|
6 | 6 | "config": { |
7 | 7 | "isWizard": false, |
8 | 8 | "basics": { |
9 | | - "description": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/Azure_Sentinel.svg\"width=\"75px\" height=\"75px\">\n\n**Note:** Please refer to the following before installing the solution: \n\n• Review the solution [Release Notes](https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/Threat%20Intelligence%20%28NEW%29/ReleaseNotes.md)\n\n • There may be [known issues](https://aka.ms/sentinelsolutionsknownissues) pertaining to this Solution, please refer to them before installing.\n\nMicrosoft Sentinel has recently improved its threat intelligence hunting experience by incorporating support for STIX objects like Threat Actor, Attack Pattern, Identity, and Relationship. As a result, we have updated our TI Solutions to leverage the new ThreatIntelIndicator table.\n[Work with STIX objects and indicators to enhance threat intelligence and threat hunting in Microsoft Sentinel (Preview) - Microsoft Sentinel | Microsoft Learn](https://learn.microsoft.com/azure/sentinel/work-with-stix-objects-indicators).\n\n The Threat Intelligence solution contains data connectors for import of supported STIX objects into Microsoft Sentinel, analytic rules for matching TI data with event data, workbook, and hunting queries. Threat indicators can be malicious IP's, URL's, filehashes, domains, email addresses etc.\n\n**Data Connectors:** 6, **Parsers:** 1, **Workbooks:** 1, **Analytic Rules:** 52, **Hunting Queries:** 5\n\n[Learn more about Microsoft Sentinel](https://aka.ms/azuresentinel) | [Learn more about Solutions](https://aka.ms/azuresentinelsolutionsdoc)", |
| 9 | + "description": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/Azure_Sentinel.svg\"width=\"75px\" height=\"75px\">\n\n**Note:** Please refer to the following before installing the solution: \n\n• Review the solution [Release Notes](https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/Threat%20Intelligence%20%28NEW%29/ReleaseNotes.md)\n\n • There may be [known issues](https://aka.ms/sentinelsolutionsknownissues) pertaining to this Solution, please refer to them before installing.\n\nMicrosoft Sentinel has recently improved its threat intelligence hunting experience by incorporating support for STIX objects like Threat Actor, Attack Pattern, Identity, and Relationship. As a result, we have updated our TI Solutions to leverage the new ThreatIntelIndicator table.\n[Work with STIX objects and indicators to enhance threat intelligence and threat hunting in Microsoft Sentinel (Preview) - Microsoft Sentinel | Microsoft Learn](https://learn.microsoft.com/azure/sentinel/work-with-stix-objects-indicators).\n\n The Threat Intelligence solution contains data connectors for import of supported STIX objects into Microsoft Sentinel, analytic rules for matching TI data with event data, workbook, and hunting queries. Threat indicators can be malicious IP's, URL's, filehashes, domains, email addresses etc.\n\n**Data Connectors:** 5, **Parsers:** 1, **Workbooks:** 1, **Analytic Rules:** 52, **Hunting Queries:** 5\n\n[Learn more about Microsoft Sentinel](https://aka.ms/azuresentinel) | [Learn more about Solutions](https://aka.ms/azuresentinelsolutionsdoc)", |
10 | 10 | "subscription": { |
11 | 11 | "resourceProviders": [ |
12 | 12 | "Microsoft.OperationsManagement/solutions", |
|
67 | 67 | "name": "dataconnectors2-text", |
68 | 68 | "type": "Microsoft.Common.TextBlock", |
69 | 69 | "options": { |
70 | | - "text": "This Solution installs the data connector for Threat Intelligence (NEW). You can get Threat Intelligence (NEW) custom log data in your Microsoft Sentinel workspace. After installing the solution, configure and enable this data connector by following guidance in Manage solution view." |
| 70 | + "text": "The data connectors installed are:" |
71 | 71 | } |
72 | 72 | }, |
73 | 73 | { |
74 | | - "name": "dataconnectors3-text", |
75 | | - "type": "Microsoft.Common.TextBlock", |
76 | | - "options": { |
77 | | - "text": "This Solution installs the data connector for Threat Intelligence (NEW). You can get Threat Intelligence (NEW) custom log data in your Microsoft Sentinel workspace. After installing the solution, configure and enable this data connector by following guidance in Manage solution view." |
78 | | - } |
| 74 | + "name": "DC1", |
| 75 | + "type": "Microsoft.Common.Section", |
| 76 | + "label": "(1)\t\tThreat Intelligence Platforms", |
| 77 | + "elements": [ |
| 78 | + { |
| 79 | + "name": "DC1-text", |
| 80 | + "type": "Microsoft.Common.TextBlock", |
| 81 | + "options": { |
| 82 | + "text": "Use this connector to send threat indicators to Microsoft Sentinel from your Threat Intelligence Platform (TIP), such as Threat Connect, Palo Alto Networks MindMeld, MISP, or other integrated applications." |
| 83 | + } |
| 84 | + } |
| 85 | + ] |
79 | 86 | }, |
80 | 87 | { |
81 | | - "name": "dataconnectors4-text", |
82 | | - "type": "Microsoft.Common.TextBlock", |
83 | | - "options": { |
84 | | - "text": "This Solution installs the data connector for Threat Intelligence (NEW). You can get Threat Intelligence (NEW) custom log data in your Microsoft Sentinel workspace. After installing the solution, configure and enable this data connector by following guidance in Manage solution view." |
85 | | - } |
| 88 | + "name": "DC2", |
| 89 | + "type": "Microsoft.Common.Section", |
| 90 | + "label": "(2)\t\tThreat Intelligence - TAXII", |
| 91 | + "elements": [ |
| 92 | + { |
| 93 | + "name": "DC2-text", |
| 94 | + "type": "Microsoft.Common.TextBlock", |
| 95 | + "options": { |
| 96 | + "text": "Use this connector to bring in threat intelligence to Microsoft Sentinel from a TAXII 2.0 or 2.1 server." |
| 97 | + } |
| 98 | + } |
| 99 | + ] |
86 | 100 | }, |
87 | 101 | { |
88 | | - "name": "dataconnectors5-text", |
89 | | - "type": "Microsoft.Common.TextBlock", |
90 | | - "options": { |
91 | | - "text": "This Solution installs the data connector for Threat Intelligence (NEW). You can get Threat Intelligence (NEW) custom log data in your Microsoft Sentinel workspace. After installing the solution, configure and enable this data connector by following guidance in Manage solution view." |
92 | | - } |
| 102 | + "name": "DC3", |
| 103 | + "type": "Microsoft.Common.Section", |
| 104 | + "label": "(3)\t\tThreat Intelligence Upload Indicators API", |
| 105 | + "elements": [ |
| 106 | + { |
| 107 | + "name": "DC3-text", |
| 108 | + "type": "Microsoft.Common.TextBlock", |
| 109 | + "options": { |
| 110 | + "text": "Microsoft Sentinel offer a data plane API to bring in threat intelligence from your Threat Intelligence Platform (TIP), such as Threat Connect, Palo Alto Networks MineMeld, MISP, or other integrated applications. Threat indicators can include IP addresses, domains, URLs, file hashes and email addresses." |
| 111 | + } |
| 112 | + } |
| 113 | + ] |
93 | 114 | }, |
94 | 115 | { |
95 | | - "name": "dataconnectors6-text", |
96 | | - "type": "Microsoft.Common.TextBlock", |
97 | | - "options": { |
98 | | - "text": "This Solution installs the data connector for Threat Intelligence (NEW). You can get Threat Intelligence (NEW) custom log data in your Microsoft Sentinel workspace. After installing the solution, configure and enable this data connector by following guidance in Manage solution view." |
99 | | - } |
| 116 | + "name": "DC4", |
| 117 | + "type": "Microsoft.Common.Section", |
| 118 | + "label": "(4)\t\tMicrosoft Defender Threat Intelligence", |
| 119 | + "elements": [ |
| 120 | + { |
| 121 | + "name": "DC4-text", |
| 122 | + "type": "Microsoft.Common.TextBlock", |
| 123 | + "options": { |
| 124 | + "text": "Microsoft Sentinel provides you the capability to import threat intelligence generated by Microsoft to enable monitoring, alerting and hunting. Use this data connector to import Indicators of Compromise (IOCs) from Microsoft Defender Threat Intelligence (MDTI) into Microsoft Sentinel. Threat indicators can include IP addresses, domains, URLs, and file hashes, etc." |
| 125 | + } |
| 126 | + } |
| 127 | + ] |
| 128 | + }, |
| 129 | + { |
| 130 | + "name": "DC5", |
| 131 | + "type": "Microsoft.Common.Section", |
| 132 | + "label": "(5)\t\tThreat Intelligence - TAXII Export", |
| 133 | + "elements": [ |
| 134 | + { |
| 135 | + "name": "DC5-text", |
| 136 | + "type": "Microsoft.Common.TextBlock", |
| 137 | + "options": { |
| 138 | + "text": "Microsoft Sentinel integrates with TAXII 2.1 servers to enable exporting of your threat intelligence objects." |
| 139 | + } |
| 140 | + } |
| 141 | + ] |
100 | 142 | }, |
101 | 143 | { |
102 | 144 | "name": "dataconnectors-parser-text", |
|
106 | 148 | } |
107 | 149 | }, |
108 | 150 | { |
109 | | - "name": "dataconnectors-link6", |
| 151 | + "name": "dataconnectors-link5", |
110 | 152 | "type": "Microsoft.Common.TextBlock", |
111 | 153 | "options": { |
112 | 154 | "link": { |
|
0 commit comments