⚠️ Unpublished: This item is from a solution that is not yet published on Azure Marketplace or not installed in Content Hub.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Publisher | Red Canary |
| Support Tier | Partner |
| Support Link | https://www.redcanary.com |
| Categories | Security - Threat Protection |
| Version | 3.0.0 |
| Author | Red Canary - microsoft@redcanary.com |
| First Published | 2022-03-04 |
| Last Updated | 2026-05-29 |
| Solution Folder | Red Canary |
The Red Canary solution for Microsoft Sentinel enables Red Canary to publish threat detections into a Microsoft Sentinel custom table for alerting and incident creation.
Underlying Microsoft Technologies used:
This solution takes a dependency on the following technologies, and some of these dependencies might result in additional ingestion or operational costs:
a. Microsoft Sentinel Codeless Connector Framework
b. Azure Monitor Logs Ingestion API
This solution provides 1 data connector(s):
🔶 CLv1: This connector ingests into a table that uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g.
_s,_d,_b,_t,_g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.
This solution uses 1 table(s):
| Table | Used By Connectors | Used By Content |
|---|---|---|
RedCanaryDetections_CL 🔶 |
Red Canary Threat Detection (via Codeless Connector Framework) | Analytics |
🔶 CLv1: This table uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g.
_s,_d,_b,_t,_g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.
This solution includes 1 content item(s):
| Content Type | Count |
|---|---|
| Analytic Rules | 1 |
| Name | Severity | Tactics | Tables Used |
|---|---|---|---|
| Red Canary Threat Detection | High | Collection, CommandAndControl, CredentialAccess, DefenseEvasion, Discovery, Execution, Exfiltration, Impact, InitialAccess, LateralMovement, Persistence, PrivilegeEscalation | RedCanaryDetections_CL |
📄 Source: Red Canary/README.md
The Red Canary solution for Microsoft Sentinel ingests Red Canary detections into the RedCanaryDetections_CL custom table and includes analytic content for creating Microsoft Sentinel incidents from those detections.
The data connector uses the Microsoft Sentinel Codeless Connector Framework (CCF) push pattern. The connector page deploys the Data Collection Endpoint (DCE), Data Collection Rule (DCR), Microsoft Entra application, application secret, and DCR role assignment required for Red Canary to send detections through the Azure Monitor Logs Ingestion API.
RedCanaryDetections_CLCustom-RedCanaryDetectionsCustom-RedCanaryDetectionsRed Canary sends detections to:
{Data Collection Endpoint URI}/dataCollectionRules/{Data Collection Rule Immutable ID}/streams/Custom-RedCanaryDetections?api-version=2023-01-01
Use OAuth 2.0 client credentials with the generated Microsoft Entra application. For Azure public cloud, request a token with this scope:
https://monitor.azure.com/.default
The request body is a JSON array of Red Canary detection records. The preferred payload matches the current Red Canary Automate payload shape:
[
{
"detection": {
"id": "12345",
"url": "https://example.my.redcanary.co/detections/12345",
"headline": "Suspicious activity affecting HOSTNAME",
"details": "Detection details from Red Canary.",
"severity": "High"
},
"host": {
"name": "HOSTNAME",
"full_name": "HOSTNAME.example.com",
"os_family": "Windows",
"os_version": "10.0"
},
"tactics": "Execution, DefenseEvasion",
"process_iocs": [],
"child_process_iocs": [],
"cross_process_iocs": [],
"file_modification_iocs": [],
"network_connection_iocs": [],
"registry_modification_iocs": [],
"identities": []
}
]
[Content truncated...]
| Version | Date Modified (DD-MM-YYYY) | Change History |
|---|---|---|
| 3.0.0 | 02-09-2026 | Added Red Canary Threat Detection (via Codeless Connector Framework) Data Connector and refreshed the Red Canary Threat Detection Analytic Rule. Update Red Canary publisher ID for certification. |
| 1.0.0 | 04-03-2022 | Initial release with Red Canary Data Connector and Red Canary Threat Detection Analytic Rule. |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊