Darktrace for Microsoft Sentinel

Solution: Darktrace

Darktrace Logo

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Solutions Index


Attribute Value
Publisher Darktrace
Support Tier Partner
Support Link https://www.darktrace.com/contact/
Categories Security - Threat Protection
Version 3.0.0
Author Darktrace - customers@darktrace.com
First Published 2022-05-02
Last Updated 2026-06-18
Solution Folder Darktrace
Marketplace Azure Marketplace · Popularity: 🟢 High (83%)

The Darktrace Microsoft Sentinel Solution lets users connect Darktrace AI-based alerting in real-time with Microsoft Sentinel, allowing creation of custom Dashboards, Workbooks, Notebooks and Custom Alerts to improve investigation. Microsoft Sentinel's enhanced visibility into Darktrace logs enables monitoring and mitigation of security threats.

Underlying Microsoft Technologies used:

This solution takes a dependency on the following technologies, and some of these dependencies either may be in Preview state or might result in additional ingestion or operational costs:

a. Microsoft Sentinel Data Collector API

For more details about this solution refer to https://www.darktrace.com/microsoft/sentinel/

Contents

Data Connectors

This solution provides 2 data connector(s):

🔶 CLv1: This connector ingests into a table that uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g. _s, _d, _b, _t, _g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.

Tables Used

This solution uses 7 table(s):

Table Used By Connectors Used By Content
DarktraceASM_CL Darktrace ActiveAI Security Platform Connector Workbooks
DarktraceEMAIL_CL Darktrace ActiveAI Security Platform Connector Workbooks
DarktraceIncidents_CL Darktrace ActiveAI Security Platform Connector Analytics, Workbooks
DarktraceModelAlerts_CL Darktrace ActiveAI Security Platform Connector Analytics, Workbooks
DarktraceResponseActions_CL Darktrace ActiveAI Security Platform Connector Workbooks
DarktraceSystemStatusAlerts_CL Darktrace ActiveAI Security Platform Connector Workbooks
darktrace_model_alerts_CL 🔶 Darktrace Connector for Microsoft Sentinel REST API (Legacy) Analytics, Workbooks

🔶 CLv1: This table uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g. _s, _d, _b, _t, _g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.

Content Items

This solution includes 7 content item(s):

Content Type Count
Analytic Rules 5
Workbooks 2

Analytic Rules

Name Severity Tactics Tables Used
Darktrace AI Analyst (Legacy) High InitialAccess, Execution, LateralMovement, CommandAndControl darktrace_model_alerts_CL
Darktrace Incident Event High InitialAccess, Execution, LateralMovement, CommandAndControl DarktraceIncidents_CL
Darktrace Model Alert High InitialAccess, Execution, LateralMovement, CommandAndControl DarktraceModelAlerts_CL
Darktrace Model Breach (Legacy) Medium InitialAccess, Execution, LateralMovement, CommandAndControl darktrace_model_alerts_CL
Darktrace System Status (Legacy) Informational Discovery, Impact darktrace_model_alerts_CL

Workbooks

Name Tables Used
DarktraceActiveAISecurityPlatformWorkbook DarktraceASM_CL
DarktraceEMAIL_CL
DarktraceIncidents_CL
DarktraceModelAlerts_CL
DarktraceResponseActions_CL
DarktraceSystemStatusAlerts_CL
DarktraceWorkbook darktrace_model_alerts_CL

Release Notes

Version Date Modified (DD-MM-YYYY) Change History
3.1.1 30-06-2026 Fixed link to Darktrace set up guide
3.1.0 17-06-2026 Added modelBreaches and accountName to DarktraceIncidents_CL, accountName to DarktraceModelAlerts_CL. Updated analytic rules with Account entity mapping for SaaS/identity correlation.
3.0.0 06-03-2026 Added new Darktrace ActiveAI Security Platform CCF data connector, DCR, custom tables, workbook, and two new analytic rules; relabeled legacy REST API connector, workbook, and analytic rules as (Legacy)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Solutions Index