Solution: TacitRed-Defender-ThreatIntelligence
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Publisher | Data443 Risk Mitigation, Inc. |
| Support Tier | Partner |
| Support Link | https://www.data443.com |
| Categories | Security - Threat Intelligence |
| Version | 3.0.1 |
| Author | Data443 Risk Mitigation, Inc. - support@data443.com |
| First Published | 2025-11-10 |
| Last Updated | 2026-02-13 |
| Solution Folder | TacitRed-Defender-ThreatIntelligence |
| Marketplace | Azure Marketplace · Popularity: ⚪ Very Low (0%) |
The TacitRed Defender Threat Intelligence solution integrates TacitRed's threat intelligence feed with Microsoft Sentinel. It automatically retrieves compromised credentials and other threat indicators from TacitRed and ingests them into Microsoft Sentinel using the Upload API for enhanced threat detection.
This solution does not include data connectors.
This solution may contain other components such as analytics rules, workbooks, hunting queries, or playbooks.
This solution includes 1 content item(s):
| Content Type | Count |
|---|---|
| Playbooks | 1 |
| Name | Description | Tables Used |
|---|---|---|
| TacitRed to Defender TI | This playbook ingests TacitRed threat intelligence into Microsoft Defender Threat Intelligence via a... | - |
The TacitRed Defender Threat Intelligence solution integrates TacitRed's threat intelligence feed with Microsoft Sentinel. It automatically retrieves compromised credentials and other threat indicators from TacitRed and ingests them into Microsoft Sentinel using the Threat Intelligence Upload API for enhanced threat detection.
| Component | Description |
|---|---|
| Playbook | Logic App that fetches compromised credentials from TacitRed and uploads them to Microsoft Defender Threat Intelligence |
Storage Blob Data Owner to the Function App managed identity on the deployed storage account after installationStorage Blob Data Owner to the Function App managed identity on the storage account created for the Function AppReader and Microsoft Sentinel Contributor to the Function App managed identity on the target Log Analytics workspace| Version | Date Modified (DD-MM-YYYY) | Change History |
|---|---|---|
| 3.0.2 | 25-05-2026 | Fixed Content Hub InvalidTemplate deployment failure on hyphenated workspace names. Bound Application Insights to the selected Log Analytics workspace via WorkspaceResourceId so deployment does not require permission to create a managed resource group. Replaced hardcoded EndpointSuffix=core.windows.net with environment().suffixes.storage so the template works in sovereign clouds. Changed the location parameter default in Playbooks/TacitRedDefenderTI_FunctionApp/azuredeploy.json to [resourceGroup().location] so standalone deployments resolve a real region. Post-deployment guidance in README still requires manually assigning Storage Blob Data Owner to the Function App managed identity. |
| 3.0.1 | 11-02-2026 | Fixed deployment failure: Restored functionCode.zip package removed in prior commit. Removed workspace-scoped roleAssignments from Function App template to resolve InvalidTemplate error during Content Hub deployment. |
| 3.0.0 | 09-12-2025 | Initial release of TacitRed Defender Threat Intelligence solution with Azure Function and Logic App playbook for syncing TacitRed compromised credentials to Microsoft Defender Threat Intelligence. |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊