OpenCTI または OpenAEV プラットフォームを 30 日間お試しいただけます。 無料トライアル
XTMハブ by フィリグラン
サインアップ
Microsoft Sentinel App logo

Microsoft Sentinel App

Detection & Response Enablement
A picture of RG9jdW1lbnQ6YjVlMDVlZjQtM2ZlMi00YmQ0LTk4NmQtN2QyMGJiZWRhODM1

概要

Azure Sentinel solution that connects OpenCTI with Microsoft Sentinel to ingest threat intelligence, enrich incidents, and automate indicator synchronization using custom Logic Apps connectors and SOAR playbooks.

The OpenCTI for Azure Sentinel solution is a deployable application within the Microsoft Sentinel environment that enables seamless integration between Microsoft’s SIEM/SOAR capabilities and the OpenCTI threat intelligence platform.

It provides a custom Azure Logic Apps connector along with SOAR playbooks designed to operationalize threat intelligence throughout the incident lifecycle.

This integration allows organizations to:

  • Automatically ingest threat intelligence data from OpenCTI into Microsoft Sentinel.
  • Enrich Sentinel incidents and alerts with contextual indicators and knowledge from OpenCTI, improving investigation accuracy and prioritization.
  • Synchronize indicators bidirectionally, enabling analysts to push indicators from Sentinel back into OpenCTI for centralized knowledge sharing.
  • Automate SOC workflows using prebuilt playbooks for indicator creation, enrichment, and incident response.

基本情報

Filigran
Nino Rowlands
サードパーティとの統合
Endpoint Detection & Response
2026年8月19日
0

    XTM Hubの運営にはクッキーを使用しています。必須のクッキーは常に有効になっていますが、オプションのクッキー(機能、分析、マーケティング)は、お客様の同意を得た上で使用されます。「クッキー設定」から、いつでも「すべて受け入れる」、「すべて拒否する」、または設定を管理することができます。