HoneyLabs-EnrichIncident-IP

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


Enriches Microsoft Sentinel incidents with HoneyLabs honeypot intelligence. For every IP entity on the incident, the playbook queries the HoneyLabs lookup API and writes a comment with the verdict (exploitation, scanning, probing, or recognized research scanner), event counts, first and last seen, and a link to the full report.

Attribute Value
Type Playbook
Solution HoneyLabs
Source View on GitHub

Logic App Connectors

This playbook uses 2 Logic App connectors / built-in actions:

Connector / Action Type Connections Actions
azuresentinel Managed 1 4
http Built-in 0 1
Action parameters (URLs, paths, function IDs)

azuresentinel (Managed)

Action Method Endpoint Other
Entities_-_Get_IPs post /entities/ip —
Add_comment_to_incident post /Incidents/Comment —
Add_HoneyLabs_tag put /Incidents/Label —
Set_incident_severity_High put /Incidents —

http (Built-in)

Action Method Endpoint Other
HTTP_HoneyLabs_lookup GET https://honeylabs.net/lookup/@{items('For_each_IP')?['Address']}?format=json —

Additional Documentation

📄 Source: HoneyLabs-EnrichIncident-IP/readme.md

Enriches Microsoft Sentinel incidents with HoneyLabs honeypot intelligence.

For every IP entity on a new incident, the playbook queries the HoneyLabs lookup API (https://honeylabs.net/lookup/<ip>?format=json) and adds a comment with:

Prerequisites

Post-deployment

  1. Grant the playbook's system-assigned managed identity the Microsoft Sentinel Responder role on the resource group.
  2. Attach the playbook to an automation rule that fires on incident creation for incidents with IP entities.

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Playbooks · Back to HoneyLabs