When detections break silently, the evidence should be public.
Reproducible investigations into failures introduced by pipeline configuration, add-on behavior, and telemetry contracts. Each investigation identifies the tested versions, affected rules, and runs behind the result.
A 2025 update to the Splunk Add-on for AWS re-attributes 39 read-only CloudTrail events from the assumed role to the individual session - enough to fragment a role's reconnaissance below AWS Excessive Security Scanning's threshold and silence it.
An A/B validation of 38 Splunk ESCU AWS detections with the official CloudTrail pack in and out of the data ingestion pipeline, or what a cost-saving reduction quietly does to your detections.
AWS
CloudTrail
Cribl
Splunk
In the pipeline
Open investigations
Each one publishes only once its runtime evidence, affected scope, and exact versions clear review - so these are the questions, not the verdicts yet.
TM-2026-002recheck pending
O365 inbox-rule fields disappear before detection aggregation
The data contract between O365 inbox-rule events and the top-level fields the shipped detection groups by, measured against the current add-on.
A Cribl masking rule that redacts emails and IPs across the stream, and what it leaves behind for the identity fields O365 detections group and correlate on.
TM-2026-005in review
An allowlist of one: detections that watch only user_type=IAMUser
Shipped ESCU AWS detections that filter on user_type=IAMUser - and the assumed-role, SSO, federation, and root activity that never reaches them, on any add-on version.