⚠️ Unpublished: This item is from a solution that is not yet published on Azure Marketplace or not installed in Content Hub.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Publisher | Speculus |
| Support Tier | Partner |
| Support Link | https://speculus.co |
| Categories | Security - Threat Intelligence |
| Version | 3.0.0 |
| Author | Speculus - dev@speculus.co |
| First Published | 2026-07-01 |
| Solution Folder | Speculus Threat Intelligence |
The Speculus Threat Intelligence solution ingests STIX 2.1 IP indicators from the Speculus TAXII 2.1 server into Microsoft Sentinel using the Codeless Connector Framework (CCF). Indicators carry risk scoring, named attribution, scanner/Tor/proxy classification, and geo/network enrichment. The solution deploys a REST API poller connector, a custom log table, a data collection rule, analytics rules for matching indicators against network and sign-in telemetry, and an incident-enrichment playbook that looks up IP entities against the Speculus REST API on demand.
This solution provides 1 data connector(s):
This solution uses 1 table(s):
| Table | Used By Connectors | Used By Content |
|---|---|---|
Speculus_Indicators_CL |
Speculus Threat Intelligence | Analytics |
This solution includes 4 content item(s):
| Content Type | Count |
|---|---|
| Analytic Rules | 3 |
| Playbooks | 1 |
| Name | Severity | Tactics | Tables Used |
|---|---|---|---|
| Speculus - Network traffic to or from high-risk IP indicator | High | CommandAndControl, InitialAccess | Speculus_Indicators_CL |
| Speculus - Sign-in attempt from high-risk IP indicator | High | InitialAccess, CredentialAccess | Speculus_Indicators_CL |
| Speculus - Threat intelligence feed outage | Informational | Impact | Speculus_Indicators_CL |
| Name | Description | Tables Used |
|---|---|---|
| Speculus Incident Enrichment - Playbook | Runs on a Microsoft Sentinel incident, looks up every IP entity against the Speculus REST API (singl... | - |
📄 Source: Speculus Threat Intelligence/README.md
Ingests STIX 2.1 IP indicators from the Speculus TAXII 2.1 server into Microsoft Sentinel using the Codeless Connector Framework (CCF) — no Azure Functions or agents required.
| Component | Name | Purpose |
|---|---|---|
| Data connector | Speculus Threat Intelligence | RestApiPoller against the Speculus TAXII 2.1 objects endpoint |
| Custom table | Speculus_Indicators_CL |
Flattened STIX indicators with Speculus enrichment |
| Data collection rule | dcr-speculus-indicators |
Filters the TAXII envelope to Indicator SDOs and flattens STIX + x_speculus_* fields |
| Analytics rules | 3 | High-risk IP match vs. CommonSecurityLog, high-risk IP match vs. SigninLogs, feed outage detection |
| Playbook | pb-speculus-incident-enrichment |
On-demand: looks up every IP entity on a triggered incident against the Speculus REST API and posts full enrichment as an incident comment |
The connector polls {taxiiBaseUrl}/collections/{collectionId}/objects/ (TAXII 2.1) with Authorization: Bearer <API key>, using added_after for incremental collection and the TAXII envelope's next cursor / more flag for pagination. Each page's objects array contains STIX 2.1 SDOs (an Identity, then Indicators, plus Malware/Relationship objects when an indicator has named attribution). The data collection rule keeps only type == "indicator" objects — attribution is preserved on the indicator itself via x_speculus_attribution — and flattens the STIX fields and Speculus custom properties into Speculus_Indicators_CL.
https://feed.speculus.co/api1f3a1c2d4-5b6e-4a7f-8c9d-0e1f2a3b4c5d (the speculus-ioc-feed collection)Speculus_Indicators_CL within the first polling window (60 minutes).pb-speculus-incident-enrichment runs per-incident rather than on a schedule: it reads the IP entities attached to a Sentinel incident, calls GET {baseUrl}/v1/objects/{ip} on the Speculus REST API for each one, and posts the full enrichment (risk score, activity, attribution, labels, scanner/Tor/blacklist flags, ISP/ASN, geo, and the verdict description) as an incident comment.
azuresentinel connection (one-time, interactive).[Content truncated...]
| Version | Date Modified (DD-MM-YYYY) | Change History |
|---|---|---|
| 3.0.0 | 28-07-2026 | Initial release: CCF TAXII 2.1 poller data connector, Speculus_Indicators_CL custom table + DCR, 3 analytics rules, and pb-speculus-incident-enrichment playbook (on-demand IP entity lookup against the Speculus REST API, posted as an incident comment) |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊