⚠️ Illusive Active Defense

⚠️ Unpublished: This item is from a solution that is not yet published on Azure Marketplace or not installed in Content Hub.

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Solutions Index


Attribute Value
Publisher
Support Tier
Solution Folder Illusive Active Defense

Contents

Data Connectors

This solution does not include data connectors.

This solution may contain other components such as analytics rules, workbooks, hunting queries, or playbooks.

Content Items

This solution includes 2 content item(s) (0 in solution, 2 discovered 🔍):

Content Type Total In Solution Discovered
Playbooks 2 0 2

Playbooks

Name Description Tables Used
Illusive-SentinelIncident-Enrichment ⚠️

-
Illusive-SentinelIncident-Response ⚠️

-

⚠️ Items marked with ⚠️ are not listed in the Solution JSON file. They were discovered by scanning the solution folder and may be legacy items, under development, or excluded from the official solution package.

Additional Documentation

📄 Source: Illusive Active Defense/README.md

image

Illusive Active Defense Sentinel Solution

Instructions for configuring, running, and using the Illusive Active Defense Sentinel solution.

Table of Contents

  1. Executive summary
  2. Basic requirements
  3. Workflow
  4. Locate the Sentinel workspace
  5. Azure application setup
  6. Generate an Illusive API key
  7. Configure Illusive to send logs to a Linux-based syslog server
  8. Deploy solution package or deploy playbooks
  9. Configure the Illusive analytic rule
  10. Access and view the playbook

Executive summary

Configure Sentinel and load custom playbooks to have Illusive open Sentinel incidents, populate them with Illusive-based information, and automate incident response.

This solution contains the following components:

Basic requirements (set up in advance)

To use the Illusive Active Defense solution, you must have the following:

[Content truncated...]


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Solutions Index