URL Trigger Entity Analyzer

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


This playbook is triggered manually when a URL entity is selected in a Microsoft Sentinel incident and provides detailed security insights including classification, analysis results, and recommendations.

Attribute Value
Type Playbook
Solution SentinelSOARessentials
Source View on GitHub

Logic App Connectors

This playbook uses 2 Logic App connectors / built-in actions:

Connector / Action Type Connections Actions
azuresentinel Managed 1 1
sentinelmcp Managed 1 1
Action parameters (URLs, paths, function IDs)

azuresentinel (Managed)

Action Method Endpoint Other
Add_comment_to_incident_(V3) post /Incidents/Comment

sentinelmcp (Managed)

Action Method Endpoint Other
URL_Analyzer post /aiprimitives/analysis

Additional Documentation

📄 Source: Url-Trigger-Entity-Analyzer/readme.md

URL Entity Analyzer - Microsoft Sentinel Playbook

Activating the 'Deploy' button initiates the deployment of an Azure Logic App integrated with Microsoft Sentinel MCP Actions, utilizing a Microsoft Sentinel entity trigger. The Logic App is configured to run manually when a URL entity is selected in a Sentinel incident. This Logic App analyzes suspicious URLs and provides detailed security insights including classification, analysis results, and recommendations.

Deployment

Important Note: As of now, this playbook only works when triggered from the Microsoft Sentinel portal in Azure. It is not currently supported in the Defender portal.

The playbook can be manually triggered when:

After the analysis is complete, the MCP Entity Analyzer conducts a comprehensive investigation of the URL entity and automatically adds a detailed comment to the incident with:

Prerequisites

Prior to beginning the installation process, it's crucial to confirm that you have met the following prerequisites:

Parameters

During deployment, you'll need to provide:

Deployment

To deploy the URL Entity Analyzer Logic App:

  1. Press on the Deploy button below
  2. Select your subscription and resource group (use the same tenant where Microsoft Sentinel is configured)
  3. Provide the required Workspace ID parameter
  4. Configure the lookBackDays parameter if needed (default is 10 days)

Deploy to Azure Deploy to Azure Gov

Post Deployment

After successful deployment:

Logic App Designer

How to Run the Playbook

To manually trigger the URL Entity Analyzer:

  1. Navigate to Microsoft Sentinel in the Azure portal
  2. Go to Incidents and open an incident containing URL entities
  3. Click on the Entities tab
  4. Select a URL entity from the list
  5. Click on Run playbook button in the top right
  6. Select Entity-analyzer-Url-Trigger from the playbook list
  7. The analysis will run and results will be added as a comment to the incident

Run Playbook

How It Works

  1. Manual Trigger: The Logic App is manually triggered when a security analyst selects a URL entity in a Sentinel incident and runs the playbook
  2. Analysis: The URL is sent to Microsoft Sentinel's MCP Entity Analyzer for comprehensive analysis using the SentinelMCP connector

[Content truncated...]


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Playbooks · Back to SentinelSOARessentials