⚠️ Speculus Threat Intelligence

⚠️ Unpublished: This item is from a solution that is not yet published on Azure Marketplace or not installed in Content Hub.

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Connectors Index


Attribute Value
Connector ID SpeculusThreatIntel
Publisher Speculus
Used in Solutions Speculus Threat Intelligence
Collection Method CCF
Connector Definition Files Speculus_ConnectorDefinition.json
DCR Definition Files Speculus_DCR.json
CCF Configuration Speculus_PollerConfig.json
CCF Capabilities APIKey, Paging

Ingest STIX 2.1 threat intelligence indicators from the Speculus TAXII 2.1 server using the Codeless Connector Framework (CCF). The Speculus feed provides IP indicators enriched with risk scoring, named attribution, scanner/Tor/proxy classification, and geo/network context.

Tables Ingested

This connector ingests data into the following tables:

Table Transformations Ingestion API Lake-Only
Speculus_Indicators_CL ? ✓ ?

💡 Tip: Tables with Ingestion API support allow data ingestion via the Azure Monitor Data Collector API, which also enables custom transformations during ingestion.

Permissions

Resource Provider Permissions:

Custom Permissions:

Setup Instructions

⚠️ Note: These instructions were automatically generated from the connector's user interface definition file using AI and may not be fully accurate. Please verify all configuration steps in the Microsoft Sentinel portal.

1. Connect Speculus Threat Intelligence

Provide your Speculus TAXII server details and API key, then click Connect.

Unless Speculus has provided different values, use the default TAXII base URL https://feed.speculus.co/api1 and collection ID f3a1c2d4-5b6e-4a7f-8c9d-0e1f2a3b4c5d (the speculus-ioc-feed collection).

Note: TAXII polling is not metered against your Speculus API quota — only the single-IP REST lookup used by the incident-enrichment playbook is quota-metered.


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Connectors Index