Skip to content

Release Notes - New Features & Bug Fixes

πŸ“§ Email Security

✨ New Provider

  • Add the Microsoft 365 Management Activity Email Security Provider, reading Exchange mail-send audit events from the Office 365 Management Activity API and emitting OCSF Email Activity (class 4009). Unlike the existing Exchange provider, this one carries file attachment metadata, separated To/Cc/Bcc recipients, sender context, sensitivity labels, and delivery status. Supported on Global, GCC, GCC High, and DoD clouds, with either a client secret or an X.509 client-assertion certificate as the credential.

  • Because the Management Activity API is a subscription-based firehose, provider-side filtering is limited to the blob publication time (metadata.logged_time), not the time the message was sent, and each message produces two audit records β€” a Send record carrying the message and its attachments, and a MipLabel record carrying separated recipients and structured attachment metadata. The two are returned as they arrive rather than merged.

✨ Enhancement

  • Add email.bcc and email.actor to the Synqly OCSF 1.8.0 extension. bcc is typed as an array of email addresses, matching cc and to.

  • Publish the Microsoft 365 Management Activity provider configuration guide, covering the Entra app registration, the two required Office 365 Management APIs application permissions, both credential types, and the Connect field table.


🌐 Network Security

✨ Enhancement

  • Add AWS Route 53 Resolver query log support to the Network Security Connector, through two new operations: GET /v1/network-security/dns/log-configurations discovers the query-log configurations an integration can read, returned as OCSF Cloud Resources Inventory Info (class 5023), and GET /v1/network-security/dns/log-events returns normalized DNS events from those configurations as OCSF DNS Activity (class 4003). Both CloudWatch Logs and S3 destinations are supported, with time-range filtering and pagination. To scope an integration to specific configurations, set dns_log_configuration_ids the same way traffic_log_configuration_ids already works.

πŸ›‘οΈ EDR (Endpoint Detection & Response)

πŸ› Bug Fix

  • Fix Microsoft Defender query_edr_events skipping and repeating events across page boundaries when events share a timestamp. Defender routinely emits several events at the same millisecond, and paging on time alone left their relative order undefined, so a page boundary landing inside such a group lost some events and duplicated others. The event identifier is now applied as a secondary sort whenever time is the requested ordering.

πŸ“¦ Endpoint Management

✨ Enhancement

  • Add the standard meta query parameter to the four device action endpoints β€” update, lock, restart, and wipe β€” so meta functions work there as they do on every other engine endpoint. The request body schema, paths, and methods are unchanged, and callers that omit meta see no difference in behavior. Go SDK consumers should note one rename: the request body type DeviceActionRequest is now DeviceActionRequestBody. Only the Go type name changes; no request or response payload is affected.

πŸ“¦ Asset Management

✨ Enhancement

  • Add GET /v1/assets/devices/{deviceUid}/software (query_device_software) for per-device software inventory, implemented for Ivanti Neurons. Other Asset Management providers declare it unsupported and keep tenant-wide query_software as-is.

πŸ› Bug Fix

  • Stop advertising tenant-wide Query Software Inventory on Ivanti Neurons, which has no tenant-wide software list β€” software exists only on device records, so an unscoped GET /v1/assets/software could never succeed. Ivanti query_software is now declared unsupported and returns 501 when called without a device scope, instead of 400. Existing callers filtering on device.uid[eq] or device.uid[in] keep working unchanged.

πŸ” Vulnerability Management

✨ Enhancement

  • Add filters to the Pentera provider for parity with the other vulnerability providers: finding.last_seen_time and finding.last_seen_time_dt (gte, gt, lte, lt) on Query Findings, and device.uid (eq, in) on Query Assets. Pentera's API accepts only a task-run ID, so these are applied by Synqly, and last-seen is aliased to the vulnerability creation time Pentera exposes.

  • Improve the Horizon3 NodeZero field mapping. CISA KEV status is now forwarded to vulnerabilities[].xattributes, and is_exploit_available is set only when a finding is actually in the KEV catalog rather than defaulting to false on nearly every finding. NodeZero proof data is now shaped into finding.supporting_data β€” caption, command output, source URL, module, and collection time β€” while the raw record remains at vulnerabilities[].xattributes.proofs. finding.src_url is now set from the weakness portal URL on query_findings, matching the other Horizon3 finding path, and finding.xattributes is reachable as a typed field in the SDKs for OCSF 1.3.0, 1.4.0, and 1.6.0 instead of being dropped.

πŸ› Bug Fix

  • Fix Axonius silently truncating Query Findings and Query Assets walks. The next-page offset skipped one row per page and drifted ahead of the true row position, and the end-of-results check used Axonius's unfiltered page counts, which run ahead of a filtered result set and could end a walk early or hand back a cursor for a page that was already short. Paging now advances contiguously with no skipped or repeated rows, and a short page ends the walk.

  • Fix Microsoft Defender EASM query_findings returning no findings at all for workspaces containing page assets. A page asset's identifier embeds a full URL, and percent-escaping it into the request path left an escaped slash the Azure gateway rejects with a 400 before EASM saw the request β€” and because the asset walk stopped on the first error, one unencodable asset zeroed out findings for the entire workspace. Asset identifiers are now sent as base64url, and a 400 or 404 on a single asset is logged and skipped rather than ending the walk, while auth, throttling, and upstream faults still surface.

  • Stop advertising sort fields the connector cannot honor. The Vulnerabilities Connector rejects every order clause before the provider runs, so Microsoft Defender query_assets (device.last_seen_time, device.hostname, device.os.name) and Tenable.sc query_findings (severity, finding.first_seen_time, finding.last_seen_time) advertised orderings that returned a 400 to any caller that followed capabilities. Those orderings have been removed from the published capabilities; query behavior is unchanged.


πŸ” Application Security

πŸ› Bug Fix

  • Fix HCL AppScan on Cloud Application Findings and Findings queries failing to transform when a finding carries a CVE ID but a null or empty CVSS score. The mapping errored while resolving cvss.base_score instead of omitting it.

πŸ‘€ Identity Management

✨ Enhancement

  • Add query_risk_events to the PingOne Identity Provider, backed by PingOne Protect. Risk evaluations are read from audit activities, giving an auditable history with pagination, time filtering, and include_raw_data, and are returned as OCSF Detection Finding (class 2004) with severity, user, source, and recommended action. query_risky_users is not supported on PingOne; the existing directory, user, group, and audit log operations are unaffected.

πŸ› Bug Fix

  • Fix Greenhouse Test Connection reporting a bad User ID as "Invalid URL" and blaming a field that does not exist. A typed 401 from the provider was being wrapped into an untyped 500 before classification, so an authentication failure was reported as a configuration error; the error chain is now inspected for the typed failure first. This classification fix applies to every provider that wraps transport errors this way.

  • Accept either a numeric Greenhouse user ID or a full Greenhouse user URL in the User ID field, which is now labeled and documented with examples and client-side validation in Connect. A pasted URL is reduced to the numeric ID automatically, and an empty value remains valid.


πŸ“Š SIEM & Sink

✨ Enhancement

  • Paginate Elasticsearch event queries over a Point-in-Time snapshot with search_after instead of a from offset. Events sharing a sort value β€” very common with @timestamp β€” could previously be returned twice or skipped between pages, and documents written mid-session shifted the offset window. The snapshot freezes the index for the whole pagination session and adds an automatic tiebreaker, so each event is returned exactly once in a stable order. Cursors issued before this release keep working, and an expired snapshot now returns a clear "restart pagination" error. Alert pagination, raw-body passthrough, and OpenSearch are unchanged.

  • Document how to update the Synqly Sentinel Solution and its data collection rule, based on troubleshooting with Microsoft support. The process is not as clean as we would like, but it is the best path currently available; we have asked Microsoft for a better workflow.


βš™οΈ Core

✨ Enhancement

  • Derive OCSF enrichment from the compiled OCSF schema rather than a hand-maintained table, on CrowdStrike, Microsoft, OpenSearch, and AWS to start. Events from those providers now carry a complete, version-correct observables[] array, enum sibling names (class_name, severity, status, and the rest), and a metadata.profiles set reflecting the profiles the event actually exercises. Enrichment is strictly additive: hand-authored observables are preserved, an explicit profile declaration is never overridden, and every other provider is unchanged.

  • Restore OCSF base object fields that the legacy Synqly extension was dropping from the typed SDKs. resource_details and agent replaced their base OCSF definitions instead of extending them, discarding every attribute the frozen legacy copy did not redeclare β€” agent.policies on all versions, resource_details.hostname and tags at 1.4.0, and twelve more fields at 1.6.0. These now merge with the base objects, so fields such as resource_details.tags β€” already written on the wire by the AWS and Palo Alto cloud inventory providers β€” are reachable as typed fields. The change is additive only.

πŸ› Bug Fix

  • Fix error responses being corrupted across unrelated requests. When a provider returned a shared package-level error value, the first request to reach it stamped its own integration context onto that shared value permanently, so later requests β€” on any integration, in any account β€” could receive the first request's integration ID, HTTP status, and problem type. The mutation was also unsynchronized, racing between concurrent requests. Errors are now copied before they are annotated.

  • Stop Pentera credentials reaching api/response metadata and error parameters. The Pentera login response and the session token every data response carries at meta.token were being recorded like any other provider call, so a caller requesting response metadata on a Pentera vulnerabilities call could receive a live credential. The login is now treated as a credential exchange and skipped by collection, and meta.token reads REDACTED. Separately, and for every provider, a failed credential exchange no longer reports its request or response body in error parameters or parse-error messages.

  • Refuse a private key pasted into a provider's certificate field, on both credential create and rotate. That field is stored unencrypted on the assumption that a certificate is public material. The audit trail obfuscator, which persists the request body of every credential write, also now matches certificate and private_key, so a certificate credential's private key no longer lands in the audit log verbatim.


πŸ“š SDK Releases

Latest Versions

  • Released Synqly SDK versions: 2.0.56, 2.0.57, 2.0.58, 2.0.59, 2.0.60, 2.0.61, 2.0.62, 2.0.63, 2.0.64, 2.0.65, 2.0.66

🚒 Synqly Embedded

Latest Release: v0.1.157

  • Service Image Tag: embedded-2026.09.18
  • Service Image Tag (NO FIPS): embedded-2026.09.18-no-fips
  • Release Date: September 18, 2026