β¨ New Provider
Add the Microsoft 365 Management Activity Email Security Provider, reading Exchange mail-send audit events from the Office 365 Management Activity API and emitting OCSF Email Activity (class
4009). Unlike the existing Exchange provider, this one carries file attachment metadata, separatedTo/Cc/Bccrecipients, sender context, sensitivity labels, and delivery status. Supported on Global, GCC, GCC High, and DoD clouds, with either a client secret or an X.509 client-assertion certificate as the credential.Because the Management Activity API is a subscription-based firehose, provider-side filtering is limited to the blob publication time (
metadata.logged_time), not the time the message was sent, and each message produces two audit records β aSendrecord carrying the message and its attachments, and aMipLabelrecord carrying separated recipients and structured attachment metadata. The two are returned as they arrive rather than merged.
β¨ Enhancement
Add
email.bccandemail.actorto the Synqly OCSF 1.8.0 extension.bccis typed as an array of email addresses, matchingccandto.Publish the Microsoft 365 Management Activity provider configuration guide, covering the Entra app registration, the two required Office 365 Management APIs application permissions, both credential types, and the Connect field table.
β¨ Enhancement
- Add AWS Route 53 Resolver query log support to the Network Security Connector, through two new operations:
GET /v1/network-security/dns/log-configurationsdiscovers the query-log configurations an integration can read, returned as OCSF Cloud Resources Inventory Info (class5023), andGET /v1/network-security/dns/log-eventsreturns normalized DNS events from those configurations as OCSF DNS Activity (class4003). Both CloudWatch Logs and S3 destinations are supported, with time-range filtering and pagination. To scope an integration to specific configurations, setdns_log_configuration_idsthe same waytraffic_log_configuration_idsalready works.
π Bug Fix
- Fix Microsoft Defender
query_edr_eventsskipping and repeating events across page boundaries when events share a timestamp. Defender routinely emits several events at the same millisecond, and paging on time alone left their relative order undefined, so a page boundary landing inside such a group lost some events and duplicated others. The event identifier is now applied as a secondary sort whenevertimeis the requested ordering.
β¨ Enhancement
- Add the standard
metaquery parameter to the four device action endpoints βupdate,lock,restart, andwipeβ so meta functions work there as they do on every other engine endpoint. The request body schema, paths, and methods are unchanged, and callers that omitmetasee no difference in behavior. Go SDK consumers should note one rename: the request body typeDeviceActionRequestis nowDeviceActionRequestBody. Only the Go type name changes; no request or response payload is affected.
β¨ Enhancement
- Add
GET /v1/assets/devices/{deviceUid}/software(query_device_software) for per-device software inventory, implemented for Ivanti Neurons. Other Asset Management providers declare it unsupported and keep tenant-widequery_softwareas-is.
π Bug Fix
- Stop advertising tenant-wide Query Software Inventory on Ivanti Neurons, which has no tenant-wide software list β software exists only on device records, so an unscoped
GET /v1/assets/softwarecould never succeed. Ivantiquery_softwareis now declared unsupported and returns501when called without a device scope, instead of400. Existing callers filtering ondevice.uid[eq]ordevice.uid[in]keep working unchanged.
β¨ Enhancement
Add filters to the Pentera provider for parity with the other vulnerability providers:
finding.last_seen_timeandfinding.last_seen_time_dt(gte,gt,lte,lt) on Query Findings, anddevice.uid(eq,in) on Query Assets. Pentera's API accepts only a task-run ID, so these are applied by Synqly, and last-seen is aliased to the vulnerability creation time Pentera exposes.Improve the Horizon3 NodeZero field mapping. CISA KEV status is now forwarded to
vulnerabilities[].xattributes, andis_exploit_availableis set only when a finding is actually in the KEV catalog rather than defaulting tofalseon nearly every finding. NodeZero proof data is now shaped intofinding.supporting_dataβ caption, command output, source URL, module, and collection time β while the raw record remains atvulnerabilities[].xattributes.proofs.finding.src_urlis now set from the weakness portal URL onquery_findings, matching the other Horizon3 finding path, andfinding.xattributesis reachable as a typed field in the SDKs for OCSF 1.3.0, 1.4.0, and 1.6.0 instead of being dropped.
π Bug Fix
Fix Axonius silently truncating Query Findings and Query Assets walks. The next-page offset skipped one row per page and drifted ahead of the true row position, and the end-of-results check used Axonius's unfiltered page counts, which run ahead of a filtered result set and could end a walk early or hand back a cursor for a page that was already short. Paging now advances contiguously with no skipped or repeated rows, and a short page ends the walk.
Fix Microsoft Defender EASM
query_findingsreturning no findings at all for workspaces containingpageassets. Apageasset's identifier embeds a full URL, and percent-escaping it into the request path left an escaped slash the Azure gateway rejects with a400before EASM saw the request β and because the asset walk stopped on the first error, one unencodable asset zeroed out findings for the entire workspace. Asset identifiers are now sent as base64url, and a400or404on a single asset is logged and skipped rather than ending the walk, while auth, throttling, and upstream faults still surface.Stop advertising sort fields the connector cannot honor. The Vulnerabilities Connector rejects every order clause before the provider runs, so Microsoft Defender
query_assets(device.last_seen_time,device.hostname,device.os.name) and Tenable.scquery_findings(severity,finding.first_seen_time,finding.last_seen_time) advertised orderings that returned a400to any caller that followed capabilities. Those orderings have been removed from the published capabilities; query behavior is unchanged.
π Bug Fix
- Fix HCL AppScan on Cloud Application Findings and Findings queries failing to transform when a finding carries a CVE ID but a null or empty CVSS score. The mapping errored while resolving
cvss.base_scoreinstead of omitting it.
β¨ Enhancement
- Add
query_risk_eventsto the PingOne Identity Provider, backed by PingOne Protect. Risk evaluations are read from audit activities, giving an auditable history with pagination, time filtering, andinclude_raw_data, and are returned as OCSF Detection Finding (class2004) with severity, user, source, and recommended action.query_risky_usersis not supported on PingOne; the existing directory, user, group, and audit log operations are unaffected.
π Bug Fix
Fix Greenhouse Test Connection reporting a bad User ID as "Invalid URL" and blaming a field that does not exist. A typed
401from the provider was being wrapped into an untyped500before classification, so an authentication failure was reported as a configuration error; the error chain is now inspected for the typed failure first. This classification fix applies to every provider that wraps transport errors this way.Accept either a numeric Greenhouse user ID or a full Greenhouse user URL in the User ID field, which is now labeled and documented with examples and client-side validation in Connect. A pasted URL is reduced to the numeric ID automatically, and an empty value remains valid.
β¨ Enhancement
Paginate Elasticsearch event queries over a Point-in-Time snapshot with
search_afterinstead of afromoffset. Events sharing a sort value β very common with@timestampβ could previously be returned twice or skipped between pages, and documents written mid-session shifted the offset window. The snapshot freezes the index for the whole pagination session and adds an automatic tiebreaker, so each event is returned exactly once in a stable order. Cursors issued before this release keep working, and an expired snapshot now returns a clear "restart pagination" error. Alert pagination, raw-body passthrough, and OpenSearch are unchanged.Document how to update the Synqly Sentinel Solution and its data collection rule, based on troubleshooting with Microsoft support. The process is not as clean as we would like, but it is the best path currently available; we have asked Microsoft for a better workflow.
β¨ Enhancement
Derive OCSF enrichment from the compiled OCSF schema rather than a hand-maintained table, on CrowdStrike, Microsoft, OpenSearch, and AWS to start. Events from those providers now carry a complete, version-correct
observables[]array, enum sibling names (class_name,severity,status, and the rest), and ametadata.profilesset reflecting the profiles the event actually exercises. Enrichment is strictly additive: hand-authored observables are preserved, an explicit profile declaration is never overridden, and every other provider is unchanged.Restore OCSF base object fields that the legacy Synqly extension was dropping from the typed SDKs.
resource_detailsandagentreplaced their base OCSF definitions instead of extending them, discarding every attribute the frozen legacy copy did not redeclare βagent.policieson all versions,resource_details.hostnameandtagsat 1.4.0, and twelve more fields at 1.6.0. These now merge with the base objects, so fields such asresource_details.tagsβ already written on the wire by the AWS and Palo Alto cloud inventory providers β are reachable as typed fields. The change is additive only.
π Bug Fix
Fix error responses being corrupted across unrelated requests. When a provider returned a shared package-level error value, the first request to reach it stamped its own integration context onto that shared value permanently, so later requests β on any integration, in any account β could receive the first request's integration ID, HTTP status, and problem type. The mutation was also unsynchronized, racing between concurrent requests. Errors are now copied before they are annotated.
Stop Pentera credentials reaching
api/responsemetadata and error parameters. The Pentera login response and the session token every data response carries atmeta.tokenwere being recorded like any other provider call, so a caller requesting response metadata on a Pentera vulnerabilities call could receive a live credential. The login is now treated as a credential exchange and skipped by collection, andmeta.tokenreadsREDACTED. Separately, and for every provider, a failed credential exchange no longer reports its request or response body in error parameters or parse-error messages.Refuse a private key pasted into a provider's certificate field, on both credential create and rotate. That field is stored unencrypted on the assumption that a certificate is public material. The audit trail obfuscator, which persists the request body of every credential write, also now matches
certificateandprivate_key, so a certificate credential's private key no longer lands in the audit log verbatim.
Latest Versions
- Released Synqly SDK versions:
2.0.56,2.0.57,2.0.58,2.0.59,2.0.60,2.0.61,2.0.62,2.0.63,2.0.64,2.0.65,2.0.66
Latest Release: v0.1.157
- Service Image Tag:
embedded-2026.09.18 - Service Image Tag (NO FIPS):
embedded-2026.09.18-no-fips - Release Date: September 18, 2026