Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Creates Microsoft Sentinel incidents for identity and infrastructure security threats reported by Cayosoft Guardian across on-premises Active Directory and Microsoft Entra ID. This includes threats related to accounts, service accounts, computers, security groups, and trusted domains. Incident severity is determined dynamically based on the severity of the detected threat. This rule complements the Cloud Application Security Threats rule, which covers cloud application and service principal thr
| Attribute | Value |
|---|---|
| Type | Analytic Rule |
| Solution | Cayosoft Guardian |
| ID | 4720d7a5-6845-4ce4-aa45-79334e1a1176 |
| Severity | Medium |
| Status | Available |
| Kind | Scheduled |
| Required Connectors | CayosoftGuardianConnector |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Selection Criteria | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|---|
CayosoftThreatAlerts_CL |
? | ✓ | ? |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊