Cayosoft Guardian - Cloud Application Security Threats

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


Creates Microsoft Sentinel incidents for cloud application and Microsoft Entra ID service principal security threats reported by Cayosoft Guardian. Incident severity is determined dynamically based on the severity of the detected threat. This rule complements the Core Identity and Infrastructure Threats rule, which covers all other Cayosoft Guardian threat types not included in this rule. Alerts with the same Cayosoft ThreatId are grouped into a single incident within a 1-day lookback window.

Attribute Value
Type Analytic Rule
Solution Cayosoft Guardian
ID e6f6c71c-f1fd-473b-9129-249db5d7462c
Severity Medium
Status Available
Kind Scheduled
Required Connectors CayosoftGuardianConnector
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
CayosoftThreatAlerts_CL ? ✓ ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Analytic Rules · Back to Cayosoft Guardian