Darktrace for Microsoft Sentinel

Solution: Darktrace

Darktrace Logo

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Solutions Index


Attribute Value
Publisher Darktrace
Support Tier Partner
Support Link https://www.darktrace.com/en/contact/
Categories domains
Version 2.0.1
Author Darktrace
First Published 2022-05-02
Solution Folder Darktrace
Marketplace Azure Marketplace · Popularity: 🟢 High (85%)

The Darktrace Sentinel Solution lets users connect Darktrace AI-based alerting in real-time with Microsoft Sentinel, allowing creation of custom Dashboards, Workbooks, Notebooks and Custom Alerts to improve investigation. Microsoft Sentinel's enhanced visibility into Darktrace logs enables monitoring and mitigation of security threats.

Underlying Microsoft Technologies used:

This solution takes a dependency on the following technologies, and some of these dependencies either may be in Preview state or might result in additional ingestion or operational costs:

a. Microsoft Sentinel Data Collector API

For more details about this solution refer to https://www.darktrace.com/microsoft/sentinel/

Contents

Data Connectors

This solution provides 1 data connector(s):

🔶 CLv1: This connector ingests into a table that uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g. _s, _d, _b, _t, _g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.

Tables Used

This solution uses 1 table(s):

Table Used By Connectors Used By Content
darktrace_model_alerts_CL 🔶 Darktrace Connector for Microsoft Sentinel REST API Analytics, Workbooks

🔶 CLv1: This table uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g. _s, _d, _b, _t, _g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.

Content Items

This solution includes 4 content item(s):

Content Type Count
Analytic Rules 3
Workbooks 1

Analytic Rules

Name Severity Tactics Tables Used
Darktrace AI Analyst High - darktrace_model_alerts_CL
Darktrace Model Breach Medium - darktrace_model_alerts_CL
Darktrace System Status Informational - darktrace_model_alerts_CL

Workbooks

Name Tables Used
DarktraceWorkbook darktrace_model_alerts_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Solutions Index