Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Polls the PRODAFT USTA malware-hash IoC feed hourly, maps each record to a STIX 2.1 file indicator (MD5/SHA-1/SHA-256), and uploads it to Microsoft Sentinel Threat Intelligence via the Upload STIX Objects API. Indicators appear in the Threat Intelligence blade and the ThreatIntelIndicators table with SourceSystem 'PRODAFT USTA - Malware Hashes'. Each run starts its fetch window from a watermark - the newest already-imported indicator's created time, read from the ThreatIntelIndicators table - so
| Attribute | Value |
|---|---|
| Type | Playbook |
| Solution | PRODAFT USTA - IoC Threat Intelligence |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Selection Criteria | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|---|
ThreatIntelIndicators |
SourceSystem == "PRODAFT USTA - Malware Hashes" |
✓ | ✓ | ✗ |
This playbook uses 3 Logic App connectors / built-in actions:
| Connector / Action | Type | Connections | Actions |
|---|---|---|---|
azuremonitorlogs |
Managed | 1 | 1 |
azuresentinel |
Managed | 1 | 1 |
http |
Built-in | 0 | 1 |
azuremonitorlogs (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Get_Import_Watermark | post | /queryData |
— |
azuresentinel (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Upload_STIX_Objects | post | /ThreatIntelligence/@{encodeURIComponent(uriComponent(parameters('WorkspaceID')))}/UploadStixObjects/ |
— |
http (Built-in)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Fetch_USTA_Page | GET | @variables('NextUrl') |
— |
Hourly import playbook for the malware-hashes USTA IoC feed. Each run resumes from a
watermark — the newest already-imported indicator's created time — maps each new record
to a STIX 2.1 file indicator (file:hashes MD5/SHA-1/SHA-256), and uploads them to Microsoft
Sentinel Threat Intelligence (Upload STIX Objects API) using its system-assigned managed
identity. Indicators appear in the Threat Intelligence blade / ThreatIntelIndicators table
with SourceSystem == "PRODAFT USTA - Malware Hashes".
At the start of every run the playbook queries the ThreatIntelIndicators table for
max(Created) of SourceSystem == "PRODAFT USTA - Malware Hashes" and uses that (minus a
5-minute safety overlap) as the start= of the fetch. Because a record only lands in that
table after a successful upload, a failed run does not advance the watermark: the next run
re-reads the same value and retries the missed window, so no indicators are skipped on
failure. If the table has no such indicators yet (first run), it falls back to LookBackHours.
The watermark query runs through the Azure Monitor Logs connection (managed-identity auth) using the
same managed identity, but it needs Log Analytics Reader on the workspace in addition to the Microsoft Sentinel
Contributor role used for the upload. Microsoft Sentinel Contributor is not sufficient on its own: it grants
Microsoft.OperationalInsights/workspaces/*/read, and an Azure RBAC wildcard of that shape does not
cover the bare Microsoft.OperationalInsights/workspaces/read action this connection performs, so the
query fails with AuthorizationFailed.
When a record carries ip_addresses, every address is appended to the same indicator's
pattern as its own observation expression — ipv4-addr:value or ipv6-addr:value, chosen per
address — so the indicator covers the URL/hash and its resolved IPs under one validity window.
Only the first 10 addresses of a record are included; any beyond that are dropped.
Microsoft Sentinel expands a multi-observation pattern into one ObservableKey/ObservableValue row per
observable, so those IPs are independently matchable. Note that CDN-fronted hosts resolve to
shared edge addresses, which can produce false positives if you match on IP alone.
| Parameter | Required | Default | Description |
|---|---|---|---|
PlaybookName |
no | PRODAFTUstaIoC-ImportMalwareHashes |
Logic App name. |
UstaBaseUrl |
no | https://usta.prodaft.com |
USTA API base URL. |
UstaApiKey |
yes | — | USTA long-lived API key (secured). |
WorkspaceName |
yes | — | Name of the Microsoft Sentinel (Log Analytics) workspace that indicators are uploaded to. |
WorkspaceResourceGroup |
no | resource group of the deployment | Resource group of the workspace, if it differs from where the playbook is deployed. |
LookBackHours |
no | 2 |
First-run / fallback look-back window (hours), used only until the first indicator is imported (empty watermark). Afterwards each run resumes from the import watermark. |
UstaApiKey and WorkspaceName. (Or Automation → Create → Playbook, then deploy this azuredeploy.json.)AuthorizationFailed). Open IAM on the workspace itself, not on the Logic App — granting the role while the playbook's own blade is open scopes it to the Logic App (.../Microsoft.Logic/workflows/...), which looks correct in the portal but gives the identity no access to the workspace.# ---- configuration ----
SUB="<subscription-id>"
RG="<resource-group>" # resource group of the Microsoft Sentinel workspace
WS="<workspace-name>" # Log Analytics workspace name
USTA_API_KEY="<usta-api-key>"
PLAYBOOK="PRODAFTUstaIoC-ImportMalwareHashes"
az account set --subscription "$SUB"
# 1. Deploy the playbook and capture its managed-identity principalId
PRINCIPAL_ID=$(az deployment group create \
--resource-group "$RG" \
--template-file azuredeploy.json \
--parameters PlaybookName="$PLAYBOOK" \
*[Content truncated...]*
---
**Browse:** [🏠](../README.md) · [Solutions](../solutions-index.md) · [Connectors](../connectors-index.md) · [Methods](../methods-index.md) · [Tables](../tables-index.md) · [Content](../content/content-index.md) · [Parsers](../parsers/parsers-index.md) · [ASIM Parsers](../asim/asim-index.md) · [ASIM Products](../asim/asim-products-index.md) · [Logic Apps](../logic-apps/logic-apps-index.md) · [📊](../statistics.md)
↑ [Back to Playbooks](playbooks.md) · [Back to PRODAFT USTA - IoC Threat Intelligence](../solutions/prodaft-usta-ioc-threat-intelligence.md)