Uniqkey Security Events for Microsoft Sentinel

Solution: Uniqkey

Uniqkey Logo

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Solutions Index


Attribute Value
Publisher Uniqkey
Support Tier Partner
Support Link https://uniqkey.eu/
Categories Identity,Security - Others
Version 3.0.0
Author Uniqkey - support@uniqkey.eu
First Published 2026-08-25
Last Updated 2026-09-01
Solution Folder Uniqkey
Marketplace Azure Marketplace · Popularity: 🟢 High (84%)

The Uniqkey solution for Microsoft Sentinel enables ingestion of security and audit events from the Uniqkey business password management platform. Events cover authentication, credential access, credential management, sharing, policy management, threat detection and other administrative activity, giving security teams visibility into password and access hygiene across the organization.

Underlying Microsoft Technologies used:

This solution takes a dependency on the following technologies, and some of these dependencies either may be in Preview state or might result in additional ingestion or operational costs:

a. Microsoft Sentinel Codeless Connector Framework

Contents

Data Connectors

This solution provides 1 data connector(s):

Tables Used

This solution uses 1 table(s):

Table Used By Connectors Used By Content
UniqkeyEvents_CL Uniqkey Security Events Analytics, Workbooks

Content Items

This solution includes 10 content item(s):

Content Type Count
Analytic Rules 9
Workbooks 1

Analytic Rules

Name Severity Tactics Tables Used
Uniqkey - Credential export from newly created account Medium CredentialAccess, Persistence UniqkeyEvents_CL
Uniqkey - Data export activity Medium CredentialAccess, Exfiltration UniqkeyEvents_CL
Uniqkey - Departing employee credential export High CredentialAccess, Exfiltration UniqkeyEvents_CL
Uniqkey - Event ingestion stopped Medium DefenseEvasion UniqkeyEvents_CL
Uniqkey - Excessive credential access Medium CredentialAccess UniqkeyEvents_CL
Uniqkey - Platform threat detection High InitialAccess, CredentialAccess UniqkeyEvents_CL
Uniqkey - Security policy change Medium DefenseEvasion, Persistence UniqkeyEvents_CL
Uniqkey - Self-granted privilege or access change Medium PrivilegeEscalation, Persistence UniqkeyEvents_CL
Uniqkey - Sign-in from unfamiliar IP address Low InitialAccess UniqkeyEvents_CL

Workbooks

Name Tables Used
Uniqkey UniqkeyEvents_CL

Additional Documentation

📄 Source: Uniqkey/README.md

This solution ingests security and audit events from the Uniqkey business password management platform into Microsoft Sentinel using the Codeless Connector Framework (CCF).

Contents

Component Path Purpose
Connector definition Data Connectors/UniqkeyAuditLogs_ccf/Uniqkey_ConnectorDefinition.json Connector page UI in the Sentinel portal
Poller config Data Connectors/UniqkeyAuditLogs_ccf/Uniqkey_PollerConfig.json REST API polling (bearer auth, cursor paging, time windows)
Data collection rule Data Connectors/UniqkeyAuditLogs_ccf/Uniqkey_DCR.json Raw event to UniqkeyEvents_CL schema transformation
Table schema Data Connectors/UniqkeyAuditLogs_ccf/Uniqkey_Table.json Custom table UniqkeyEvents_CL
Packaging manifest Data/Solution_Uniqkey.json Input for the V3 packaging tool
Analytic rules Analytic Rules/*.yaml 9 scheduled detections (anomalous sign-in, export/exfiltration patterns, insider privilege escalation, policy changes, platform threat detections, ingestion health)
Workbook Workbooks/Uniqkey.json Uniqkey Security Events dashboard (volume, sign-in map, client systems, top users, exports, threat detections)

Open items before PR submission

Build & validate

pwsh .script/local-validation/build-and-validate.ps1 -SolutionName "Uniqkey"

Release Notes

Version Date Modified (DD-MM-YYYY) Change History
3.0.0 25-08-2026 Initial release of the Uniqkey solution with a CCF data connector for Uniqkey security events

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Solutions Index