⚠️ Cybereinforce Threat Enforcement (CTE)

⚠️ Unpublished: This item is from a solution that is not yet published on Azure Marketplace or not installed in Content Hub.

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Connectors Index


Attribute Value
Connector ID cybereinforce_cte
Publisher Cybeurope
Used in Solutions Cybereinforce
Collection Method REST Pull API
Connector Definition Files cybereinforce_cte.json
Ingestion API HTTP Data Collector API — Connector definition requires workspace key (SharedKey pattern)

The Cybereinforce Threat Enforcement data connector ingests browser-level URL blocking, threat-intelligence match, and audit/administration events into Microsoft Sentinel using a scheduled Logic App and the Azure Monitor Logs Ingestion API. Cybereinforce enforces Microsoft Defender threat intelligence directly at the browser (Chrome, Firefox, Safari) on enrolled endpoints, and this connector surfaces that enforcement activity for SOC investigation, hunting, and alerting.

Tables Ingested

This connector ingests data into the following tables:

Table Transformations Ingestion API Lake-Only
CybereinforceCTE_CL ? ✓ ?

💡 Tip: Tables with Ingestion API support allow data ingestion via the Azure Monitor Data Collector API, which also enables custom transformations during ingestion.

Permissions

Resource Provider Permissions:

Custom Permissions:

Setup Instructions

⚠️ Note: These instructions were automatically generated from the connector's user interface definition file using AI and may not be fully accurate. Please verify all configuration steps in the Microsoft Sentinel portal.

1. Step 1 - Generate a Cybereinforce MicrosoftToken

  1. Sign in to the Cybereinforce Admin portal.
  2. Under Integrations, find the MicrosoftToken section.
  3. Click Generate MicrosoftToken (/api/microsoftToken).
  4. Copy the generated token and your Cybereinforce Tenant ID - both are required for the deployment in Step 2.

2. Step 2 - Deploy the data ingestion infrastructure

This step deploys the required Azure resources: a custom Log Analytics table (CybereinforceCTE_CL), a Data Collection Endpoint, a Data Collection Rule, a user-assigned managed identity, and a Logic App that polls Cybereinforce on a schedule and forwards new events into the table.

  1. Click the Deploy to Azure button below.

    Deploy to Azure

  2. Select the Subscription, Resource Group, and Location where your Microsoft Sentinel workspace resides.

  3. Enter the Log Analytics Workspace Resource ID, the Cybereinforce Tenant ID, and the MicrosoftToken copied in Step 1.

  4. Click Review + create and then Create.

3. Step 3 - Confirm ingestion

After a few polling cycles (default every 15 minutes), new events should appear in the CybereinforceCTE_CL table. Run one of the sample queries above in Log Analytics to confirm data is flowing.


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Connectors Index