Dataverse - TI map URL to DataverseActivity

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Identifies a match in DataverseActivity from any URL IOC from Microsoft Sentinel Threat Intelligence.

Attribute Value
Type Analytic Rule
Solution Microsoft Business Applications
ID d88a0e22-3b6a-40c2-af28-c064b44d03b7
Severity Medium
Status Available
Kind Scheduled
Tactics InitialAccess, Execution, Persistence
Techniques T1566, T1456, T1474, T0819, T0865, T0862, T0863, T1204, T1574, T0873
Required Connectors Dataverse, ThreatIntelligence, ThreatIntelligenceTaxii, MicrosoftDefenderThreatIntelligence, ThreatIntelligence, ThreatIntelligenceTaxii, MicrosoftDefenderThreatIntelligence
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
DataverseActivity Fields has "http"
Message in "Create,Update"
ThreatIntelligenceIndicator

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules · Back to Microsoft Business Applications