← Platform Changes

Analytics rules — August 23, 2026

166 files changed, 475 insertions, 179 deletionsview the commit on the mirror.

Four universal authentication detectors added; 124 identity detectors gain the SaaS Threat Detection module

  • Four new Identity Analytics detectors cover a newly named event class, universal authentication: brute force, password spray, inactive-user authentication, and successful sign-in with suspicious features.
  • 124 detectors were reassigned, adding SaaS Threat Detection alongside Identity Threat Module — 103 identity detectors and 21 that also carry Email.
  • 36 cloud detectors gained a detector_tags grouping for the first time: Cloud Log Tampering Analytics, OCI Analytics, and SSM Remote Management Analytics.
  • One rule was renamed, one variation was withdrawn, and two deduplication periods were retuned. Nothing else changed.

Highlights

Changes

166 files listed, 7 written up and shaded below.

Group
Change