RecordedFuture-ImportToDefenderEndpoint (DEPRECATED)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


DEPRECATED: This playbook is no longer functional. Microsoft has deprecated the Graph Security tiIndicators API that this playbook relies on. Do not deploy this playbook. This playbook previously leveraged Recorded Future API and automatically imported the Command and Control IPs and Weaponized Domains Security Control Feeds, as Threat Intelligence Indicators, for prevention purposes in Microsoft Defender for Endpoint.

Attribute Value
Type Playbook
Solution Standalone Content
Source View on GitHub

Logic App Connectors

This playbook uses 1 Logic App connector / built-in action:

Connector / Action Type Connections Actions
microsoftgraphsecurity Managed 1 1
Action parameters (URLs, paths, function IDs)

microsoftgraphsecurity (Managed)

Action Method Endpoint Other
Submit_multiple_tiIndicators post /beta/security/tiIndicators/submitTiIndicators

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Playbooks