Joe Sandbox for Microsoft Sentinel

Solution: JoeSandbox

JoeSandbox Logo

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Solutions Index


Attribute Value
Publisher Stefan Bühlmann
Support Tier Partner
Support Link https://www.joesecurity.org/support
Categories domains
Version 3.0.0
Author Stefan Bühlmann
First Published 2025-09-12
Last Updated 2026-02-18
Solution Folder JoeSandbox
Marketplace Azure Marketplace · Popularity: ⚪ Very Low (0%)

The JoeSandbox Connector for Microsoft Sentinel enhances security operations by providing enriched threat intelligence, enabling faster and more informed responses to security incidents. The integration has two main parts: first, URL detonation and enrichment, which provides detailed insights into suspicious URLs. Second, it automatically generates and feeds threat intelligence for all submissions to JoeSandbox, improving threat detection and incident response in Sentinel. This seamless integration empowers teams to proactively address emerging threats.

Contents

Data Connectors

This solution provides 1 data connector(s):

Tables Used

This solution uses 1 table(s):

Table Used By Connectors Used By Content
ThreatIntelligenceIndicator JoeSandboxThreatIntelligence -

Content Items

This solution includes 2 content item(s):

Content Type Count
Playbooks 2

Playbooks

Name Description Tables Used
JoeSandbox File Analyis Submits a attachment or set of attachment associated with an office 365 email to JoeSandbox for Anal... -
JoeSandbox URL Analyis Submits a url or set of urls associated with an incident to JoeSandbox for Analyis. -

Additional Documentation

📄 Source: JoeSandbox/README.md

JoeSandbox Threat Intelligence Feed and Enrichment Integration - Microsoft Sentinel

Latest Version: 1.0.0 - Release Date: 15/09/2025

Overview

Requirements

Microsoft Sentinel

Creating Application for API Access

01

02a

02

03

app_per

10

11

Provide Permission To App Created Above

[Content truncated...]

Release Notes

Version Date Modified (DD-MM-YYYY) Change History
3.0.0 13-02-2026 Initial Solution Release.
Removed Manual Deployment Steps.

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Solutions Index