We've introduced correlation signals designed to detect bursts of Defender Antivirus activity within short timeframes. These detections trigger when the number of antivirus signals exceed defined thresholds within a specified time window. Now, multiple weaker, lower-fidelity signals will be combined into a single, powerful higher-fidelity signal and reported as part of a single report.