⚠️ Unpublished: This item is from a solution that is not yet published on Azure Marketplace or not installed in Content Hub.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Connector ID | cybereinforce_cte |
| Publisher | Cybeurope |
| Used in Solutions | Cybereinforce |
| Collection Method | REST Pull API |
| Connector Definition Files | cybereinforce_cte.json |
| Ingestion API | HTTP Data Collector API — Connector definition requires workspace key (SharedKey pattern) |
The Cybereinforce Threat Enforcement data connector ingests browser-level URL blocking, threat-intelligence match, and audit/administration events into Microsoft Sentinel using a scheduled Logic App and the Azure Monitor Logs Ingestion API. Cybereinforce enforces Microsoft Defender threat intelligence directly at the browser (Chrome, Firefox, Safari) on enrolled endpoints, and this connector surfaces that enforcement activity for SOC investigation, hunting, and alerting.
This connector ingests data into the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
CybereinforceCTE_CL |
? | ✓ | ? |
💡 Tip: Tables with Ingestion API support allow data ingestion via the Azure Monitor Data Collector API, which also enables custom transformations during ingestion.
Resource Provider Permissions:
Custom Permissions:
⚠️ Note: These instructions were automatically generated from the connector's user interface definition file using AI and may not be fully accurate. Please verify all configuration steps in the Microsoft Sentinel portal.
1. Step 1 - Generate a Cybereinforce MicrosoftToken
2. Step 2 - Deploy the data ingestion infrastructure
This step deploys the required Azure resources: a custom Log Analytics table (CybereinforceCTE_CL), a Data Collection Endpoint, a Data Collection Rule, a user-assigned managed identity, and a Logic App that polls Cybereinforce on a schedule and forwards new events into the table.
Click the Deploy to Azure button below.
Select the Subscription, Resource Group, and Location where your Microsoft Sentinel workspace resides.
Enter the Log Analytics Workspace Resource ID, the Cybereinforce Tenant ID, and the MicrosoftToken copied in Step 1.
Click Review + create and then Create.
3. Step 3 - Confirm ingestion
After a few polling cycles (default every 15 minutes), new events should appear in the CybereinforceCTE_CL table. Run one of the sample queries above in Log Analytics to confirm data is flowing.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊