Changelog
Synapse-Microsoft-Defender Changelog
NEXTVERS - 2025-MM-DD
Features and Enhancements
Updated
microsoft.defender.ti.articlesto set themedia:news:bodyproperty with the body text.
v2.0.0 - 2025-05-16
Automatic Migrations
Migrated all legacy
media:news:urlproperties created by Synapse-Microsoft-Defender to the new Microsoft Defender TI URL format.
Features and Enhancements
Updated the
media:news:urlproperty to use the new Microsoft Defender TI URL format.
v1.1.0 - 2025-03-07
Features and Enhancements
Updated
microsoft.defender.ti.pdnsto handle cases where the declared response types were not correct for A and AAAA records.Updated
microsoft.defender.ti.articles,microsoft.defender.ti.profiles,microsoft.defender.ti.ssl.search, andmicrosoft.defender.ti.whois.search, to populate theit:exec:query:synuserproperties.Added new endpoints section in command help to document the endpoints used by each command, accessible via the
--helpflag.
v1.0.0 - 2025-01-17
Automatic Migrations
Migrated all
inet:ssl:certcreated by Synapse-Microsoft-Defender toinet:tls:servercertnodes. The migratedinet:ssl:certnodes are removed by this migration if they don’t have any othermeta:source -(seen)>edges.Migrated all
proj:ticketnodes created by Synapse-Microsoft-Defender to use the:idproperty instead of the deprecated:ext:idproperty. These nodes are only migrated if they have the Synapse-Microsoft-Defendermeta:source -(seen)>edge.
Features and Enhancements
Added
--no-hostsoption to themicrosoft.defender.ti.ssl.searchcommand to retrieve/query hosts related to the returned SSL certificates.Updated Power-Up to make
inet:tls:servercertnodes instead of deprecatedinet:ssl:certnodes.Updated commands that accept
inet:ssl:certnodes as inputs to acceptinet:tls:servercertnodes instead.Updated Power-Up to use the
:idproperty instead of deprecated:ext:idproperty.Updated deprecated
$lib.list()usage to JSON style syntax.
v0.6.0 - 2024-12-12
NOTE: This release is a BETA preview and may be subject to change!
Features and Enhancements
Added
microsoft.defender.ti.profilescommand to retrieve/query threat actor and tool profiles from Microsoft Defender TI.
v0.5.0 - 2024-09-17
NOTE: This release is a BETA preview and may be subject to change!
Features and Enhancements
Add IPv4 support to
microsoft.defender.ti.whoisandmicrosoft.defender.ti.whois.history.
v0.4.0 - 2024-04-01
NOTE: This release is a BETA preview and may be subject to change!
Features and Enhancements
Add
microsoft.defender.ti.reputationcommand which allows users to enrich an FQDN with reputation data from Microsoft Defender TI.
v0.3.1 - 2024-03-13
NOTE: This release is a BETA preview and may be subject to change!
Bugfixes
Fix broken link in
microsoft.defender.ti.ssl.searchhelp.
v0.3.0 - 2024-03-06
NOTE: This release is a BETA preview and may be subject to change!
Features and Enhancements
Update
$lib.bytesusage with$lib.axonAPIs.
Bugfixes
Use alert/incident creation time for
:detectedproperty.Set
:createdand:updatedonproj:ticketnodes created from alerts and incidents.
v0.2.1 - 2024-02-20
NOTE: This release is a BETA preview and may be subject to change!
Features and Enhancements
Update deprecated
$lib.dict()usage to JSON style syntax.
v0.2.0 - 2024-02-06
NOTE: This release is a BETA preview and may be subject to change!
Features and Enhancements
Add a workaround to retry unexpected HTTP 400 errors from the Microsoft Defender TI backend.
Bugfixes
Clarify warning message for unsupported DNS record types.
v0.1.0 - 2024-01-05
NOTE: This release is a BETA preview and may be subject to change!
Features and Enhancements
Initial release of the
Synapse-Microsoft-DefenderPower-Up