Solution: Darktrace
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
| Attribute | Value |
|---|---|
| Publisher | Darktrace |
| Support Tier | Partner |
| Support Link | https://www.darktrace.com/en/contact/ |
| Categories | domains |
| Version | 2.0.1 |
| Author | Darktrace |
| First Published | 2022-05-02 |
| Solution Folder | Darktrace |
| Marketplace | Azure Marketplace · Popularity: 🟢 High (85%) |
The Darktrace Sentinel Solution lets users connect Darktrace AI-based alerting in real-time with Microsoft Sentinel, allowing creation of custom Dashboards, Workbooks, Notebooks and Custom Alerts to improve investigation. Microsoft Sentinel's enhanced visibility into Darktrace logs enables monitoring and mitigation of security threats.
Underlying Microsoft Technologies used:
This solution takes a dependency on the following technologies, and some of these dependencies either may be in Preview state or might result in additional ingestion or operational costs:
a. Microsoft Sentinel Data Collector API
For more details about this solution refer to https://www.darktrace.com/microsoft/sentinel/
This solution provides 1 data connector(s):
🔶 CLv1: This connector ingests into a table that uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g.
_s,_d,_b,_t,_g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.
This solution uses 1 table(s):
| Table | Used By Connectors | Used By Content |
|---|---|---|
darktrace_model_alerts_CL 🔶 |
Darktrace Connector for Microsoft Sentinel REST API | Analytics, Workbooks |
🔶 CLv1: This table uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g.
_s,_d,_b,_t,_g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.
This solution includes 4 content item(s):
| Content Type | Count |
|---|---|
| Analytic Rules | 3 |
| Workbooks | 1 |
| Name | Severity | Tactics | Tables Used |
|---|---|---|---|
| Darktrace AI Analyst | High | - | darktrace_model_alerts_CL |
| Darktrace Model Breach | Medium | - | darktrace_model_alerts_CL |
| Darktrace System Status | Informational | - | darktrace_model_alerts_CL |
| Name | Tables Used |
|---|---|
| DarktraceWorkbook | darktrace_model_alerts_CL |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊