Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Creates Microsoft Sentinel incidents for cloud application and Microsoft Entra ID service principal security threats reported by Cayosoft Guardian. Incident severity is determined dynamically based on the severity of the detected threat. This rule complements the Core Identity and Infrastructure Threats rule, which covers all other Cayosoft Guardian threat types not included in this rule. Alerts with the same Cayosoft ThreatId are grouped into a single incident within a 1-day lookback window.
| Attribute | Value |
|---|---|
| Type | Analytic Rule |
| Solution | Cayosoft Guardian |
| ID | e6f6c71c-f1fd-473b-9129-249db5d7462c |
| Severity | Medium |
| Status | Available |
| Kind | Scheduled |
| Required Connectors | CayosoftGuardianConnector |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Selection Criteria | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|---|
CayosoftThreatAlerts_CL |
? | ✓ | ? |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊