⚠️ Unpublished: This item is from a solution that is not yet published on Azure Marketplace or not installed in Content Hub.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Publisher | Datazag |
| Support Tier | Partner |
| Support Link | https://datazag.com/support |
| Categories | Security - Threat Intelligence |
| Version | 3.0.0 |
| Author | Datazag - support@datazag.com |
| First Published | 2026-08-06 |
| Last Updated | 2026-08-06 |
| Solution Folder | Datazag |
The Datazag solution for Microsoft Sentinel delivers brand impersonation, platform impersonation and attacker-infrastructure indicators derived from Certificate Transparency, published as STIX 2.1 objects over a TAXII 2.1 server.\n\nIndicators are ingested using Microsoft Sentinel's built-in Threat Intelligence - TAXII data connector and land in the native ThreatIntelIndicators table. No custom table, data collection rule or workspace function is required, and indicators are available to analytic rules and hunting queries immediately. Because indicators are retained in the workspace, existing logs can also be retro-hunted against them. Datazag never queries your workspace: delivery is pull-only, on a schedule you control.\n\nBefore you install\n\nYou need an active Datazag subscription. Contact support@datazag.com to obtain the username and password for your organisation, quoting the collections your subscription includes.\n\nConnecting the feed\n\nIn the Microsoft Defender portal, go to Microsoft Sentinel > Configuration > Data connectors, open Threat Intelligence - TAXII, select Open connector page, then Add. Enter a friendly name of your choosing, the API root URL and collection ID below, and the credentials issued by Datazag. A polling frequency of once an hour is recommended. Repeat for each collection your subscription includes; each is a separate TAXII server entry.\n\nAPI root URL: https://taxii.datazag.com/api/\n\n| Collection | ID |\n|---|---|\n| Platform impersonation | c7ad8fef-c704-4b36-9526-5d7c3bd018c4 |\n| Attacker infrastructure | eedf8709-5e4f-4ed4-b840-5eaafa236b70 |\n\nBrand impersonation collections are issued per organisation; Datazag will supply your collection ID with your credentials.\n\nPrerequisites\n\na. An active Datazag subscription and TAXII credentials, as above.\n\nb. The analytic rule and hunting query in this solution match indicators against DNS activity through the Advanced Security Information Model (ASIM). The ASIM DNS parsers must be deployed and the workspace must be receiving DNS telemetry for this content to return results.\n\nContent in this solution identifies Datazag indicators by their STIX created_by_ref rather than by SourceSystem, because SourceSystem reflects the friendly name you choose when adding the TAXII server.
This solution does not include data connectors.
This solution may contain other components such as analytics rules, workbooks, hunting queries, or playbooks.
The following 1 table(s) are used internally by this solution's content items:
| Table | Used By Content |
|---|---|
ThreatIntelIndicators |
Analytics, Hunting |
This solution includes 2 content item(s):
| Content Type | Count |
|---|---|
| Analytic Rules | 1 |
| Hunting Queries | 1 |
| Name | Severity | Tactics | Tables Used |
|---|---|---|---|
| Datazag - impersonation domain resolved in DNS | High | InitialAccess, CommandAndControl | Internal use:ThreatIntelIndicators |
| Name | Tactics | Tables Used |
|---|---|---|
| Datazag - retro-hunt historical DNS against impersonation indicators | InitialAccess, CommandAndControl | Internal use:ThreatIntelIndicators |
| Version | Date Modified (DD-MM-YYYY) | Change History |
|---|---|---|
| 3.0.0 | 27-08-2026 | Initial Datazag Threat Intelligence solution release. |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊