Cynerio Medical Device Security Sentinel Connector

Solution: Cynerio

Cynerio Logo

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Solutions Index


Attribute Value
Publisher Cynerio
Support Tier Partner
Support Link https://cynerio.com
Categories domains
Version 3.0.0
Author micha@cynerio.co
First Published 2023-03-29
Last Updated 2023-03-29
Solution Folder Cynerio
Marketplace Azure Marketplace · Rating: ★★★★★ 5.0/5 (1 ratings) · Popularity: ⚪ Very Low (0%)

The Cynerio solution for Microsoft Sentinel enables you to ingest Cynerio Security Events to the Microsoft Sentinel platform, providing more insight into your organization network security posture and improving your security operation capabilities.

Contents

Data Connectors

This solution provides 1 data connector(s):

🔶 CLv1: This connector ingests into a table that uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g. _s, _d, _b, _t, _g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.

Tables Used

This solution uses 1 table(s):

Table Used By Connectors Used By Content
CynerioEvent_CL 🔶 Cynerio Security Events Analytics, Workbooks

🔶 CLv1: This table uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g. _s, _d, _b, _t, _g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.

Content Items

This solution includes 8 content item(s) (6 in solution, 2 discovered 🔍):

Content Type Total In Solution Discovered
Analytic Rules 5 5 -
Parsers 2 0 2
Workbooks 1 1 -

Analytic Rules

Name Severity Tactics Tables Used
Cynerio - Exploitation Attempt of IoT device High LateralMovement CynerioEvent_CL
Cynerio - IoT - Default password High CredentialAccess CynerioEvent_CL
Cynerio - IoT - Weak password High CredentialAccess CynerioEvent_CL
Cynerio - Medical device scanning Medium LateralMovement CynerioEvent_CL
Cynerio - Suspicious Connection to External Address High LateralMovement CynerioEvent_CL

Workbooks

Name Tables Used
CynerioOverviewWorkbook CynerioEvent_CL

Parsers

Name Description Tables Used
CynerioEvent_Authentication ⚠️ - CynerioEvent_CL (read)
CynerioEvent_NetworkSession ⚠️ - CynerioEvent_CL (read)

⚠️ Items marked with ⚠️ are not listed in the Solution JSON file. They were discovered by scanning the solution folder and may be legacy items, under development, or excluded from the official solution package.

Release Notes

Version Date Modified (DD-MM-YYYY) Change History
3.0.0 11-07-2023 New analytic rules and workbook
2.0.0 29-03-2023 Initial Solution Release

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Solutions Index