich Endpoint</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>VMRay</strong>: Version 19.0</p>
<ul>
<li><p>Introduced light theme support for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Scan Hash</strong></p></li>
<li><p><strong>Scan URL</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Chronicle</strong>: Version 81.0</p>
<ul>
<li><p>Added support for CIDR matching to the following action:</p>
<ul>
<li><strong>Is Value In Reference List</strong></li>
</ul></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>April 01, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-marketplace-release-notes#April_01_2026</id>
    <updated>2026-04-01T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/marketplace-integrations/release-notes#April_01_2026"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p><strong>Microsoft 365 Defender</strong>: Version 26.0</p>
<ul>
<li><p>The following new job has been added:</p>
<ul>
<li><strong>Sync Alerts</strong></li>
</ul></li>
</ul>
<h3>Feature</h3>
<p><strong>SentinelOneV2</strong>: Version 48.0</p>
<ul>
<li><p>The following new job has been added:</p>
<ul>
<li><strong>Sync Alerts</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Teams</strong>: Version 36.0</p>
<ul>
<li><p>Optimized user lookup logic for the following actions:</p>
<ul>
<li><p><strong>Add Users To Channel</strong></p></li>
<li><p><strong>Create Chat</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Akamai</strong>: Version 6.0</p>
<ul>
<li><p>Updated the JSON results of the following actions:</p>
<ul>
<li><p><strong>Add Items To Client List</strong></p></li>
<li><p><strong>Remove Items From Client List</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p>Source code is now publicly available on <a href="https://github.com/chronicle/content-hub">GitHub</a>
for the following integrations:</p>
<ul>
<li><p><strong>CyberX</strong>: Version 6.0</p></li>
<li><p><strong>JuniperVSRX</strong>: Version 11.0</p></li>
<li><p><strong>McAfee NSM</strong>: Version 11.0</p></li>
<li><p><strong>Micro Focus ITSMA</strong>: Version 7.0</p></li>
<li><p><strong>Portnox</strong>: Version 9.0</p></li>
<li><p><strong>ReversingLabs A1000</strong>: Version 10.0</p></li>
<li><p><strong>Stealthwatch V6.10</strong>: Version 6.0</p></li>
<li><p><strong>Symantec Content Analysis</strong>: Version 7.0</p></li>
</ul>
<h3>Change</h3>
<p><strong>Azure Active Directory</strong>: Version 25.0</p>
<ul>
<li><p>Added the ability to fetch last login time information to the following
actions:</p>
<ul>
<li><p><strong>Enrich User</strong></p></li>
<li><p><strong>Get Manager Contact Details</strong></p></li>
</ul></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>March 25, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-marketplace-release-notes#March_25_2026</id>
    <updated>2026-03-25T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/marketplace-integrations/release-notes#March_25_2026"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p><strong>Azure API</strong>: Version 3.0</p>
<ul>
<li><p>Added predefined widget to the following action:</p>
<ul>
<li><strong>Ping</strong></li>
</ul></li>
</ul>
<h3>Feature</h3>
<p><strong>Microsoft Graph Security</strong>: Version 26.0</p>
<ul>
<li><p>Added predefined widget to the following action:</p>
<ul>
<li><strong>Get Incident</strong></li>
</ul></li>
</ul>
<h3>Feature</h3>
<p><strong>Google Cloud IAM</strong>: Version 20.0</p>
<ul>
<li><p>The following new action has been added:</p>
<ul>
<li><strong>Rotate Service Account Keys</strong></li>
</ul></li>
</ul>
<h3>Feature</h3>
<p><strong>Siemplify</strong>: Version 106.0</p>
<ul>
<li><p>The following new action has been added:</p>
<ul>
<li><strong>Search Cases</strong></li>
</ul></li>
<li><p>Added predefined widget to the following action:</p>
<ul>
<li><strong>Search Cases</strong></li>
</ul></li>
</ul>
<h3>Feature</h3>
<p><strong>Microsoft Defender ATP</strong>: Version 30.0</p>
<ul>
<li><p>The following new actions have been added:</p>
<ul>
<li><p><strong>Get Machine Recommendations</strong></p></li>
<li><p><strong>Get Machine Vulnerabilities</strong></p></li>
<li><p><strong>Get User Related Alerts</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>BitSight</strong>: Version 12.0</p>
<ul>
<li><p>IIntroduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get Company Details</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>RSA NetWitness Platform</strong>: Version 16.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Update Incident</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>CyberArk Credential Provider</strong>: Version 3.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Application Password Value</strong></p></li>
<li><p><strong>Run CLI Application Password SDK Command</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>CrowdStrike Falcon</strong>: Version 75.0</p>
<ul>
<li><p>Added offline queueing support to the following actions:</p>
<ul>
<li><p><strong>Execute Command</strong></p></li>
<li><p><strong>Run Script</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>MobileIron</strong>: Version 6.0</p>
<ul>
<li><strong>Integration</strong>: The integration's source code is now publicly available on
<a href="https://github.com/chronicle/content-hub">Github</a>.</li>
</ul>
<h3>Change</h3>
<p><strong>FireEye HX</strong>: Version 22.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Acknowledge Alert Groups</strong></p></li>
<li><p><strong>Get Indicator</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Anomali ThreatStream</strong>: Version 14.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Related Associations</strong></p></li>
<li><p><strong>Get Related Entities</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>HashiCorp Vault</strong>: Version 6.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Generate AWS Credentials</strong></p></li>
<li><p><strong>List AWS Roles</strong></p></li>
<li><p><strong>List Key-Value Secret Keys</strong></p></li>
<li><p><strong>Read Key-Value Secret</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>AWS WAF</strong>: Version 11.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>List Rule Groups</strong></p></li>
<li><p><strong>List Web ACLs</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Graph Security</strong>: Version 26.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get Alert</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>JoeSandbox</strong>: Version 10.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Detonate File</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>ThreatQ</strong>: Version 18.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Add Attribute</strong></p></li>
<li><p><strong>Add Source</strong></p></li>
<li><p><strong>Create Adversary</strong></p></li>
<li><p><strong>Create Event</strong></p></li>
<li><p><strong>Create Indicator</strong></p></li>
<li><p><strong>Create Object</strong></p></li>
<li><p><strong>Link Objects</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Symantec Endpoint Security Complete Cloud</strong>: Version 8.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Symantec Endpoint Security Complete Cloud</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>EmailV2</strong>: Version 40.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Delete Email</strong></p></li>
<li><p><strong>Forward Email</strong></p></li>
<li><p><strong>Save Email Attachments To Case</strong></p></li>
<li><p><strong>Send Email</strong></p></li>
<li><p><strong>Send Thread Reply</strong></p></li>
<li><p><strong>Wait for Email from User</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Cofense Triage</strong>: Version 20.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Add Tags To Report</strong></p></li>
<li><p><strong>Categorize Report</strong></p></li>
<li><p><strong>Download Report Email</strong></p></li>
<li><p><strong>Download Report Preview</strong></p></li>
<li><p><strong>Get Report Reporters</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>CA Service Desk Manager</strong>: Version 26.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Wait For Status Change</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Defender ATP</strong>: Version 30.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Update Alert</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Akamai</strong>: Version 5.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Activate Client List</strong></p></li>
<li><p><strong>Activate Network List</strong></p></li>
<li><p><strong>Add Items To Network List</strong></p></li>
<li><p><strong>Remove Items From Network List</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>SSH</strong>: Version 20.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>List Connections</strong></p></li>
<li><p><strong>List iptables Rules</strong></p></li>
<li><p><strong>List Processes</strong></p></li>
<li><p><strong>Run Command</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Azure Sentinel</strong>: Version 62.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Add Comment to Incident</strong></p></li>
<li><p><strong>Create Alert Rule</strong></p></li>
<li><p><strong>Create Custom Hunting Rule</strong></p></li>
<li><p><strong>Get Alert Rule Details</strong></p></li>
<li><p><strong>Get Custom Hunting Rule Details</strong></p></li>
<li><p><strong>Get Incident Statistic</strong></p></li>
<li><p><strong>Update Alert Rule</strong></p></li>
<li><p><strong>Update Custom Hunting Rule</strong></p></li>
<li><p><strong>Update Incident Details</strong></p></li>
<li><p><strong>Update Incident Details v2</strong></p></li>
<li><p><strong>Update Incident Labels</strong></p></li>
<li><p><strong>Update Incident Labels v2</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Cloud Compute</strong>: Version 16.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Add IP To Firewall Rule</strong></p></li>
<li><p><strong>Add Network Tags</strong></p></li>
<li><p><strong>Delete Instance</strong></p></li>
<li><p><strong>Execute VM Patch Job</strong></p></li>
<li><p><strong>Remove IP From Firewall Rule</strong></p></li>
<li><p><strong>Remove Network Tags</strong></p></li>
<li><p><strong>Start Instance</strong></p></li>
<li><p><strong>Stop Instance</strong></p></li>
<li><p><strong>Update Firewall Rule</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Graph Mail Delegated</strong>: Version 16.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Forward Email</strong></p></li>
<li><p><strong>Save Email to the Case</strong></p></li>
<li><p><strong>Send Email</strong></p></li>
<li><p><strong>Send Email HTML</strong></p></li>
<li><p><strong>Send Thread Reply</strong></p></li>
<li><p><strong>Send Vote Email</strong></p></li>
<li><p><strong>Wait For Email From User</strong></p></li>
<li><p><strong>Wait For Vote Email Results</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Extrahop</strong>: Version 8.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Update Detection</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Palo Alto Cortex XDR</strong>: Version 26.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Incident Details</strong></p></li>
<li><p><strong>Query</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Recorded Future</strong>: Version 21.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get Alert Details</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>VSphere</strong>: Version 11.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get System Info</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>FireEye CM</strong>: Version 14.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Add IOC Feed</strong></p></li>
<li><p><strong>Download Alert Artifacts</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Tenable.io</strong>: Version 16.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Scan Endpoints</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Remote Agent Utilities</strong>: Version 7.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Serialize A File</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>FireEye Helix</strong>: Version 18.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Archive Search</strong></p></li>
<li><p><strong>Get Alert Details</strong></p></li>
<li><p><strong>Index Search</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Okta</strong>: Version 16.0</p>
<ul>
<li><strong>Integration</strong>: Added support for OAuth authentication.</li>
</ul>
<h3>Change</h3>
<p><strong>Office 365 CloudApp Security</strong>: Version 25.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Add IP To IP Address Range</strong></p></li>
<li><p><strong>Create IP Address Range</strong></p></li>
<li><p><strong>Remove IP From IP Address Range</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Palo Alto Prisma Cloud</strong>: Version 6.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Enrich Assets</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Cloud Armor</strong>: Version 5.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Add a Rule to a Security Policy</strong></p></li>
<li><p><strong>Create a Security Policy</strong></p></li>
<li><p><strong>Update a Security Policy</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Redis</strong>: Version 8.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Add To List</strong></p></li>
<li><p><strong>Get List</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Carbon Black Response</strong>: Version 38.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get FileMod Data For Process</strong></p></li>
<li><p><strong>Get Process Tree Data</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Graph Mail</strong>: Version 39.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Forward Email</strong></p></li>
<li><p><strong>Save Email to the Case</strong></p></li>
<li><p><strong>Send Email</strong></p></li>
<li><p><strong>Send Email HTML</strong></p></li>
<li><p><strong>Send Thread Reply</strong></p></li>
<li><p><strong>Send Vote Email</strong></p></li>
<li><p><strong>Wait For Email From User</strong></p></li>
<li><p><strong>Wait For Vote Email Results</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>NessusScanner</strong>: Version 12.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get Scan Templates</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Atlassian Confluence Server</strong>: Version 5.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Child Pages</strong></p></li>
<li><p><strong>Get Page by ID</strong></p></li>
<li><p><strong>Get Page Comments</strong></p></li>
<li><p><strong>List Pages</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Slack</strong>: Version 29.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Build Block</strong></p></li>
<li><p><strong>Create Channel</strong></p></li>
<li><p><strong>Get User Details</strong></p></li>
<li><p><strong>Get User Details By Id</strong></p></li>
<li><p><strong>Rename Channel</strong></p></li>
<li><p><strong>Wait For Reply</strong></p></li>
<li><p><strong>Wait For Reply With Webhook</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>McAfee ATD</strong>: Version 16.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Report</strong></p></li>
<li><p><strong>Submit File</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Symantec ICDX</strong>: Version 9.0</p>
<ul>
<li><strong>Integration</strong>: The integration's source code is now publicly available on
<a href="https://github.com/chronicle/content-hub">Github</a>.</li>
</ul>
<h3>Change</h3>
<p><strong>McAfee NSM</strong>: Version 10.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get Alert Info Data</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Cloudflare</strong>: Version 7.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Create Firewall Rule</strong></p></li>
<li><p><strong>Create Rule List</strong></p></li>
<li><p><strong>Update Firewall Rule</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Rapid7 InsightIDR</strong>: Version 12.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Create Saved Query</strong></p></li>
<li><p><strong>Set Investigation Assignee</strong></p></li>
<li><p><strong>Set Investigation Status</strong></p></li>
<li><p><strong>Update Investigation</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Exchange Extension Pack</strong>: Version 13.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Add Domains to Exchange-Siemplify Mail Flow Rules</strong></p></li>
<li><p><strong>Add Senders to Exchange-Siemplify Mail Flow Rule</strong></p></li>
<li><p><strong>Purge Compliance Search Results</strong></p></li>
<li><p><strong>Remove Domains from Exchange-Siemplify Mail Flow Rules</strong></p></li>
<li><p><strong>Remove Senders from Exchange-Siemplify Mail Flow Rules</strong></p></li>
<li><p><strong>Run Compliance Search</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>CSV</strong>: Version 40.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Save Json To CSV</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Mandiant ASM</strong>: Version 12.0</p>
<ul>
<li><p>IIntroduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Update Issue</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Shodan</strong>: Version 16.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>DNS Resolve</strong></p></li>
<li><p><strong>DNS Reverse</strong></p></li>
<li><p><strong>Get Api Info</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Kubernetes Engine</strong>: Version 9.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Operation Status</strong></p></li>
<li><p><strong>List Clusters</strong></p></li>
<li><p><strong>List Node Pools</strong></p></li>
<li><p><strong>List Operations</strong></p></li>
<li><p><strong>Set Cluster Addons</strong></p></li>
<li><p><strong>Set Cluster Labels</strong></p></li>
<li><p><strong>Set Node Autoscaling</strong></p></li>
<li><p><strong>Set Node Count</strong></p></li>
<li><p><strong>Set Node Pool Management</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>SiemplifyUtilities</strong>: Version 28.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Delete File</strong></p></li>
<li><p><strong>Filter JSON</strong></p></li>
<li><p><strong>Get Deployment URL</strong></p></li>
<li><p><strong>List Operations</strong></p></li>
<li><p><strong>Parse EML to JSON</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Anomali</strong>: Version 14.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get Related Associations</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Reversinglabs A1000</strong>: Version 9.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Upload File</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>CyberArk PAM</strong>: Version 9.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get Account Password Value</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Jira</strong>: Version 55.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Create Alert Issue</strong></p></li>
<li><p><strong>Create Issue</strong></p></li>
<li><p><strong>List Issues</strong></p></li>
<li><p><strong>Update Issue</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Ivanti Endpoint Manager</strong>: Version 9.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Execute Query</strong></p></li>
<li><p><strong>List Column Set Fields</strong></p></li>
<li><p><strong>List Column Sets</strong></p></li>
<li><p><strong>List Delivery Methods</strong></p></li>
<li><p><strong>List Packages</strong></p></li>
<li><p><strong>List Queries</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Check Point Firewall</strong>: Version 15.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Add a SAM Rule</strong></p></li>
<li><p><strong>Remove SAM Rule</strong></p></li>
<li><p><strong>Run Script</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Any.Run</strong>: Version 11.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>AnalyzeFile</strong></p></li>
<li><p><strong>AnalyzeFileURL</strong></p></li>
<li><p><strong>AnalyzeURL</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Carbon Black Protection</strong>: Version 12.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><strong>Get System Info</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>LogRhythm</strong>: Version 22.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Add Note To Case</strong></p></li>
<li><p><strong>Create Cas</strong></p></li>
<li><p><strong>Download Case Files</strong></p></li>
<li><p><strong>Update Case</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>BMC Remedy ITSM</strong>: Version 12.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Create Incident</strong></p></li>
<li><p><strong>Create Record</strong></p></li>
<li><p><strong>Wait For Incident Fields Update</strong></p></li>
<li><p><strong>Wait For Record Fields Update</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>AlienVault USM Anywhere</strong>: Version 35.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get Alarm Details</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Zoho Desk</strong>: Version 11.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Add Comment To Ticket</strong></p></li>
<li><p><strong>Create Ticket</strong></p></li>
<li><p><strong>Update Ticket</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>AWS GuardDuty</strong>: Version 11.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Create a Detector</strong></p></li>
<li><p><strong>Create a Trusted IP List</strong></p></li>
<li><p><strong>Create Threat Intelligence Set</strong></p></li>
<li><p><strong>Get all Trusted IP lists</strong></p></li>
<li><p><strong>Get Finding Details</strong></p></li>
<li><p><strong>List Detectors</strong></p></li>
<li><p><strong>List Findings for a Detector</strong></p></li>
<li><p><strong>List Threat Intelligence Sets</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>AWS Elastic Compute Cloud (EC2)</strong>: Version 10.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>List Instances</strong></p></li>
<li><p><strong>List Security Groups</strong></p></li>
<li><p><strong>Take Snapshot</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Cybereason</strong>: Version 24.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Malop</strong></p></li>
<li><p><strong>List Malop Processes</strong></p></li>
<li><p><strong>List Reputation Items</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Rapid7 InsightVm</strong>: Version 15.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Scan Results</strong></p></li>
<li><p><strong>Launch Scan</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Cisco AMP</strong>: Version 22.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Create Group</strong></p></li>
<li><p><strong>Get File Lists By Policy</strong></p></li>
<li><p><strong>Get Groups</strong></p></li>
<li><p><strong>Get Policies</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Trend Micro Cloud App Security</strong>: Version 11.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Enrich Entities</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>CiscoUmbrella</strong>: Version 18.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get Malicious Domains</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Solar Winds Orion</strong>: Version 7.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Enrich Endpoint</strong></p></li>
<li><p><strong>Execute Entity Query</strong></p></li>
<li><p><strong>Execute Query</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Tenable Security Center</strong>: Version 21.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Add IP To IP List Asset</strong></p></li>
<li><p><strong>Create IP List Asset</strong></p></li>
<li><p><strong>Get Report</strong></p></li>
<li><p><strong>Get Scan Results</strong></p></li>
<li><p><strong>Run Asset Scan</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Gmail</strong>: Version 8.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Forward Email</strong></p></li>
<li><p><strong>Save Email To The Case</strong></p></li>
<li><p><strong>Send Email</strong></p></li>
<li><p><strong>Send Thread Reply</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>FireEye AX</strong>: Version 8.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get Appliance Details</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>FortiAnalyzer</strong>: Version 11.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Add Comment To Alert</strong></p></li>
<li><p><strong>Update Alert</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>WMI</strong>: Version 14.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>GetSystemInfo</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Chat</strong>: Version 7.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Send Advanced Message</strong></p></li>
<li><p><strong>Send Message</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>SentinelOneV2</strong>: Version 47.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Create Device Control Rule</strong></p></li>
<li><p><strong>Download Threat File</strong></p></li>
<li><p><strong>Enrich Endpoint</strong></p></li>
<li><p><strong>Get System Status</strong></p></li>
<li><p><strong>Update Alert</strong></p></li>
<li><p><strong>Update Device Control Rule</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Translate</strong>: Version 6.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Translate Text</strong></p></li>
<li><p><strong>List Languages</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Exchange</strong>: Version 122.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Save Mail Attachments To The Case</strong></p></li>
<li><p><strong>Send Mail</strong></p></li>
<li><p><strong>Send Thread Reply</strong></p></li>
<li><p><strong>Send Vote Mail</strong></p></li>
<li><p><strong>Wait for mail from user</strong></p></li>
<li><p><strong>Wait for Vote Mail Results</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Symantec ATP</strong>: Version 12.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get Incident Comments</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Azure API</strong>: Version 3.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Execute HTTP Request</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Tanium</strong>: Version 18.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Create Question</strong></p></li>
<li><p><strong>Download File</strong></p></li>
<li><p><strong>Get Question Results</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Site24x7</strong>: Version 6.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Generate Refresh Token</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>ConnectWise</strong>: Version 21.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Add Attachment To Ticket</strong></p></li>
<li><p><strong>Get Ticket</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Cisco Threat Grid</strong>: Version 17.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Upload Sample</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Zendesk</strong>: Version 12.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Ticket Details</strong></p></li>
<li><p><strong>Search Tickets</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Symantec Endpoint Protection 12</strong>: Version 15.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>GetReport</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>ServiceNow</strong>: Version 62.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Add Comment To Record</strong></p></li>
<li><p><strong>Add Parent Incident</strong></p></li>
<li><p><strong>Create Alert Incident</strong></p></li>
<li><p><strong>Create Incident</strong></p></li>
<li><p><strong>Create Record</strong></p></li>
<li><p><strong>Get Incident</strong></p></li>
<li><p><strong>Get Oauth Token</strong></p></li>
<li><p><strong>Get Record Details</strong></p></li>
<li><p><strong>Update Incident</strong></p></li>
<li><p><strong>Update Record</strong></p></li>
<li><p><strong>Wait For Field Update</strong></p></li>
<li><p><strong>Wait For Status Update</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Cuckoo</strong>: Version 13.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Detonate File</strong></p></li>
<li><p><strong>Get Report</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Sophos</strong>: Version 20.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>List Alert Actions</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>IronPort</strong>: Version 15.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get All Recipients By Sender</strong></p></li>
<li><p><strong>Get All Recipients By Subject</strong></p></li>
<li><p><strong>Get Report</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Lastline</strong>: Version 8.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Search Analysis History</strong></p></li>
<li><p><strong>Submit File</strong></p></li>
<li><p><strong>Submit URL</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>F5 BIG-IP iControl API</strong>: Version 7.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Add IP To Address List</strong></p></li>
<li><p><strong>Add IP To Data Group</strong></p></li>
<li><p><strong>Add Port To Port List</strong></p></li>
<li><p><strong>Create Address List</strong></p></li>
<li><p><strong>Create Data Group</strong></p></li>
<li><p><strong>Create iRule</strong></p></li>
<li><p><strong>Create Port List</strong></p></li>
<li><p><strong>Remove IP From Address List</strong></p></li>
<li><p><strong>Remove IP From Data Group</strong></p></li>
<li><p><strong>Remove Port From Port List</strong></p></li>
<li><p><strong>Update iRule</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Palo Alto Panorama</strong>: Version 35.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Add Ips to group</strong></p></li>
<li><p><strong>Block ips in policy</strong></p></li>
<li><p><strong>Block Urls</strong></p></li>
<li><p><strong>Edit Blocked Applications</strong></p></li>
<li><p><strong>Get Blocked Applications</strong></p></li>
<li><p><strong>Remove Ips from group</strong></p></li>
<li><p><strong>Unblock ips in policy</strong></p></li>
<li><p><strong>Unblock Urls</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Cynet</strong>: Version 12.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Hash Query</strong></p></li>
<li><p><strong>Remediation Status</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Trend Vision One</strong>: Version 8.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Execute Email</strong></p></li>
<li><p><strong>Update Workbench Alert</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>MalShare</strong>: Version 10.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Upload File</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Tor</strong>: Version 9.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Is Exit Node</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Qualys VM</strong>: Version 24.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Download Report</strong></p></li>
<li><p><strong>List Ips</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>BMC Helix Remedyforce</strong>: Version 17.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Create Record</strong></p></li>
<li><p><strong>Wait For Fields Update</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>AlienVault USM Appliance</strong>: Version 25.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get PCAP Files For Events</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Service Desk Plus</strong>: Version 8.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Create Request</strong></p></li>
<li><p><strong>Get Request</strong></p></li>
<li><p><strong>Update Request</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>FireEye NX</strong>: Version 11.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Download Alert Artifacts</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Intezer</strong>: Version 13.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Alert</strong></p></li>
<li><p><strong>Submit Alert</strong></p></li>
<li><p><strong>Submit File</strong></p></li>
<li><p><strong>Submit Suspicious Email</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>MISP</strong>: Version 37.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Create Event</strong></p></li>
<li><p><strong>Create File Misp Object</strong></p></li>
<li><p><strong>Create IP-Port Misp Object</strong></p></li>
<li><p><strong>Create network-connection Misp Object</strong></p></li>
<li><p><strong>Create Virustotal-Report Object</strong></p></li>
<li><p><strong>Download File</strong></p></li>
<li><p><strong>Publish Event</strong></p></li>
<li><p><strong>Unpublish Event</strong></p></li>
<li><p><strong>Upload File</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Palo Alto Next Gen Firewall</strong>: Version 28.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Add Ips to group</strong></p></li>
<li><p><strong>Block ips in policy</strong></p></li>
<li><p><strong>Block Urls</strong></p></li>
<li><p><strong>Edit Blocked Applications</strong></p></li>
<li><p><strong>Get Blocked Applications</strong></p></li>
<li><p><strong>Remove Ips from group</strong></p></li>
<li><p><strong>Unblock ips in policy</strong></p></li>
<li><p><strong>Unblock Urls</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Illusive Networks</strong>: Version 6.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>List Deceptive Items</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Freshworks Freshservice</strong>: Version 18.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Create Agent</strong></p></li>
<li><p><strong>Deactivate Agent</strong></p></li>
<li><p><strong>Update Agent</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Splunk</strong>: Version 64.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Submit Event</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>AlgoSec</strong>: Version 7.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Allow IP</strong></p></li>
<li><p><strong>Block IP</strong></p></li>
<li><p><strong>Wait for Change Request Status Update</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Salesforce</strong>: Version 17.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Case</strong></p></li>
<li><p><strong>Search Records</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>RSA Archer</strong>: Version 14.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Add Incident Journal Entry</strong></p></li>
<li><p><strong>Create Incident</strong></p></li>
<li><p><strong>Get Incident Details</strong></p></li>
<li><p><strong>Update Incident</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>QRadar</strong>: Version 66.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>QRadar AQL Search</strong></p></li>
<li><p><strong>QRadar Simple AQL Search</strong></p></li>
<li><p><strong>Update Offense</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Mimecast</strong>: Version 15.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Create Block Sender Policy</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Sumo Logic Cloud SIEM</strong>: Version 12.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Add Tags To Insight</strong></p></li>
<li><p><strong>Add Comment To Insight</strong></p></li>
<li><p><strong>Update Insight</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>ArcSight</strong>: Version 45.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>List Resources</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Teams</strong>: Version 35.0</p>
<ul>
<li><p><strong>Integration</strong>: Updated dependencies.</p></li>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Create Channel</strong></p></li>
<li><p><strong>Create Channel</strong></p></li>
<li><p><strong>Send Chat Message</strong></p></li>
<li><p><strong>Send Message Reply</strong></p></li>
<li><p><strong>Wait For Reply</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Service Desk Plus V3</strong>: Version 8.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Add Note</strong></p></li>
<li><p><strong>Add Note And Wait For Reply</strong></p></li>
<li><p><strong>Close Request</strong></p></li>
<li><p><strong>Create Alert Request</strong></p></li>
<li><p><strong>Create Request</strong></p></li>
<li><p><strong>Create Request - Dropdown Lists</strong></p></li>
<li><p><strong>Get Request</strong></p></li>
<li><p><strong>Update Request</strong></p></li>
<li><p><strong>Wait For Field Update</strong></p></li>
<li><p><strong>Wait For Status Update</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>AWS CloudWatch</strong>: Version 9.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Create Log Group</strong></p></li>
<li><p><strong>Create Log Stream</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Endgame</strong>: Version 14.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get Investigation Details</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Falcon Sandbox</strong>: Version 20.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Wait For Job and Fetch Report</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Cloud Recommender</strong>: Version 10.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Apply IAM Recommendations</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>HTTP Rest API</strong>: Version 14.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Data</strong></p></li>
<li><p><strong>Post Data</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Threat Intelligence</strong>: Version 13.0</p>
<ul>
<li><p>Improved loading for predefined widgets of the following actions:</p>
<ul>
<li><p><strong>Enrich Entities</strong></p></li>
<li><p><strong>Enrich IOC</strong></p></li>
</ul></li>
<li><p>Removed the usage of a deprecated API endpoint and the <code>Retrieve AI Summary</code>
parameter from the following action:</p>
<ul>
<li><strong>Submit File</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>IntSights</strong>: Version 26.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Download Alert CSV</strong></li>
</ul></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>March 18, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-marketplace-release-notes#March_18_2026</id>
    <updated>2026-03-18T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/marketplace-integrations/release-notes#March_18_2026"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p><strong>Microsoft Graph Mail</strong>: Version 37.0</p>
<ul>
<li><p>A new predefined widget has been added to the following action:</p>
<ul>
<li><strong>Delete Email</strong></li>
</ul></li>
</ul>
<h3>Feature</h3>
<p><strong>CrowdStrike Falcon</strong>: Version 73.0</p>
<ul>
<li><p>The following new action has been added:</p>
<ul>
<li><strong>Hide Hosts</strong></li>
</ul></li>
</ul>
<h3>Feature</h3>
<p><strong>Endgame</strong>: Version 73.0</p>
<ul>
<li><p>New predefined widgets have been added to following actions:</p>
<ul>
<li><p><strong>Get Endpoints</strong></p></li>
<li><p><strong>Get Host Isolation Config</strong></p></li>
<li><p><strong>Hunt File</strong></p></li>
<li><p><strong>Hunt IP</strong></p></li>
<li><p><strong>Hunt Process</strong></p></li>
<li><p><strong>Hunt Registry</strong></p></li>
<li><p><strong>Hunt User</strong></p></li>
<li><p><strong>List Investigations</strong></p></li>
</ul></li>
</ul>
<h3>Feature</h3>
<p><strong>Microsoft Graph Security</strong>: Version 24.0</p>
<ul>
<li><p>A new predefined widget has been added to the following action:</p>
<ul>
<li><strong>List Incidents</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Azure Security Center</strong>: Version 14.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>List Regulatory Standards</strong></p></li>
<li><p><strong>List Regulatory Standard Controls</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Zoho Desk</strong>: Version 9.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get Ticket Details</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Stellar Cyber Starlight</strong>: Version 17.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Advanced Search</strong></p></li>
<li><p><strong>Simple Search</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Siemplify ThreatFuse</strong>: Version 17.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Related Associations</strong></p></li>
<li><p><strong>Get Related Domains</strong></p></li>
<li><p><strong>Get Related Email Addresses</strong></p></li>
<li><p><strong>Get Related Hashes</strong></p></li>
<li><p><strong>Get Related IPs</strong></p></li>
<li><p><strong>Get Related URLs</strong></p></li>
<li><p><strong>Submit Observables</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Devo</strong>: Version 10.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Advanced Query</strong></p></li>
<li><p><strong>Simple Query</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>AWS CloudWatch</strong>: Version 7.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>List Log Groups</strong></p></li>
<li><p><strong>List Log Streams</strong></p></li>
<li><p><strong>Search Log Events</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>ZScaler</strong>: Version 11.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get Url Categories</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Workspace</strong>: Version 24.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Add Members To Group</strong></p></li>
<li><p><strong>Block Extension</strong></p></li>
<li><p><strong>Create Group</strong></p></li>
<li><p><strong>Create OU</strong></p></li>
<li><p><strong>Create User</strong></p></li>
<li><p><strong>Delete Extension</strong></p></li>
<li><p><strong>List Group Members</strong></p></li>
<li><p><strong>List OU Of Account</strong></p></li>
<li><p><strong>List Users</strong></p></li>
<li><p><strong>Update OU</strong></p></li>
<li><p><strong>Update User</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Azure Active Directory</strong>: Version 23.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>List Groups</strong></p></li>
<li><p><strong>List Members in the Group</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Trend Micro Cloud App Security</strong>: Version 9.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Entity Email Search</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Tanium</strong>: Version 16.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Task Details</strong></p></li>
<li><p><strong>List Connections</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Intezer</strong>: Version 11.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Detonate File</strong></p></li>
<li><p><strong>Detonate Hash</strong></p></li>
<li><p><strong>Detonate URL</strong></p></li>
<li><p><strong>Get File Report</strong></p></li>
<li><p><strong>Get URL Report</strong></p></li>
<li><p><strong>Index File</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>RSA NetWitness</strong>: Version 18.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Run General Query</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>MongoDB</strong>: Version 8.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Free Query</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Exchange</strong>: Version 120.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Block Sender by Message ID</strong></p></li>
<li><p><strong>Delete Mail</strong></p></li>
<li><p><strong>Download Attachments</strong></p></li>
<li><p><strong>Extract EML Data</strong></p></li>
<li><p><strong>List Exchange-Siemplify Inbox Rules</strong></p></li>
<li><p><strong>Move Mail To Folder</strong></p></li>
<li><p><strong>Search Mails</strong></p></li>
<li><p><strong>Unblock Sender by Message ID</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>ThreatQ</strong>: Version 16.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>List Events</strong></p></li>
<li><p><strong>List Related Objects</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>RSA NetWitness Platform</strong>: Version 14.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Run General Query</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Carbon Black Response</strong>: Version 36.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Binary Free Query</strong></p></li>
<li><p><strong>Process Free Query</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Symantec Endpoint Protection</strong>: Version 19.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Report And Enrich</strong></p></li>
<li><p><strong>GetReport</strong></p></li>
<li><p><strong>ListEndpoints</strong></p></li>
<li><p><strong>ListGroups</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>AlienVault USM Anywhere</strong>: Version 33.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>List Events</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Mandiant Digital Threat Monitoring</strong>: Version 5.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Update Alert</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>FireEye CM</strong>: Version 12.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Download Custom Rules File</strong></p></li>
<li><p><strong>Download Quarantined Email</strong></p></li>
<li><p><strong>List IOC Feeds</strong></p></li>
<li><p><strong>List Quarantined Emails</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Threat Intelligence</strong>: Version 11.0</p>
<ul>
<li><p>Updated <code>is_suspicious</code> and <code>is_risky</code> logic handling in the following
actions:</p>
<ul>
<li><p><strong>Enrich Entities</strong></p></li>
<li><p><strong>Submit File</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Shodan</strong>: Version 14.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Search</strong></p></li>
<li><p><strong>SearchForExploits</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Snowflake</strong>: Version 7.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Execute Custom Query</strong></p></li>
<li><p><strong>Execute Simple Query</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Proofpoint Threat Protection</strong>: Version 2.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Allow List Entries</strong></p></li>
<li><p><strong>Get Block List Entries</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Vectra</strong>: Version 11.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get Triage Rule Details</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>MSSQL</strong>: Version 18.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>RunSQLQuery</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Rapid7 InsightVm</strong>: Version 13.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>List Scans</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>ServiceNow</strong>: Version 60.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Add Attachment</strong></p></li>
<li><p><strong>Download Attachments</strong></p></li>
<li><p><strong>Get Child Incident Details</strong></p></li>
<li><p><strong>Get CMDB Record Details</strong></p></li>
<li><p><strong>Get User Details</strong></p></li>
<li><p><strong>List CMDB Records</strong></p></li>
<li><p><strong>List Record Comments</strong></p></li>
<li><p><strong>Wait For Comments</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>CiscoUmbrella</strong>: Version 16.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>List Top Domains</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>RSA NetWitness EDR</strong>: Version 7.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Add IP To Blacklist</strong></p></li>
<li><p><strong>Add URL To Blacklist</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft 365 Defender</strong>: Version 24.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Execute Custom Query</strong></p></li>
<li><p><strong>Execute Entity Query</strong></p></li>
<li><p><strong>Execute Query</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Easy Vista</strong>: Version 6.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get EasyVista Ticket</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Sumologic</strong>: Version 18.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Search</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Symantec Endpoint Security Complete Cloud</strong>: Version 6.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>List Device Groups</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Rapid Response (GRR)</strong>: Version 9.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Hunt Details</strong></p></li>
<li><p><strong>List Hunts</strong></p></li>
<li><p><strong>Start a Hunt</strong></p></li>
<li><p><strong>Stop a Hunt</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>TruSTAR</strong>: Version 7.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Related IOCs</strong></p></li>
<li><p><strong>Get Related Reports</strong></p></li>
<li><p><strong>List Enclaves</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>FireEye AX</strong>: Version 6.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Submit File</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>McAfee ATD</strong>: Version 14.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get Analyzer Profiles</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Mimecast</strong>: Version 13.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Advanced Archive Search</strong></p></li>
<li><p><strong>Simple Archive Search</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Azure Sentinel</strong>: Version 60.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>List Alert Rules</strong></p></li>
<li><p><strong>List Custom Hunting Rules</strong></p></li>
<li><p><strong>List Incidents</strong></p></li>
<li><p><strong>Run Custom Hunting Rule Query</strong></p></li>
<li><p><strong>Run KQL Query</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>ElasticSearch</strong>: Version 42.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Advanced ES Search</strong></p></li>
<li><p><strong>DSL Search</strong></p></li>
<li><p><strong>Simple ES Search</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>FireEye HX</strong>: Version 20.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Alert Group Details</strong></p></li>
<li><p><strong>Get Alerts</strong></p></li>
<li><p><strong>Get Alerts in Alert Group</strong></p></li>
<li><p><strong>Get Indicators</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>FortiGate</strong>: Version 18.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>List Address Groups</strong></p></li>
<li><p><strong>List Policies</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>CBProtection</strong>: Version 10.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Find File</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>BlueLiv</strong>: Version 11.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Add Comment to a Threat</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>MISP</strong>: Version 35.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Add Attribute</strong></p></li>
<li><p><strong>Add Sighting to an Attribute</strong></p></li>
<li><p><strong>Add Tag to an Attribute</strong></p></li>
<li><p><strong>Add Tag to an Event</strong></p></li>
<li><p><strong>Create Url Misp Object</strong></p></li>
<li><p><strong>Delete an Attribute</strong></p></li>
<li><p><strong>Delete an Event</strong></p></li>
<li><p><strong>List Event Objects</strong></p></li>
<li><p><strong>List Sightings of an Attribute</strong></p></li>
<li><p><strong>Remove Tag from an Attribute</strong></p></li>
<li><p><strong>Remove Tag from an Event</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Exchange Extension Pack</strong>: Version 11.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Fetch Compliance Search Results</strong></p></li>
<li><p><strong>List Exchange-Siemplify Mail Flow Rules</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Cloud Storage</strong>: Version 13.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Download an Object From a Bucket</strong></p></li>
<li><p><strong>Get a Bucket's Access Control List</strong></p></li>
<li><p><strong>List Bucket Objects</strong></p></li>
<li><p><strong>List Buckets</strong></p></li>
<li><p><strong>Upload an Object To a Bucket</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Graph Mail Delegated</strong>: Version 14.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Delete Email</strong></p></li>
<li><p><strong>Download Attachments from Email</strong></p></li>
<li><p><strong>Extract Data from Attached EML</strong></p></li>
<li><p><strong>Move Email To Folder</strong></p></li>
<li><p><strong>Run Microsoft Search Query</strong></p></li>
<li><p><strong>Search Emails</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Ivanti Endpoint Manager</strong>: Version 7.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Execute Task</strong></p></li>
<li><p><strong>Scan Endpoints</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Akamai</strong>: Version 3.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Add Items To Client List</strong></p></li>
<li><p><strong>Get Client Lists</strong></p></li>
<li><p><strong>Get Network Lists</strong></p></li>
<li><p><strong>Remove Items From Client List</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>CyberArk PAM</strong>: Version 7.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>List Accounts</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Nozomi Networks</strong>: Version 8.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>List Vulnerabilities</strong></p></li>
<li><p><strong>Run a Query</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>iBoss</strong>: Version 12.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>List Policy Block List Entries</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>FireEye EX</strong>: Version 12.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Download Alert Artifacts</strong></p></li>
<li><p><strong>Download Quarantined Email</strong></p></li>
<li><p><strong>List Quarantined Emails</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>AWS Security Hub</strong>: Version 9.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Create Insight</strong></p></li>
<li><p><strong>Get Insight Details</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Mandiant ASM</strong>: Version 10.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get ASM Entity Details</strong></p></li>
<li><p><strong>Search Issues</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Cisco Orbital</strong>: Version 17.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Execute Query</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>IronScales</strong>: Version 5.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Incident Details</strong></p></li>
<li><p><strong>Get Incident Mitigation Details</strong></p></li>
<li><p><strong>Get Mitigation Impersonation Detail</strong></p></li>
<li><p><strong>Get Mitigations Per Mailbox</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Cloud IAM</strong>: Version 16.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Create Role</strong></p></li>
<li><p><strong>Create Service Account</strong></p></li>
<li><p><strong>Delete Role</strong></p></li>
<li><p><strong>List Roles</strong></p></li>
<li><p><strong>List Service Accounts</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Armis</strong>: Version 13.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>List Alert Connections</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Attivo</strong>: Version 8.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>List Critical ThreatPath</strong></p></li>
<li><p><strong>List Service ThreatPaths</strong></p></li>
<li><p><strong>List Vulnerability Hosts</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Falcon Sandbox</strong>: Version 18.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Analyze File</strong></p></li>
<li><p><strong>Analyze File URL</strong></p></li>
<li><p><strong>Search</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Tenable.io</strong>: Version 14.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Vulnerability Details</strong></p></li>
<li><p><strong>List Plugin Families</strong></p></li>
<li><p><strong>List Policies</strong></p></li>
<li><p><strong>List Scanners</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Chat</strong>: Version 5.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>List Spaces</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>IntSights</strong>: Version 24.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get Alert Image</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Jira</strong>: Version 53.0</p>
<ul>
<li><p><strong>Integration</strong>: Added support for service account token based authentication.</p></li>
<li><p><strong>Integration</strong>: Updated issue object handling.</p></li>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Download Attachments</strong></p></li>
<li><p><strong>Get Issues</strong></p></li>
<li><p><strong>List Relation Types</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google BigQuery</strong>: Version 16.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Run Custom Query</strong></p></li>
<li><p><strong>Run SQL Query</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>ArcSight</strong>: Version 43.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Activelist Entries</strong></p></li>
<li><p><strong>Get Query Results</strong></p></li>
<li><p><strong>Get Report</strong></p></li>
<li><p><strong>Is Value In Activelist Column</strong></p></li>
<li><p><strong>Search</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Check Point Firewall</strong>: Version 13.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Download Log Attachment</strong></p></li>
<li><p><strong>List Layers On Site</strong></p></li>
<li><p><strong>List Policies On Site</strong></p></li>
<li><p><strong>Show Logs</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>FortiAnalyzer</strong>: Version 9.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Search Logs</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Defender ATP</strong>: Version 28.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Create Isolate Machine Task</strong></p></li>
<li><p><strong>Create Run Antivirus Scan Task</strong></p></li>
<li><p><strong>Create Stop And Quarantine File Specific Machine Task</strong></p></li>
<li><p><strong>Create Unisolate Machine Task</strong></p></li>
<li><p><strong>Get Current Task Status</strong></p></li>
<li><p><strong>List Alerts</strong></p></li>
<li><p><strong>List Indicators</strong></p></li>
<li><p><strong>List Machines</strong></p></li>
<li><p><strong>Run Advanced Hunting Query</strong></p></li>
<li><p><strong>Wait Task Status</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Teams</strong>: Version 33.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>List Chats</strong></p></li>
<li><p><strong>List Teams</strong></p></li>
<li><p><strong>List Users</strong></p></li>
<li><p><strong>Send Message</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Recorded Future</strong>: Version 19.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Update Alert</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Active Directory</strong>: Version 39.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Group Members</strong></p></li>
<li><p><strong>Search Active Directory</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Cofense Triage</strong>: Version 18.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Report Headers</strong></p></li>
<li><p><strong>List Categories</strong></p></li>
<li><p><strong>List Playbooks</strong></p></li>
<li><p><strong>List Reports Related To Threat Indicators</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>ElasticSearchV7</strong>: Version 20.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Advanced ES Search</strong></p></li>
<li><p><strong>DSL Search</strong></p></li>
<li><p><strong>Simple ES Search</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>BMC Remedy ITSM</strong>: Version 10.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Incident Details</strong></p></li>
<li><p><strong>Get Record Details</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Cloudflare</strong>: Version 5.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Add IP To Rule List</strong></p></li>
<li><p><strong>List Firewall Rules</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>OpenSearch</strong>: Version 2.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Advanced OS Search</strong></p></li>
<li><p><strong>DSL Search</strong></p></li>
<li><p><strong>Simple OS Search</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Graph Mail</strong>: Version 37.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Download Attachments from Email</strong></p></li>
<li><p><strong>Extract Data from Attached EML</strong></p></li>
<li><p><strong>Move Email To Folder</strong></p></li>
<li><p><strong>Search Emails</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>F5 BIG-IP Access Policy Manager</strong>: Version 6.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>List Active Sessions</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>McAfee Mvision EPO</strong>: Version 9.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>List Endpoints In Group</strong></p></li>
<li><p><strong>List Groups</strong></p></li>
<li><p><strong>List Tags</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Palo Alto Cortex XDR</strong>: Version 24.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Execute XQL Search</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>XForce</strong>: Version 17.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get IP By Category</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Okta</strong>: Version 14.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get User</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Intune</strong>: Version 6.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>List Managed Devices</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>F5 BIG-IP iControl API</strong>: Version 5.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>List Address Lists</strong></p></li>
<li><p><strong>List Data Groups</strong></p></li>
<li><p><strong>List Port Lists</strong></p></li>
<li><p><strong>List iRules</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>AppSheet</strong>: Version 4.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Add Record</strong></p></li>
<li><p><strong>Delete Record</strong></p></li>
<li><p><strong>List Tables</strong></p></li>
<li><p><strong>Search Records</strong></p></li>
<li><p><strong>Update Record</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>McAfee ESM</strong>: Version 44.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Send Advanced Query To ESM</strong></p></li>
<li><p><strong>Send Query To ESM</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Cloud Recommender</strong>: Version 8.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Recommendation</strong></p></li>
<li><p><strong>List Recommendations</strong></p></li>
<li><p><strong>Update Recommendation</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Any.Run</strong>: Version 9.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Search Report History</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>FireEye Helix</strong>: Version 16.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Lists</strong></p></li>
<li><p><strong>Get List Items</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Area1</strong>: Version 7.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get Recent Indicators</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>ExabeamAdvancedAnalytics</strong>: Version 8.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Add Comments To Entity</strong></p></li>
<li><p><strong>Create Watchlist</strong></p></li>
<li><p><strong>List Watchlist Items</strong></p></li>
<li><p><strong>List Watchlists</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Azure Monitor</strong>: Version 2.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Search Logs</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Rapid7 InsightIDR</strong>: Version 10.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>List Investigations</strong></p></li>
<li><p><strong>List Saved Queries</strong></p></li>
<li><p><strong>Run Saved Query</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Amazon Macie</strong>: Version 8.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Create Custom Data Identifier</strong></p></li>
<li><p><strong>List Findings</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>AWS IAM Access Analyzer</strong>: Version 8.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Scan Resources</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>ProofPoint TAP</strong>: Version 13.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>DecodeURL</strong></p></li>
<li><p><strong>Get Threat Forensics</strong></p></li>
<li><p><strong>GetCampaign</strong></p></li>
<li><p><strong>List Campaigns</strong></p></li>
<li><p><strong>Search Events</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Splunk</strong>: Version 62.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Execute Entity Query</strong></p></li>
<li><p><strong>SplunkQuery</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>LogPoint</strong>: Version 18.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Execute Entity Query</strong></p></li>
<li><p><strong>Execute Query</strong></p></li>
<li><p><strong>List Repos</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>BitSight</strong>: Version 10.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>List Company Highlights</strong></p></li>
<li><p><strong>List Company Vulnerabilities</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>WMI</strong>: Version 12.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>ListServices</strong></p></li>
<li><p><strong>ListUsers</strong></p></li>
<li><p><strong>RunQuery</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>AWS Identity and Access Management (IAM)</strong>: Version .0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Create a Group</strong></p></li>
<li><p><strong>Create a Policy</strong></p></li>
<li><p><strong>Create a User</strong></p></li>
<li><p><strong>List Groups</strong></p></li>
<li><p><strong>List Policies</strong></p></li>
<li><p><strong>List Users</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Fortinet FortiSIEM</strong>: Version 8.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Execute Custom Query</strong></p></li>
<li><p><strong>Execute Simple Query</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Humio</strong>: Version 7.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Execute Custom Search</strong></p></li>
<li><p><strong>Execute Simple Search</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>AlgoSec</strong>: Version 5.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>List Templates</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>AWS WAF</strong>: Version 9.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Create IP Set</strong></p></li>
<li><p><strong>Create Regex Pattern Set</strong></p></li>
<li><p><strong>Create Rule Group</strong></p></li>
<li><p><strong>Create Web ACL</strong></p></li>
<li><p><strong>List IP Sets</strong></p></li>
<li><p><strong>List Regex Pattern Sets</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>CA Service Desk Manager</strong>: Version 24.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Search Tickets</strong></p></li>
<li><p><strong>Sync Ticket History</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Freshworks Freshservice</strong>: Version 16.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Add Ticket Time Entry</strong></p></li>
<li><p><strong>Add a Ticket Note</strong></p></li>
<li><p><strong>Add a Ticket Reply</strong></p></li>
<li><p><strong>Create Requester</strong></p></li>
<li><p><strong>Create Ticket</strong></p></li>
<li><p><strong>List Agents</strong></p></li>
<li><p><strong>List Requesters</strong></p></li>
<li><p><strong>List Ticket Conversations</strong></p></li>
<li><p><strong>List Ticket Time Entries</strong></p></li>
<li><p><strong>List Tickets</strong></p></li>
<li><p><strong>Update Requester</strong></p></li>
<li><p><strong>Update Ticket</strong></p></li>
<li><p><strong>Update Ticket Time Entry</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>BMC Helix RemedyForce</strong>: Version 15.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Execute Custom Query</strong></p></li>
<li><p><strong>Execute Simple Query</strong></p></li>
<li><p><strong>Get Record Details</strong></p></li>
<li><p><strong>List Record Types</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>AWS S3</strong>: Version 6.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Download File From Bucket</strong></p></li>
<li><p><strong>Get Bucket Policy</strong></p></li>
<li><p><strong>List Bucket Objects</strong></p></li>
<li><p><strong>List Buckets</strong></p></li>
<li><p><strong>Upload File To Bucket</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Cybereason</strong>: Version 22.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Execute Custom Investigation Search</strong></p></li>
<li><p><strong>Execute Simple Investigation Search</strong></p></li>
<li><p><strong>List Malop Affected Machines</strong></p></li>
<li><p><strong>List Malop Remediations</strong></p></li>
<li><p><strong>List Processes</strong></p></li>
<li><p><strong>List files</strong></p></li>
<li><p><strong>Remediate Malop</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>SCCM</strong>: Version 19.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Run WQL Query</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Netskope</strong>: Version 15.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>List Alerts</strong></p></li>
<li><p><strong>List Clients</strong></p></li>
<li><p><strong>List Events</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Qradar</strong>: Version .0</p>
<ul>
<li><p>Optimized the caching fetched offenses logic in the following connectors:</p>
<ul>
<li><p><strong>Qradar Correlation Events Connector V2</strong></p></li>
<li><p><strong>Qradar Offenses Connector</strong></p></li>
</ul></li>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Rule MITRE Coverage</strong></p></li>
<li><p><strong>List Reference Maps</strong></p></li>
<li><p><strong>List Reference Maps of Sets</strong></p></li>
<li><p><strong>List Reference Sets</strong></p></li>
<li><p><strong>List Reference Tables</strong></p></li>
<li><p><strong>Lookup for a Key in Reference Map</strong></p></li>
<li><p><strong>Lookup for a Key in Reference Map of Sets</strong></p></li>
<li><p><strong>Lookup for a Value in Reference Map</strong></p></li>
<li><p><strong>Lookup for a Value in Reference Map of Sets</strong></p></li>
<li><p><strong>Lookup for a Value in Reference Set</strong></p></li>
<li><p><strong>Lookup for a Value in Reference Tables</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Cloud Compute</strong>: Version 14.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Add Labels To Instance</strong></p></li>
<li><p><strong>Get Instance IAM Policy</strong></p></li>
<li><p><strong>List Instances</strong></p></li>
<li><p><strong>Remove External IP Addresses</strong></p></li>
<li><p><strong>Set Instance IAM Policy</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Cylance</strong>: Version 17.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Global List</strong></p></li>
<li><p><strong>Get Threats</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>EmailV2</strong>: Version 38.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Search Email</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>McAfee EPO</strong>: Version 35.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Execute Custom Query</strong></p></li>
<li><p><strong>Execute Entity Query</strong></p></li>
<li><p><strong>Execute Query By ID</strong></p></li>
<li><p><strong>List Queries</strong></p></li>
<li><p><strong>List Tasks</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>ArcSight Logger</strong>: Version 10.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Send Query</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>SonicWall-Beta</strong>: Version 7.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>List Address Groups</strong></p></li>
<li><p><strong>List URI Groups</strong></p></li>
<li><p><strong>List URI Lists</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>VSphere</strong>: Version 9.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>List Vms</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>SiemplifyUtilities</strong>: Version 26.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Export Entities as OpenIOC File</strong></p></li>
<li><p><strong>Extract Top From JSON</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Office 365 CloudApp Security</strong>: Version 23.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Enrich Entities</strong></p></li>
<li><p><strong>List Files</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Salesforce</strong>: Version 15.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>List Cases</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>AWS Elastic Compute Cloud (EC2)</strong>: Version 8.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Start Instance</strong></p></li>
<li><p><strong>Stop Instance</strong></p></li>
<li><p><strong>Terminate Instance</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>McAfee Mvision ePO V2</strong>: Version 6.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>List Devices</strong></p></li>
<li><p><strong>List Tags</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Anomali ThreatStream</strong>: Version 12.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Submit Observables</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Automox</strong>: Version 6.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>List Policies</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Graph Security</strong>: Version 24.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>List Alerts</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Qualys VM</strong>: Version 22.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Download Vm Scan Results</strong></p></li>
<li><p><strong>Launch VM Scan And Fetch Results</strong></p></li>
<li><p><strong>List Groups</strong></p></li>
<li><p><strong>List Reports</strong></p></li>
<li><p><strong>List Scans</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Cloud Logging</strong>: Version 4.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Execute Query</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Cisco ISE</strong>: Version 14.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>List Endpoint Identity Group</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>SentinelOneV2</strong>: Version 45.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Create Path Exclusion Record</strong></p></li>
<li><p><strong>Get Blacklist</strong></p></li>
<li><p><strong>Get Deep Visibility Query Result</strong></p></li>
<li><p><strong>Get Site Agents</strong></p></li>
<li><p><strong>Get Threats</strong></p></li>
<li><p><strong>Initiate Deep Visibility Query</strong></p></li>
<li><p><strong>List Sites</strong></p></li>
<li><p><strong>Mark as Threat</strong></p></li>
<li><p><strong>Mitigate Threat</strong></p></li>
<li><p><strong>Resolve Threat</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Palo Alto Panorama</strong>: Version 33.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Correlated Traffic Between IPs</strong></p></li>
<li><p><strong>Search logs</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Cisco AMP</strong>: Version 20.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for the predefined widget of the following
action:</p>
<ul>
<li><strong>Get File List Items</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Slack</strong>: Version 27.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Get Channel Or User Conversation History</strong></p></li>
<li><p><strong>List Channels</strong></p></li>
<li><p><strong>List Users</strong></p></li>
<li><p><strong>Send Interactive Message</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>LogRhythm</strong>: Version 20.0</p>
<ul>
<li><p>Introduced Light Theme compatibility for predefined widgets of the following
actions:</p>
<ul>
<li><p><strong>Add Alarm To Case</strong></p></li>
<li><p><strong>Attach File To Case</strong></p></li>
<li><p><strong>Get Alarm Details</strong></p></li>
<li><p><strong>List Case Evidence</strong></p></li>
</ul></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>March 12, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-marketplace-release-notes#March_12_2026</id>
    <updated>2026-03-12T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/marketplace-integrations/release-notes#March_12_2026"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p><strong>Microsoft Azure Sentinel</strong>: Version 59.0</p>
<ul>
<li><p>The following new job has been added:</p>
<ul>
<li><strong>Sync Incidents V2</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Azure Sentinel</strong>: Version 59.0</p>
<ul>
<li><p>Deprecated the following job:</p>
<ul>
<li><strong>Sync Incidents V2</strong></li>
</ul>
<aside class="note"><strong>Note:</strong><span> Use the Sync Incidents V2 job for syncing.</span></aside></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>March 11, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-marketplace-release-notes#March_11_2026</id>
    <updated>2026-03-11T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/marketplace-integrations/release-notes#March_11_2026"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<p><strong>CrowdStrike Falcon</strong>: Version 72.0</p>
<ul>
<li><p>Updated the handling of <code>Days To Expire</code> in the following action:</p>
<ul>
<li><strong>Upload IOCs</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Case Federation</strong>: Version 7.0</p>
<ul>
<li><strong>Integration</strong>: Updated to support self-service configuration.</li>
</ul>
<h3>Change</h3>
<p><strong>ProofPoint TAP</strong>: Version 12.0</p>
<ul>
<li><p>Updated input handling in the following action:</p>
<ul>
<li><strong>DecodeURL</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Teams</strong>: Version 32.0</p>
<ul>
<li><p>Updated reply handling in the following action:</p>
<ul>
<li><strong>Wait for Reply</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p>Introduced Light Theme compatibility for predefined widgets in the following
integrations:</p>
<ul>
<li><p><strong>CrowdStrike Falcon</strong>: Version 72.0</p></li>
<li><p><strong>Google Chronicle</strong>: Version 79.0</p></li>
<li><p><strong>Google Cloud API</strong>: Version 8.0</p></li>
<li><p><strong>Google Cloud Asset Inventory</strong>: Version 13.0</p></li>
<li><p><strong>Google Security Command Center</strong>: Version 16.0</p></li>
<li><p><strong>Google Threat Intelligence</strong>: Version 10.0</p></li>
<li><p><strong>HTTP v2</strong>: Version 13.0</p></li>
<li><p><strong>MITRE ATT&amp;CK</strong>: Version 17.0</p></li>
<li><p><strong>ScreenshotMachine</strong>: Version 14.0</p></li>
<li><p><strong>Siemplify</strong>: Version 104.0</p></li>
<li><p><strong>UrlScan.io</strong>: Version 28.0</p></li>
<li><p><strong>Vertex AI</strong>: Version 5.0</p></li>
<li><p><strong>VirusTotalV3</strong>: Version 38.0</p></li>
<li><p><strong>Vmware Carbon Black Cloud</strong>: Version 37.0</p></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>March 03, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-marketplace-release-notes#March_03_2026</id>
    <updated>2026-03-03T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/marketplace-integrations/release-notes#March_03_2026"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p><strong>Siemplify</strong>: Version 103.0</p>
<ul>
<li><p>The following new job has been added:</p>
<ul>
<li><strong>Response Integration &amp; Connector Upgrade</strong></li>
</ul></li>
</ul>
<h3>Feature</h3>
<p><strong>Akamai</strong>: Version 2.0</p>
<ul>
<li><p>The following new action has been added:</p>
<ul>
<li><strong>Activate Client List</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Splunk</strong>: Version 61.0</p>
<ul>
<li><p>Updated input handling in the following action:</p>
<ul>
<li><strong>Update Notable Events</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>CrowdStrike Falcon</strong>: Version 71.0</p>
<ul>
<li><p>Added the ability to define an expiration date for IOCs to the following
action:</p>
<ul>
<li><strong>Upload IOCs</strong></li>
</ul></li>
<li><p>Added support for hidden hosts in the following action:</p>
<ul>
<li><strong>Get Host Information</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Security Command Center</strong>: Version 15.0</p>
<ul>
<li><p>Updated the processing of mute states in the following action:</p>
<ul>
<li><strong>List Asset Vulnerabilities</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>AWS GuardDuty</strong>: Version 9.0</p>
<ul>
<li><p>Updated severity handling in the following connector:</p>
<ul>
<li><strong>AWS GuardDuty - Findings Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Graph Mail Delegated</strong>: Version 13.0</p>
<ul>
<li><p>Updated folder handling in the following actions:</p>
<ul>
<li><p><strong>Forward Email</strong></p></li>
<li><p><strong>Save Email To Case</strong></p></li>
<li><p><strong>Send Email</strong></p></li>
<li><p><strong>Send Email HTML</strong></p></li>
<li><p><strong>Send Thread Reply</strong></p></li>
<li><p><strong>Send Vote Email</strong></p></li>
<li><p><strong>Wait For Email From User</strong></p></li>
<li><p><strong>Wait For Vote Email Results</strong></p></li>
</ul></li>
<li><p>Updated folder handling in the following connector:</p>
<ul>
<li><strong>Microsoft Graph Mail Delegated Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Chronicle</strong>: Version 78.0</p>
<ul>
<li><p>Updated raw log data processing in the following actions:</p>
<ul>
<li><p><strong>Get Detection Details</strong></p></li>
<li><p><strong>Execute UDM Query</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Graph Mail</strong>: Version 36.0</p>
<ul>
<li><p>Updated folder handling in the following actions:</p>
<ul>
<li><p><strong>Forward Email</strong></p></li>
<li><p><strong>Save Email To Case</strong></p></li>
<li><p><strong>Send Email</strong></p></li>
<li><p><strong>Send Email HTML</strong></p></li>
<li><p><strong>Send Thread Reply</strong></p></li>
<li><p><strong>Send Vote Email</strong></p></li>
<li><p><strong>Wait For Email From User</strong></p></li>
<li><p><strong>Wait For Vote Email Results</strong></p></li>
</ul></li>
<li><p>Updated folder handling in the following connector:</p>
<ul>
<li><strong>Microsoft Graph Mail Connector</strong></li>
</ul></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>February 25, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-marketplace-release-notes#February_25_2026</id>
    <updated>2026-02-25T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/marketplace-integrations/release-notes#February_25_2026"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p><strong>Google Workspace</strong>: Version 23.0</p>
<ul>
<li><p>The following new action has been added:</p>
<ul>
<li><strong>Remove Extension</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Chronicle</strong>: Version 77.0</p>
<ul>
<li><strong>Integration</strong>: Updated the error handling for Workload Identity
authentication.</li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft 365 Defender</strong>: Version 23.0</p>
<ul>
<li><p>Added support for Graph API to the following actions:</p>
<ul>
<li><p><strong>Execute Query</strong></p></li>
<li><p><strong>Execute Custom Query</strong></p></li>
<li><p><strong>Execute Entity Query</strong></p></li>
</ul></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>February 18, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-marketplace-release-notes#February_18_2026</id>
    <updated>2026-02-18T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/marketplace-integrations/release-notes#February_18_2026"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p>New <strong>Proofpoint Threat Protection</strong> integration</p>
<h3>Change</h3>
<p><strong>Cofense Triage</strong>: Version 17.0</p>
<ul>
<li><p>Optimized the report processing in the following connector:</p>
<ul>
<li><strong>Cofense Triage - Reports Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Qualys VM</strong>: Version 21.0</p>
<ul>
<li><strong>Integration</strong>: Added the ability to configure the <code>X-Requested-With</code> header.</li>
</ul>
<h3>Change</h3>
<p><strong>QRadar</strong>: Version 63.0</p>
<ul>
<li><p>Updated the logic for offense processing in the following connectors:</p>
<ul>
<li><p><strong>Qradar Correlation Events Connector V2</strong></p></li>
<li><p><strong>Qradar Offenses Connector</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Palo Alto Cortex XDR</strong>: Version 23.0</p>
<ul>
<li><p>Added the ability to provide agents using input parameters in the following
actions:</p>
<ul>
<li><p><strong>Scan Endpoint</strong></p></li>
<li><p><strong>Isolate Endpoint</strong></p></li>
<li><p><strong>Unisolate Endpoint</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Chronicle</strong>: Version 76.0</p>
<ul>
<li><p>Restored the previous JSON result structure for empty result sets in the
following action:</p>
<ul>
<li><strong>Execute UDM Query</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Exchange</strong>: Version 119.0</p>
<ul>
<li><p>Updated the handling of S/MIME emails sent on MacOS in the following
connectors:</p>
<ul>
<li><p><strong>Exchange - Mail Connector v2 with OAuth Authentication</strong></p></li>
<li><p><strong>Exchange - Mail Connector v2</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>CrowdStrike Falcon</strong>: Version 70.0</p>
<ul>
<li><p>Deprecated the following actions:</p>
<ul>
<li><p><strong>Add Incident Comment</strong></p></li>
<li><p><strong>Update Incident</strong></p></li>
<li><p><strong>Add Comment to Detection</strong></p></li>
<li><p><strong>Close Detection</strong></p></li>
<li><p><strong>Update Detection</strong></p></li>
</ul></li>
<li><p>Deprecated the following connectors:</p>
<ul>
<li><p><strong>CrowdStrike - Detections Connector</strong></p></li>
<li><p><strong>Crowdstrike - Incidents Connector</strong></p></li>
</ul></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>February 11, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-marketplace-release-notes#February_11_2026</id>
    <updated>2026-02-11T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/marketplace-integrations/release-notes#February_11_2026"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p><strong>CiscoUmbrella</strong>: Version 15.0</p>
<ul>
<li><p>The following new actions have been added:</p>
<ul>
<li><p><strong>Is Domain In Cisco Popularity List</strong></p></li>
<li><p><strong>List Top Domains</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Tenable.io</strong>: Version 13.0</p>
<ul>
<li><p>Optimized the asset processing of the following connector:</p>
<ul>
<li><strong>TenableIO - Vulnerabilities Connector</strong></li>
</ul></li>
<li><p>Updated the entity processing logic of the following actions:</p>
<ul>
<li><p><strong>Enrich Entities</strong></p></li>
<li><p><strong>List Endpoint Vulnerabilities</strong></p></li>
<li><p><strong>Scan Endpoints</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Threat Intelligence</strong>: Version 9.0</p>
<ul>
<li><p>Added the ability to define the data freshness threshold for available hashes
to the following action:</p>
<ul>
<li><strong>Submit File</strong></li>
</ul></li>
<li><p>Added the ability to filter using monitor names to the following connector:</p>
<ul>
<li><strong>Google Threat Intelligence - DTM Alerts Connector</strong></li>
</ul></li>
<li><p><strong>Integration</strong>: Updated the connectivity test method to avoid API quota
consumption.</p></li>
</ul>
<h3>Change</h3>
<p><strong>Palo Alto Cortex XDR</strong>: Version 22.0</p>
<ul>
<li><p>Updated the event processing and dynamic list handling of the following
connector:</p>
<ul>
<li><strong>Palo Alto Cortex XDR Connector</strong></li>
</ul></li>
<li><p>Added the ability to ignore certain types of artifacts to the following
connector:</p>
<ul>
<li><strong>Palo Alto Cortex XDR Connector</strong></li>
</ul></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>February 04, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-marketplace-release-notes#February_04_2026</id>
    <updated>2026-02-04T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/marketplace-integrations/release-notes#February_04_2026"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<p><strong>Azure Security Center</strong>: Version 13.0</p>
<ul>
<li><p>Updated the configuration (<code>Connector.def</code>) of the following connector:</p>
<ul>
<li><strong>Azure Security Center - Security Alerts Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Chronicle</strong>: Version 75.0</p>
<ul>
<li><p>Optimized performance for large data tables in the following actions:</p>
<ul>
<li><p><strong>Is Value In Data Table</strong></p></li>
<li><p><strong>Remove Rows From Data Table</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Siemplify</strong>: Version 102.0</p>
<ul>
<li><p>Refactored the following actions:</p>
<ul>
<li><p><strong>Get Case Details</strong></p></li>
<li><p><strong>Wait For Custom Fields</strong></p></li>
<li><p><strong>Set Custom Fields</strong></p></li>
<li><p><strong>Get Similar Cases</strong></p></li>
<li><p><strong>Get Custom Field Values</strong></p></li>
<li><p><strong>Export Case</strong></p></li>
</ul></li>
<li><p>Updated error handling in the following action:</p>
<ul>
<li><strong>Assign Case</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Siemplify ThreatFuse</strong>: Version 16.0</p>
<ul>
<li><p>Updated the configuration (<code>Connector.def</code>) of the following connector::</p>
<ul>
<li><strong>Siemplify ThreatFuse - Observables Connector</strong></li>
</ul></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>January 28, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-marketplace-release-notes#January_28_2026</id>
    <updated>2026-01-28T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/marketplace-integrations/release-notes#January_28_2026"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p><strong>Google Threat Intelligence</strong>: Version 8.0</p>
<ul>
<li><p>The following new actions have been added:</p>
<ul>
<li><p><strong>Add ASM Issue Note</strong></p></li>
<li><p><strong>Add Tag To DTM Alert</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Azure Active Directory</strong>: Version 22.0</p>
<ul>
<li><p>Added the ability to fetch MFA information to the following actions:</p>
<ul>
<li><p><strong>Enrich User</strong></p></li>
<li><p><strong>Get Manager Contact Details</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Jira</strong>: Version 52.0</p>
<ul>
<li><p>Optimized ticket processing workflows in the following job:</p>
<ul>
<li><strong>Sync Closure Job</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Proofpoint Cloud Threat Response</strong>: Version 2.0</p>
<ul>
<li><strong>Integration</strong>: Updated dependencies.</li>
</ul>
<h3>Change</h3>
<p><strong>Salesforce</strong>: Version 14.0</p>
<ul>
<li><strong>Integration</strong>: Updated the Salesforce SDK to the latest version</li>
</ul>
<h3>Change</h3>
<p><strong>Siemplify</strong>: Version 101.0</p>
<ul>
<li><p>Added support to set custom fields upon alert closure to the following action:</p>
<ul>
<li><strong>Close Alert</strong></li>
</ul></li>
<li><p>Added support to set custom fields upon case closure to the following action:</p>
<ul>
<li><strong>Close Case</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Threat Intelligence</strong>: Version 8.0</p>
<ul>
<li><p>Added the ability to automatically set the <code>is_suspicious</code> flag on entities
based on specific GTI score and Engine count thresholds in the following
action:</p>
<ul>
<li><strong>Enrich Entities</strong></li>
</ul></li>
<li><p>Added the ability to flag entities as <code>is_risky</code> within the JSON output when
GTI scores or Engine counts meet specified criteria to the following action:</p>
<ul>
<li><strong>Submit File</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Chronicle</strong>: Version 74.0</p>
<ul>
<li><p>Reverted the JSON result structure for aggregated queries in the following
action:</p>
<ul>
<li><strong>Execute UDM Query</strong></li>
</ul></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>January 21, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-marketplace-release-notes#January_21_2026</id>
    <updated>2026-01-21T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/marketplace-integrations/release-notes#January_21_2026"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p><strong>Okta</strong>: Version 13.0</p>
<ul>
<li><p>The following new action has been added:</p>
<ul>
<li><strong>Clear Okta User Session</strong></li>
</ul></li>
</ul>
<h3>Feature</h3>
<p>New <strong>Azure API</strong> integration</p>
<h3>Change</h3>
<p><strong>Netskope</strong>: Version 14.0</p>
<ul>
<li><p>Refactored the following action:</p>
<ul>
<li><strong>Ping</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>HTTP v2</strong>: Version 12.0</p>
<ul>
<li><p>Updated <code>Expected Response Values</code> description in the following action:</p>
<ul>
<li><strong>Execute HTTP Request</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft 365 Defender</strong>: Version 22.0</p>
<ul>
<li><p>Updated the tracking logic for alerts in the following connector:</p>
<ul>
<li><strong>Microsoft 365 Defender - Incidents Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>QRadar</strong>: Version 62.0</p>
<ul>
<li><p>Updated the event processing logic of the following connector:</p>
<ul>
<li><strong>QRadar Correlations Connector V2</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Chronicle</strong>: Version 73.0</p>
<ul>
<li><p>Updated the processing of queries in the following action:</p>
<ul>
<li><strong>Execute UDM Query</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Cloud API</strong>: Version 7.0</p>
<ul>
<li><p>Updated <code>Expected Response Values</code> description in the following action:</p>
<ul>
<li><strong>Execute HTTP Request</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Azure Active Directory</strong>: Version 21.0</p>
<ul>
<li><p>Updated the JSON result example of the following action:</p>
<ul>
<li><strong>List Members in The Group</strong></li>
</ul></li>
<li><p>Added more metadata to the JSON result example of the following action:</p>
<ul>
<li><strong>List Groups</strong></li>
</ul></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>January 14, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-marketplace-release-notes#January_14_2026</id>
    <updated>2026-01-14T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/marketplace-integrations/release-notes#January_14_2026"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<p><strong>Siemplify</strong>: Version 100.0</p>
<ul>
<li><p>Updated the following action to include the JSON result in the action output:</p>
<ul>
<li><strong>Get Custom Field Values</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Graph Mail</strong>: Version 35.0</p>
<ul>
<li><p>Improved the "mark emails as read" functionality in the following connector:</p>
<ul>
<li><strong>Microsoft Graph Mail Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Graph Mail Delegated</strong>: Version 12.0</p>
<ul>
<li><p>Improved the "mark emails as read" functionality in the following connector:</p>
<ul>
<li><strong>Microsoft Graph Mail Delegated Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Okta</strong>: Version 12.0</p>
<ul>
<li><p>Updated the pagination processing mechanismthe in following action:</p>
<ul>
<li><strong>List Users</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Slack</strong>: Version 26.0</p>
<ul>
<li><p>Updated the Base URL construction logic for the following action:</p>
<ul>
<li><strong>Build Block</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Azure Active Directory</strong>: Version 20.0</p>
<ul>
<li><p>Updated the action to include the email ID in the action output and expanded
capabilities to return all metadata fields in the following action:</p>
<ul>
<li><strong>Get Manager Contact Details</strong></li>
</ul></li>
<li><p><strong>Integration</strong>: Updated the code to handle special characters in identifiers
by implementing URL encoding and OData escaping.</p></li>
</ul>
]]>
    </content>
  </entry>

</feed>
