Infoblox App for Microsoft Sentinel

Solution: Infoblox

Infoblox Logo

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Solutions Index


Attribute Value
Publisher Infoblox
Support Tier Partner
Support Link https://support.infoblox.com/
Categories Networking,Security - Threat Intelligence,Security - Threat Protection,Security - Network
Version 3.1.2
Author Infoblox
First Published 2024-07-15
Last Updated 2026-09-04
Solution Folder Infoblox
Marketplace Azure Marketplace · Popularity: 🟢 High (80%)

The Infoblox Solution for Microsoft Sentinel is designed to enhance the capabilities of Security Operations Centers (SOC) by integrating actionable intelligence and contextual network data derived from DNS data into Microsoft Sentinel. This integration provides SOC analysts with the tools they need to quickly identify and respond to potential threats such as malware and data exfiltration, improving overall security posture. With seamless configuration and intuitive dashboards, the solution ensures that critical security events are monitored and correlated, offering actionable insights that streamline threat detection and response. SOC analysts will benefit from the app’s ability to provide contextual network data, including user and device attribution, through various lookups and visualizations. By leveraging unique DNS-based threat intelligence, audit logs and other data sources, analysts can conduct faster and more effective investigations. The solution’s functionalities, such as IQ for TD Insights Overview and DNS Events, empower analysts to reduce alert fatigue by focusing on correlated events, ultimately leading to improved efficiency and protection against emerging threats.

Benefits

  1. Reduce alert fatigue with actionable insights through IQ for TD Insights: Focus on the most critical alerts and insights to streamline threat detection and response.
  2. Faster investigations with contextual network data: Quickly correlate network activities with potential threats using detailed lookups and visualizations.
  3. Unique DNS-based Infoblox Threat Intel: Access unparalleled DNS-based threat intelligence to enhance security decision-making and threat mitigation.

Contents

Data Connectors

This solution provides 5 data connector(s):

Tables Used

This solution uses 24 table(s):

Table Used By Connectors Used By Content
CommonSecurityLog [Deprecated] Infoblox SOC Insight Data Connector via Legacy Agent, [Recommended] Infoblox Cloud Data Connector via AMA, [Recommended] Infoblox IQ for Threat Defense Insight Data Connector via AMA Analytics, Playbooks, Workbooks
Host_Name_Info_CL 🔶 - Workbooks
IP_Space_Info_CL 🔶 - Workbooks
Infoblox_Config_Insight_Details_CL 🔶 - Workbooks
Infoblox_Config_Insights_CL 🔶 - Workbooks
Service_Name_Info_CL 🔶 - Workbooks
ThreatIntelObjects Infoblox Data Connector via REST API -
ThreatIntelligenceIndicator - Workbooks
dossier_atp_CL - Workbooks
dossier_atp_threat_CL - Workbooks
dossier_dns_CL - Workbooks
dossier_geo_CL - Workbooks
dossier_infoblox_web_cat_CL - Workbooks
dossier_inforank_CL - Workbooks
dossier_malware_analysis_v3_CL - Workbooks
dossier_nameserver_CL - Workbooks
dossier_nameserver_matches_CL - Workbooks
dossier_ptr_CL - Workbooks
dossier_rpz_feeds_CL - Workbooks
dossier_rpz_feeds_records_CL - Workbooks
dossier_threat_actor_CL - Workbooks
dossier_tld_risk_CL - Workbooks
dossier_whitelist_CL - Workbooks
dossier_whois_CL - Workbooks

Internal Tables

The following 8 table(s) are used internally by this solution's content items:

Table Used By Connectors Used By Content
InfobloxInsightAssets_CL - Workbooks
InfobloxInsightEvents_CL - Workbooks
InfobloxInsightIndicators_CL - Workbooks
InfobloxInsight_CL Infoblox IQ for Threat Defense Insight Data Connector via REST API Analytics, Workbooks
SecurityAlert - Workbooks
SecurityIncident - Workbooks
ThreatIntelIndicators Infoblox Data Connector via REST API -
tide_lookup_data_CL 🔶 - Playbooks (writes), Workbooks

🔶 CLv1: This table uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g. _s, _d, _b, _t, _g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.

Content Items

This solution includes 27 content item(s):

Content Type Count
Playbooks 18
Parsers 5
Analytic Rules 2
Workbooks 2

Analytic Rules

Name Severity Tactics Tables Used
Infoblox - IQ for TD Detected Insights - API Source Medium Impact Internal use:
InfobloxInsight_CL
Infoblox - IQ for TD Insight Detected - CDC Source Medium Impact CommonSecurityLog

Workbooks

Name Tables Used
Infoblox_Lookup_Workbook dossier_atp_CL
dossier_atp_threat_CL
dossier_dns_CL
dossier_geo_CL
dossier_infoblox_web_cat_CL
dossier_inforank_CL
dossier_malware_analysis_v3_CL
dossier_nameserver_CL
dossier_nameserver_matches_CL
dossier_ptr_CL
dossier_rpz_feeds_CL
dossier_rpz_feeds_records_CL
dossier_threat_actor_CL
dossier_tld_risk_CL
dossier_whitelist_CL
dossier_whois_CL
Internal use:
SecurityAlert
SecurityIncident
tide_lookup_data_CL
Infoblox_Workbook CommonSecurityLog
Host_Name_Info_CL
IP_Space_Info_CL
Infoblox_Config_Insight_Details_CL
Infoblox_Config_Insights_CL
Service_Name_Info_CL
ThreatIntelligenceIndicator
Internal use:
InfobloxInsightAssets_CL
InfobloxInsightEvents_CL
InfobloxInsightIndicators_CL
InfobloxInsight_CL
SecurityAlert
SecurityIncident

Playbooks

Name Description Tables Used
Infoblox-Block-Allow-IP-Domain The playbook will add/remove IP or Domain value in Named List of Infoblox. -
Infoblox-Block-Allow-IP-Domain-Incident-Based The playbook will add / remove IP or Domain values in Named List that available in incidents of Info... -
Infoblox-Config-Insight-Details The playbook retrieves Config Insight Details Data and ingests it into a custom table within the Log... -
Infoblox-Config-Insights The playbook retrieves Config Insight Data and ingests it into a custom table within the Log Analyti... -
Infoblox-DHCP-Lookup The playbook will retrieve IP entities from an incident, search for related DHCP data in a table, an... CommonSecurityLog (read)
Infoblox-Data-Connector-Trigger-Sync Playbook to sync timer trigger of all Infoblox data connectors. -
Infoblox-Get-Host-Name The playbook will fetch the data from 'Hosts' API and ingest it into custom table -
Infoblox-Get-IP-Space-Data The playbook will fetch the data from 'IP Space' API and ingest it into custom table -
Infoblox-Get-Service-Name This playbook will fetch the data from 'Services' API and ingest it into custom table -
Infoblox-IPAM-Lookup The playbook will retrieve IP entities from an incident, call an API to obtain IPAM lookup data, and... -
Infoblox-IQ-for-TD-Get-Insight-Details-API Leverages the Infoblox IQ for TD API to enrich a Microsoft Sentinel Incident triggered by an Infoblo... -
Infoblox-IQ-for-TD-Get-Insights-API Leverages the Infoblox IQ for Threat Defense Insights API to ingest IQ for TD Insights at time of ru... -
Infoblox-IQ-for-TD-Import-Indicators-TI Imports each Indicator of a Microsoft Sentinel Incident triggered by an Infoblox IQ for TD Insight i... -
Infoblox-IQ-for-TD-Take-Action-API Leverages the Infoblox IQ for Threat Defense Insights API to take action on an Insight by applying t... -
Infoblox-TIDE-Lookup The playbook fetches TIDE lookup data for the provided entity type and value. Internal use:
tide_lookup_data_CL (read/write)
Infoblox-TIDE-Lookup-Comment-Enrichment The playbook enrich an incident by adding TIDE Lookup information as comment on an incident. -
Infoblox-TIDE-Lookup-Via-Incident The playbook takes entity type and value from incident available in Workbook and ingests TIDE Lookup... -
Infoblox-TimeRangeBased-DHCP-Lookup The playbook will retrieve IP entities from an incident, search for related DHCP data in a table for... -

Parsers

Name Description Tables Used
InfobloxCDC_SOCInsights - CommonSecurityLog (read)
InfobloxInsight - Internal use:
InfobloxInsight_CL (read)
InfobloxInsightAssets - Internal use:
InfobloxInsightAssets_CL (read)
InfobloxInsightEvents - Internal use:
InfobloxInsightEvents_CL (read)
InfobloxInsightIndicators - Internal use:
InfobloxInsightIndicators_CL (read)

Release Notes

Version Date Modified (DD-MM-YYYY) Change History
3.1.2 01-09-2026 Migrated Dossier data ingestion in InfobloxCloudDataConnector to the Log Ingestion API (DCE/DCR) and updated the Data Connector UI page.
3.1.1 26-08-2026 Protected Infoblox API keys using secure workflow parameters and secured HTTP action inputs and outputs.
3.1.0 17-07-2026 Updated playbooks, parsers, workbooks and analytic rule from SOC insight v1 to Infoblox for IQ for Threat Defense (SOC insight v2).
3.0.2 19-06-2025 Added flags for Asset, Indicator, Event and Comment in InfobloxSOCGetInsightDetails playbook. Updated Workbook, Parser and Analytic rule.
Migrated checkpoint from file share to azure tables.
3.0.1 07-11-2024 Bug fix in Infoblox_Workbook Workbook
3.0.0 15-07-2024 Initial Solution Release

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Solutions Index