Microsoft Sentinel Incidents
Automatic deploy
Supported by Filigran
Detection & Response Enablement
Overview
Imports security incidents, alerts, and observables from Microsoft Sentinel SIEM into OpenCTI as STIX Incidents with associated IOCs.
The Microsoft Sentinel Incidents connector imports security incidents, alerts, indicators, and observables from Microsoft Sentinel SIEM into OpenCTI. It creates structured STIX Incidents linked to associated entities and IOCs, enabling analysts to correlate SIEM detections with threat intelligence data.