TISC - Microsoft Sentinel integration
Threat Intelligence Security Center for Microsoft Sentinel offers several capabilities, including importing observables from TISC to Sentinel, enriching Sentinel incidents with details of related observables, and also allow exporting observables from Sentinel to TISC.
Remarque :
On Microsoft Sentinel, observables are referred as entities.
Prerequisites
Dependencies
The Threat Intelligence solution from Microsoft Sentinel Content Hub must be installed.
| Application | Roles and Permissions | Description |
|---|---|---|
| Microsoft Sentinel-specific roles |
|
For more information, see Roles and Permissions in Microsoft Sentinel. |
| Threat Intelligence Security Center | sn_sec_tisc.api_azure_sentinel_solution | User configured in the TISC Custom Connector should have this role to allow access to TISC APIs. |