connectors
connectors copied to clipboard
[Microsoft Sentinel] Enhance the connector i.e. import more data from MS to OCTI
Use case
As an analyst, I want all of the available technical information in a MS Sentinel alert to be included when it's imported as an incident via the connector.
Current Workaround
I have to manually copy and paste items from the MS Sentinel alert e.g. file hash, file path, etc.
Proposed Solution
Please include fileEvidence, FileHashEvidence and MalwareEvidence from Sentinel alerts.