XTM Hub by Filigran
Microsoft Sentinel App logo

Microsoft Sentinel App

Detection & Response Enablement
A picture of RG9jdW1lbnQ6YjVlMDVlZjQtM2ZlMi00YmQ0LTk4NmQtN2QyMGJiZWRhODM1

Aperçu

Azure Sentinel solution that connects OpenCTI with Microsoft Sentinel to ingest threat intelligence, enrich incidents, and automate indicator synchronization using custom Logic Apps connectors and SOAR playbooks.

The OpenCTI for Azure Sentinel solution is a deployable application within the Microsoft Sentinel environment that enables seamless integration between Microsoft’s SIEM/SOAR capabilities and the OpenCTI threat intelligence platform.

It provides a custom Azure Logic Apps connector along with SOAR playbooks designed to operationalize threat intelligence throughout the incident lifecycle.

This integration allows organizations to:

  • Automatically ingest threat intelligence data from OpenCTI into Microsoft Sentinel.
  • Enrich Sentinel incidents and alerts with contextual indicators and knowledge from OpenCTI, improving investigation accuracy and prioritization.
  • Synchronize indicators bidirectionally, enabling analysts to push indicators from Sentinel back into OpenCTI for centralized knowledge sharing.
  • Automate SOC workflows using prebuilt playbooks for indicator creation, enrichment, and incident response.

Informations de base

Filigran
Nino Rowlands
Intégrations tierces (bientôt disponible)
Endpoint Detection & Response
19 août 2026
0

    Nous utilisons des cookies pour assurer le fonctionnement de XTM Hub. Les cookies nécessaires sont toujours activés ; les cookies facultatifs (fonctionnels, d'analyse, de marketing) ne sont utilisés qu'avec votre consentement. Vous pouvez accepter tous les cookies, les refuser tous ou gérer vos préférences à tout moment dans la rubrique « Paramètres des cookies ».