Microsoft Sentinel Incidents
自動配備
Filigranの提供による
Detection & Response Enablement
概要
Imports security incidents, alerts, and observables from Microsoft Sentinel SIEM into OpenCTI as STIX Incidents with associated IOCs.
The Microsoft Sentinel Incidents connector imports security incidents, alerts, indicators, and observables from Microsoft Sentinel SIEM into OpenCTI. It creates structured STIX Incidents linked to associated entities and IOCs, enabling analysts to correlate SIEM detections with threat intelligence data.