Intel 471 Threat Intelligence
Solution: Intel471
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
↑ Back to Solutions Index
| Attribute |
Value |
| Publisher |
Intel 471 |
| Support Tier |
Partner |
| Support Link |
https://intel471.com/company/contact |
| Categories |
Security - Threat Protection |
| Version |
3.0.1 |
| Author |
Intel 471 Inc. |
| First Published |
2023-06-21 |
| Last Updated |
2026-09-02 |
| Solution Folder |
Intel471 |
| Marketplace |
Azure Marketplace · Popularity: 🔵 Medium (74%) |
The Intel 471 solution for Microsoft Sentinel ingests malware indicators from Intel 471's Verity 471 or Titan API into the Log Analytics workspace, and provides a curated set of community hunting queries to proactively hunt for threats in Microsoft Sentinel.
Contents
Data Connectors
This solution does not include data connectors.
This solution may contain other components such as analytics rules, workbooks, hunting queries, or playbooks.
Tables Used
This solution queries 4 table(s) from its content items:
Content Items
This solution includes 26 content item(s):
| Content Type |
Count |
| Hunting Queries |
25 |
| Playbooks |
1 |
Hunting Queries
| Name |
Tactics |
Tables Used |
| AWS Identity and Access Management (IAM) Discovery |
Discovery |
AWSCloudTrail |
| AnyDesk Execution from Abnormal Folder - Potential Malicious Use of RMM Tool |
CommandAndControl |
SecurityEvent |
| AnyDesk Service Installation - Potentially Malicious RMM Tool Installation |
CommandAndControl, Persistence, PrivilegeEscalation |
Event |
| Autorun or ASEP Registry Key Modification |
Persistence, PrivilegeEscalation |
SecurityEvent |
| Browser Spawning Suspicious Applications - Potential Exploit or Social Engineering |
DefenseEvasion, Execution |
SecurityEvent |
| Creating a Shadow Copy |
Collection, CredentialAccess |
SecurityEvent |
| Dump LSASS via Renamed procdump |
CredentialAccess |
SecurityEvent |
| Execution BAT Script to Unpack Payload |
DefenseEvasion |
SecurityEvent |
| File Created In Startup Folder |
Persistence, PrivilegeEscalation |
SecurityEvent |
| Java Spawning Child Process by Unique Child Process Name - Potential Exploitation Activity |
DefenseEvasion, InitialAccess |
SecurityEvent |
| MeshAgent Suspicious Child Process - Potential Malicious RMM Tool Usage |
CommandAndControl, Execution |
SecurityEvent |
| Methods for Downloading Files with PowerShell |
CommandAndControl, Execution |
SecurityEvent |
| NetSupport Manager Execution from Abnormal Folder - Potential Malicious Use of RMM Tool |
CommandAndControl |
SecurityEvent |
| Potential Maldoc Execution Chain Observed |
Execution, InitialAccess |
SecurityEvent |
| PowerShell Encoded Command Execution |
DefenseEvasion, Execution |
DeviceEvents
SecurityEvent |
| Powershell History Modification or Deletion |
DefenseEvasion |
SecurityEvent |
| Python Executing from Non-Standard Directory |
Execution |
SecurityEvent |
| Remote Atera Agent Download - Command Line |
CommandAndControl, Execution |
SecurityEvent |
| Scheduled Task Executing from Abnormal Location |
Execution, Persistence, PrivilegeEscalation |
SecurityEvent |
| Shadow Copies Deletion Using Operating Systems Utilities |
Impact |
SecurityEvent |
| Suspect Child Process to IIS Worker Process (w3wp.exe) - Potential Exploitation |
InitialAccess, LateralMovement |
SecurityEvent |
| Suspicious Child Process for Java - Potential Exploitation Activity |
DefenseEvasion, InitialAccess |
SecurityEvent |
| User Added to Default Privileged Windows Security Groups |
DefenseEvasion, InitialAccess, Persistence, PrivilegeEscalation |
SecurityEvent |
| WMIC Windows Internal Discovery and Enumeration |
Discovery, Execution |
SecurityEvent |
| Wevtutil Cleared Log |
DefenseEvasion |
SecurityEvent |
Playbooks
Release Notes
| Version |
Date Modified (DD-MM-YYYY) |
Change History |
| 3.0.1 |
28-08-2026 |
Added 25 Hunting Queries. Updated Playbook 'Intel 471 Malware Intelligence to Sentinel' to v3.0: Key Vault secret names can now be supplied at deployment, and Blob storage now authenticates with the logic app's managed identity - grant it the Storage Blob Data Contributor role or every run fails. |
| 3.0.0 |
02-12-2025 |
Added the Verity 471 backend alongside Titan, and switched indicator ingestion to the Threat Intelligence Upload Indicators API. |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
↑ Back to Solutions Index