Solution: Illusive Platform
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
| Attribute | Value |
|---|---|
| Publisher | Illusive Networks |
| Support Tier | Partner |
| Support Link | https://illusive.com/support |
| Categories | domains |
| Version | 3.0.1 |
| Author | Illusive Networks |
| First Published | 2022-05-25 |
| Solution Folder | Illusive Platform |
| Marketplace | Azure Marketplace · Popularity: ⚪ Very Low (0%) |
| Pre-requisites | Common Event Format |
The Illusive Platform solution for Microsoft Sentinel enables you to ingest Illusive Platform’s attack surface analysis data and incident logs into Microsoft Sentinel and view this information in dedicated dashboards that offer insight into your organization's attack surface risk (ASM Dashboard) and track unauthorized lateral movement in your organization's network (ADS Dashboard).
This solution is dependent on the Common Event Format solution containing the CEF via AMA connector to collect the logs. The CEF solution will be installed as part of this solution installation.
NOTE: Microsoft recommends installation of CEF via AMA Connector. The existing connectors are about to be deprecated by Aug 31, 2024.
This solution depends on 1 other solution(s):
| Solution |
|---|
| Common Event Format |
This solution provides 1 data connector(s) (plus 1 discovered⚠️):
Connectors from dependency solutions:
🔍 Discovered: This item was discovered by scanning the solution folder but is not listed in the Solution JSON file.
This solution uses 1 table(s):
| Table | Used By Connectors | Used By Content |
|---|---|---|
CommonSecurityLog |
Common Event Format (CEF) (dependency), Common Event Format (CEF) via AMA (dependency), [Deprecated] Illusive Platform via AMA, [Deprecated] Illusive Platform via Legacy Agent | Analytics, Workbooks |
This solution includes 3 content item(s):
| Content Type | Count |
|---|---|
| Workbooks | 2 |
| Analytic Rules | 1 |
| Name | Severity | Tactics | Tables Used |
|---|---|---|---|
| Illusive Incidents Analytic Rule | Medium | Persistence, PrivilegeEscalation, DefenseEvasion, CredentialAccess, LateralMovement | CommonSecurityLog |
| Name | Tables Used |
|---|---|
| IllusiveADS | CommonSecurityLog |
| IllusiveASM | CommonSecurityLog |
| Version | Date Modified (DD-MM-YYYY) | Change History |
|---|---|---|
| 3.0.1 | 12-07-2024 | Deprecating data connector |
| 3.0.0 | 13-09-2023 | Addition of new Illusive Platform AMA Data Connector |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊