⚠️ Unpublished: This item is from a solution that is not yet published on Azure Marketplace or not installed in Content Hub.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Publisher | Cybereinforce Support |
| Support Tier | Partner |
| Support Link | https://cybereinforce.com/support.html |
| Categories | Security - Threat Intelligence |
| Version | 3.0.0 |
| Author | Cybeurope - support@cybeurope.com |
| First Published | 2026-08-11 |
| Last Updated | 2026-08-12 |
| Solution Folder | Cybereinforce |
The Cybereinforce Threat Enforcement solution for Microsoft Sentinel ingests browser-level URL blocking, threat-intelligence match, and audit/administration events via a scheduled Logic App and the Azure Monitor Logs Ingestion API. It includes a data connector with deployment instructions, a workbook for SOC operational visibility, and analytics rules covering URL enforcement, threat-intel matches, device risk patterns, and license/capacity health.
This solution provides 1 data connector(s):
This solution uses 1 table(s):
| Table | Used By Connectors | Used By Content |
|---|---|---|
CybereinforceCTE_CL |
Cybereinforce Threat Enforcement (CTE) | Analytics, Workbooks |
This solution includes 20 content item(s) (19 in solution, 1 discovered 🔍):
| Content Type | Total | In Solution | Discovered |
|---|---|---|---|
| Analytic Rules | 18 | 18 | - |
| Workbooks | 2 | 1 | 1 |
| Name | Tables Used |
|---|---|
| CybereinforceCTE | CybereinforceCTE_CL |
| WorkbooksMetadata ⚠️ | - |
⚠️ Items marked with ⚠️ are not listed in the Solution JSON file. They were discovered by scanning the solution folder and may be legacy items, under development, or excluded from the official solution package.
📄 Source: Cybereinforce/README.md
Cybereinforce Threat Enforcement enforces Microsoft Defender threat intelligence directly at the browser (Chrome, Firefox, Safari) on enrolled endpoints, blocking access to known-malicious and policy-restricted URLs before they load.
This solution brings Cybereinforce's enforcement and audit activity into Microsoft Sentinel for SOC investigation, hunting, and alerting.
CybereinforceCTE_CL custom table via the Azure Monitor Logs Ingestion API.See SolutionMetadata.json for support contact details, or visit cybereinforce.com/support.html.
See ReleaseNotes.md for version history.
| Version | Date Modified (DD-MM-YYYY) | Change History |
|---|---|---|
| 3.0.0 | 14-08-2026 | Corrected solution package structure (content package registration), registered custom table schema for KQL validation, added MITRE ATT&CK tactics and techniques to the 11 attack-detection rules (the remaining 7 rules are operational/capacity alerts - license expiry, device/rule quota, enrollment on-hold - with no corresponding adversary technique, so left unmapped by design), added workbook preview images and logo. |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊