⚠️ Datazag

⚠️ Unpublished: This item is from a solution that is not yet published on Azure Marketplace or not installed in Content Hub.

Datazag Logo

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Solutions Index


Attribute Value
Publisher Datazag
Support Tier Partner
Support Link https://datazag.com/support
Categories Security - Threat Intelligence
Version 3.0.0
Author Datazag - support@datazag.com
First Published 2026-08-06
Last Updated 2026-08-06
Solution Folder Datazag

The Datazag solution for Microsoft Sentinel delivers brand impersonation, platform impersonation and attacker-infrastructure indicators derived from Certificate Transparency, published as STIX 2.1 objects over a TAXII 2.1 server.\n\nIndicators are ingested using Microsoft Sentinel's built-in Threat Intelligence - TAXII data connector and land in the native ThreatIntelIndicators table. No custom table, data collection rule or workspace function is required, and indicators are available to analytic rules and hunting queries immediately. Because indicators are retained in the workspace, existing logs can also be retro-hunted against them. Datazag never queries your workspace: delivery is pull-only, on a schedule you control.\n\nBefore you install\n\nYou need an active Datazag subscription. Contact support@datazag.com to obtain the username and password for your organisation, quoting the collections your subscription includes.\n\nConnecting the feed\n\nIn the Microsoft Defender portal, go to Microsoft Sentinel > Configuration > Data connectors, open Threat Intelligence - TAXII, select Open connector page, then Add. Enter a friendly name of your choosing, the API root URL and collection ID below, and the credentials issued by Datazag. A polling frequency of once an hour is recommended. Repeat for each collection your subscription includes; each is a separate TAXII server entry.\n\nAPI root URL: https://taxii.datazag.com/api/\n\n| Collection | ID |\n|---|---|\n| Platform impersonation | c7ad8fef-c704-4b36-9526-5d7c3bd018c4 |\n| Attacker infrastructure | eedf8709-5e4f-4ed4-b840-5eaafa236b70 |\n\nBrand impersonation collections are issued per organisation; Datazag will supply your collection ID with your credentials.\n\nPrerequisites\n\na. An active Datazag subscription and TAXII credentials, as above.\n\nb. The analytic rule and hunting query in this solution match indicators against DNS activity through the Advanced Security Information Model (ASIM). The ASIM DNS parsers must be deployed and the workspace must be receiving DNS telemetry for this content to return results.\n\nContent in this solution identifies Datazag indicators by their STIX created_by_ref rather than by SourceSystem, because SourceSystem reflects the friendly name you choose when adding the TAXII server.

Contents

Data Connectors

This solution does not include data connectors.

This solution may contain other components such as analytics rules, workbooks, hunting queries, or playbooks.

Internal Tables

The following 1 table(s) are used internally by this solution's content items:

Table Used By Content
ThreatIntelIndicators Analytics, Hunting

Content Items

This solution includes 2 content item(s):

Content Type Count
Analytic Rules 1
Hunting Queries 1

Analytic Rules

Name Severity Tactics Tables Used
Datazag - impersonation domain resolved in DNS High InitialAccess, CommandAndControl Internal use:
ThreatIntelIndicators

Hunting Queries

Name Tactics Tables Used
Datazag - retro-hunt historical DNS against impersonation indicators InitialAccess, CommandAndControl Internal use:
ThreatIntelIndicators

Release Notes

Version Date Modified (DD-MM-YYYY) Change History
3.0.0 27-08-2026 Initial Datazag Threat Intelligence solution release.

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Solutions Index