⚠️ Unpublished: This item is from a solution that is not yet published on Azure Marketplace or not installed in Content Hub.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Publisher | SpyCloud |
| Support Tier | Partner |
| Support Link | https://support.spycloud.com |
| Categories | Security - Threat Intelligence,Identity |
| Version | 3.0.0 |
| Author | SpyCloud - support@spycloud.com |
| First Published | 2026-06-09 |
| Last Updated | 2026-06-09 |
| Solution Folder | SpyCloud Enterprise Protection CCF |
The SpyCloud Enterprise Protection solution for Microsoft Sentinel ingests SpyCloud breach watchlist and catalog data via the Codeless Connector Framework (CCF), including an optional Compass daily feed. The solution includes two built-in analytic rules, two KQL parsers, and two automation playbooks for Microsoft Defender for Endpoint and Azure AD / Entra ID Conditional Access response.
Underlying Microsoft Technologies used:
This solution takes a dependency on the following technologies, and some of these dependencies either may be in Preview state or might result in additional ingestion or operational costs:
a. Codeless Connector Framework (CCF)
c. Microsoft Defender for Endpoint
This solution provides 1 data connector(s):
This solution uses 5 table(s):
This solution includes 6 content item(s):
| Content Type | Count |
|---|---|
| Analytic Rules | 2 |
| Playbooks | 2 |
| Parsers | 2 |
| Name | Severity | Tactics | Tables Used |
|---|---|---|---|
| SpyCloud infostealer malware credential exposure | High | CredentialAccess, CommandAndControl | SpyCloudBreachWatchlistV2_CL |
| SpyCloud plaintext credential exposure detected | High | CredentialAccess | SpyCloudBreachWatchlistV2_CL |
| Name | Description | Tables Used |
|---|---|---|
| SpyCloud Conditional Access Playbook | Spycloud Conditional access playbook | - |
| SpyCloud_MDE_Automation | This playbook automates endpoint response actions in Microsoft Defender for Endpoint (MDE) when SpyC... | - |
| Name | Description | Tables Used |
|---|---|---|
| get_Spycloud_enriched_data | - | SpyCloudBreachCatalogV2_CL (read) |
| get_spycloud_compass_data | - | spycloud_compassV2_CL (read) |
| Version | Date Modified (DD-MM-YYYY) | Change History |
|---|---|---|
| 3.0.0 | 09-06-2026 | Initial CCF-based release. SpyCloud Watchlist and Breach Catalog CCF data connector (Compass daily feed included), two built-in analytic rules (AR_Breached_Users_20, AR_malware_25), two KQL parsers (get_Spycloud_enriched_data, get_spycloud_compass_data), MDE Automation playbook, and Conditional Access playbook. |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊