connectors icon indicating copy to clipboard operation
connectors copied to clipboard

[Microsoft Sentinel] Enhance the connector i.e. import more data from MS to OCTI

Open Jermain-N opened this issue 1 year ago • 0 comments

Use case

As an analyst, I want all of the available technical information in a MS Sentinel alert to be included when it's imported as an incident via the connector.

Current Workaround

I have to manually copy and paste items from the MS Sentinel alert e.g. file hash, file path, etc.

Proposed Solution

Please include fileEvidence, FileHashEvidence and MalwareEvidence from Sentinel alerts.

Jermain-N avatar Sep 02 '24 19:09 Jermain-N