Add Dynatrace Application Security Attack Source IP Address to Threat Intelligence (STIX)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


This playbook will add an attacker's source IP address to Microsoft Sentinel Threat Intelligence as a STIX 2.1 indicator when a new alert is opened in Microsoft Sentinel.

Attribute Value
Type Playbook
Solution Dynatrace
Source View on GitHub

Logic App Connectors

This playbook uses 4 Logic App connectors / built-in actions:

Connector / Action Type Connections Actions
azuresentinel Managed 1 0
keyvault Managed 1 1
microsoftsentinel Managed 0 1
http Built-in 0 1
Action parameters (URLs, paths, function IDs)

keyvault (Managed)

Action Method Endpoint Other
Get_Dynatrace_Access_Token get /secrets/@{encodeURIComponent('DynatraceAccessToken')}/value —

microsoftsentinel (Managed)

Action Method Endpoint Other
Threat_Intelligence_-Upload_STIX_Objects(Preview) post /ThreatIntelligence/@{encodeURIComponent(triggerBody()?['WorkspaceId'])}/UploadStixObjects/ —

http (Built-in)

Action Method Endpoint Other
Get_Dynatrace_Attack_Details GET https://@{parameters('Tenant')}/api/v2/attacks/@{first(body('Parse_Incident_Alert_Custom_Body_JSON')?['AttackIdentifier'])} —

Additional Documentation

📄 Source: Add_DynatraceApplicationSecurityAttackSourceIpSTIXThreatIntelligence/readme.md

Add_DynatraceApplicationSecurityAttackSourceIpSTIXThreatIntelligence

author: Dynatrace

This playbook uses the Dynatrace REST APIs to automatically add an attacker's source IP address to Microsoft Sentinel Threat Intelligence as a STIX 2.1 indicator when an alert is generated by Microsoft Sentinel. You need a valid Dynatrace tenant with Application Security enabled. To learn more about the Dynatrace platform Start your free trial.

This playbook replaces the deprecated Add_DynatraceApplicationSecurityAttackSourceIpThreatIntelligence playbook, which used the now-deprecated Microsoft Graph Security tiIndicators API. This version uses the Microsoft Sentinel Upload STIX Objects API instead.

Prerequisites

Post Install Notes:

The Logic App uses a Managed System Identity (MSI) to authenticate with both Microsoft Sentinel and Azure Key Vault.

Assign RBAC Microsoft Sentinel Responder role to the Logic App at the Resource Group level of the Log Analytics Workspace (required to upload STIX threat intelligence).

Assign an access policy on the Key Vault for the playbook managed identity to fetch the secret.

Initial Setup

A Microsoft Sentinel playbook is utilized by automation rules, therefore to automatically trigger this playbook you must set up a new automation rule. If you have not set permissions yet, review here.

Basic steps for setup of the playbook and automation rule are as follows:

  1. Go to the Automation blade in Microsoft Sentinel.
  2. Create a new playbook from the Add Dynatrace Application Security Attack Source IP Address to Threat Intelligence (STIX) playbook template.
    • KeyvaultName: The name of the key vault created as a prerequisite.
    • DynatraceTenant: xyz.dynatrace.com
  3. Create a new automation rule.
    • Name: Add Dynatrace Application Security Attack Source IP Address to Threat Intelligence (STIX)
    • Trigger: When alert is created
    • Conditions: If Analytic rule name contains Dynatrace Application Security - Attack detection
    • Actions: Run playbook AddDynatraceAppSecSrcIPAddressSTIX

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Playbooks · Back to Dynatrace