⚠️ ThinkstCanary

⚠️ Unpublished: This item is from a solution that is not yet published on Azure Marketplace or not installed in Content Hub.

ThinkstCanary Logo

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Solutions Index


Attribute Value
Publisher Thinkst Applied Research
Support Tier Partner
Support Link https://help.canary.tools/
Categories Security - Threat Protection
Version 3.0.0
Author Thinkst Applied Research - support@canary.tools
First Published 2026-08-18
Last Updated 2026-08-18
Solution Folder ThinkstCanary

The Thinkst Canary solution for Microsoft Sentinel ingests Canary and Canarytoken incidents through the Codeless Connector Framework and provides normalized parsers, detections and response automation.

Contents

Data Connectors

This solution provides 1 data connector(s):

Tables Used

This solution uses 1 table(s):

Table Used By Connectors Used By Content
ThinkstCanaryIncidents_CL Thinkst Canary Analytics

Content Items

This solution includes 1 content item(s):

Content Type Count
Analytic Rules 1

Analytic Rules

Name Severity Tactics Tables Used
Canary alerts to incidents High LateralMovement, Exfiltration ThinkstCanaryIncidents_CL

Release Notes

Version Date Modified (DD-MM-YYYY) Change History
3.0.0 18-08-2026 Initial CCF connector and analytic rule for ingesting and detecting Thinkst Canary and Canarytoken incidents.

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Solutions Index