Solution: ZeroFox
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
| Attribute | Value |
|---|---|
| Publisher | ZeroFox |
| Support Tier | Partner |
| Support Link | https://www.zerofox.com/contact-us/ |
| Categories | domains |
| Version | 3.2.2 |
| Author | ZeroFox - integration-support@zerofox.com |
| First Published | 2023-07-28 |
| Solution Folder | ZeroFox |
| Marketplace | Azure Marketplace · Popularity: 🔵 Medium (64%) |
The ZeroFox solution for Microsoft Sentinel enables you to ingest ZeroFox Alerts and ZeroFox CTI events into Microsoft Sentinel using the ZeroFox API.
Underlying Microsoft Technologies used:
This solution takes a dependency on the following technologies, and some of these dependencies either may be in Preview state or might result in additional ingestion or operational costs:
a. Azure Monitor HTTP Data Collector API
This solution provides 2 data connector(s):
🔶 CLv1: This connector ingests into a table that uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g.
_s,_d,_b,_t,_g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.
This solution uses 21 table(s):
🔶 CLv1: This table uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g.
_s,_d,_b,_t,_g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.
This solution includes 4 content item(s):
| Content Type | Count |
|---|---|
| Analytic Rules | 4 |
| Name | Severity | Tactics | Tables Used |
|---|---|---|---|
| ZeroFox Alerts - High Severity Alerts | High | ResourceDevelopment, InitialAccess | ZeroFoxAlertPoller_CL |
| ZeroFox Alerts - Informational Severity Alerts | Informational | ResourceDevelopment, InitialAccess | ZeroFoxAlertPoller_CL |
| ZeroFox Alerts - Low Severity Alerts | Low | ResourceDevelopment, InitialAccess | ZeroFoxAlertPoller_CL |
| ZeroFox Alerts - Medium Severity Alerts | Medium | ResourceDevelopment, InitialAccess | ZeroFoxAlertPoller_CL |
| Version | Date Modified (DD-MM-YYYY) | Change History |
|---|---|---|
| 3.2.2 | 17-11-2025 | Added New CCF connector. |
| 3.2.1 | 26-12-2024 | Update alerts data connector version that fix issues in fetching updates |
| 3.2.0 | 26-09-2024 | Changed query parameter in alerts connector for fetching updates |
| 3.1.0 | 26-07-2024 | Updated ZeroFox connector to generate result batches and implemented async Sentinel connector logic |
| 3.0.1 | 30-04-2024 | Fixed Solution Metadata for deployment |
| 3.0.0 | 04-08-2023 | Added Data Connectors for ZeroFox's Alerts and CTI feeds |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊