Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
This playbook will add an attacker's source IP address to Microsoft Sentinel Threat Intelligence as a STIX 2.1 indicator when a new alert is opened in Microsoft Sentinel.
| Attribute | Value |
|---|---|
| Type | Playbook |
| Solution | Dynatrace |
| Source | View on GitHub |
This playbook uses 4 Logic App connectors / built-in actions:
| Connector / Action | Type | Connections | Actions |
|---|---|---|---|
azuresentinel |
Managed | 1 | 0 |
keyvault |
Managed | 1 | 1 |
microsoftsentinel |
Managed | 0 | 1 |
http |
Built-in | 0 | 1 |
keyvault (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Get_Dynatrace_Access_Token | get | /secrets/@{encodeURIComponent('DynatraceAccessToken')}/value |
— |
microsoftsentinel (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Threat_Intelligence_-Upload_STIX_Objects(Preview) | post | /ThreatIntelligence/@{encodeURIComponent(triggerBody()?['WorkspaceId'])}/UploadStixObjects/ |
— |
http (Built-in)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Get_Dynatrace_Attack_Details | GET | https://@{parameters('Tenant')}/api/v2/attacks/@{first(body('Parse_Incident_Alert_Custom_Body_JSON')?['AttackIdentifier'])} |
— |
📄 Source: Add_DynatraceApplicationSecurityAttackSourceIpSTIXThreatIntelligence/readme.md
author: Dynatrace
This playbook uses the Dynatrace REST APIs to automatically add an attacker's source IP address to Microsoft Sentinel Threat Intelligence as a STIX 2.1 indicator when an alert is generated by Microsoft Sentinel. You need a valid Dynatrace tenant with Application Security enabled. To learn more about the Dynatrace platform Start your free trial.
This playbook replaces the deprecated Add_DynatraceApplicationSecurityAttackSourceIpThreatIntelligence playbook, which used the now-deprecated Microsoft Graph Security tiIndicators API. This version uses the Microsoft Sentinel Upload STIX Objects API instead.
Prerequisites
attacks.read) scope.DynatraceAccessToken.Post Install Notes:
The Logic App uses a Managed System Identity (MSI) to authenticate with both Microsoft Sentinel and Azure Key Vault.
Assign RBAC Microsoft Sentinel Responder role to the Logic App at the Resource Group level of the Log Analytics Workspace (required to upload STIX threat intelligence).
Assign an access policy on the Key Vault for the playbook managed identity to fetch the secret.
A Microsoft Sentinel playbook is utilized by automation rules, therefore to automatically trigger this playbook you must set up a new automation rule. If you have not set permissions yet, review here.
Basic steps for setup of the playbook and automation rule are as follows:
xyz.dynatrace.comDynatrace Application Security - Attack detectionAddDynatraceAppSecSrcIPAddressSTIXBrowse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊