Canary alerts to incidents

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


Creates Microsoft Sentinel incidents from Thinkst Canary alerts.

Attribute Value
Type Analytic Rule
Solution ThinkstCanary
ID 06360572-94a7-42a4-add7-58fb933b2353
Severity High
Status Available
Kind NRT
Tactics LateralMovement, Exfiltration
Techniques T1021, T1041
Required Connectors ThinkstCanary
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
ThinkstCanaryIncidents_CL ? ✓ ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Analytic Rules · Back to ThinkstCanary