Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
This playbook fetches indicators from OpenCTI and send to Sentinel. Supported types are Domain, File, IPv4, IPv6, Account, Url. This runs for every 10 minutes
| Attribute | Value |
|---|---|
| Type | Playbook |
| Solution | OpenCTI |
| Source | View on GitHub |
This playbook uses 1 Logic App connector / built-in action:
| Connector / Action | Type | Connections | Actions |
|---|---|---|---|
OpenCTICustomConnector |
Custom | 1 | 2 |
OpenCTICustomConnector (Custom)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Run_Sample_GraphQL_Query_to_check_Auth_ | post | /graphql |
— |
| Run_GraphQL_Query_Get_Indicators | post | /graphql |
— |
📄 Source: OpenCTIPlaybooks/OpenCTI-GetIndicatorsStream/readme.md
This playbook fetches indicators from OpenCTI and send to Sentinel. Supported types are Domain, File, IPv4, IPv6, Account, Url. This runs for every 10 minutes

Deploy the playbook by clicking on "Deploy to Azure" button. This will take you to deplyoing an ARM Template wizard.
Fill in the required paramteres:
Once deployment is complete, you will need to authorize each connection.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊