↳ Source GitHubConnecteur

Cyble Threat Intel

Description

The Cyble Threat Intel Alerts API connector pushes real-time alerts from Cyble to Microsoft Sentinel and is designed to be used with the Cyble Solution for Sentinel. The connector writes logs to a table titled **SecurityIncident**.
Statut déclaré
1
Auteur / éditeur déclaré
Cyble

Sources déclarées

Métadonnées du fichier source. Aucune dépendance déduite du KQL.

Types de données

Permissions déclarées

read and write permissions on the workspace are required.
Workspace
Workspace
Microsoft.Web/sites permissions
Read and write permissions to Azure Logic App to create a Azure Logic App is required. [See the documentation to learn more about Azure Logic App](https://learn.microsoft.com/azure/logic-apps/).
Cyble Alerts API Credentials and Endpoint
**Cyble Access Token**, **Cyble Endpoint** is required for Cyble Threat Intel Connector.
 Follow the instructions in [Cyble Vision Application](https://cyble.ai) to obtain them.

Instructions du connecteur

Contenu publié dans le dépôt. Consultez le fichier original pour l’ensemble des paramètres.

>**NOTE:** This connector operates to establish a connection with the Cyble Alerts API, enabling the retrieval of its logs for Microsoft Sentinel workspace. Pulling logs into Sentinel via logic app could lead to extra charges related to data ingestion. For a detailed understanding of these potential costs, it's advisable to consult the Azure logic app pricing page. Check the [Azure Logic App pricing page](https://azure.microsoft.com/pricing/details/logic-apps/) for details.
**STEP 1 - Configuration steps for the Cyble Threat Intel Connector** Follow the instructions in [Cyble Vision Application](https://cyble.ai) to obtain the Cyble Alerts API credentials.
**STEP 2 - Launch Azure Resource Manager (ARM) Template** Use this method for automated deployment of the Logic App using an ARM Template. Click the **Deploy to Azure** button below. [![Deploy To Azure](https://aka.ms/deploytoazurebutton)](https://aka.ms/sentinel-CybleLogicApp-playbook)
**STEP 3 - Fill the following information**
Enter the subscription name under which you intend to deploy the resources.
Subscription Name
Specify the resource group. If necessary, you can create a new resource group at this point. >**NOTE:** Within the same resource group, you can't mix Windows and Linux apps in the same region. Select existing resource group without Windows apps in it or create new resource group.
Resource Group
Specify the region where your resources will be located.
Region
Assign a name for the workflow.
Workflow Name
Specify the name for the organization's **Sentinel Log Analytics** workspace.
Workspace Name
Provide your unique access token for authentication.
Cyble Access Token
Specify the endpoint to establish the correct API endpoint.
Cyble Endpoint
Determine how often the workflow should run.
Frequency Minutes
**STEP 4 - Deploy your Resources** Mark the checkbox labeled **I agree to the terms and conditions stated above**. Click **Purchase** to deploy.

Traçabilité de la source

GitHub

Les valeurs affichées proviennent des fichiers du dépôt Azure/Azure-Sentinel. Elles décrivent le modèle publié, pas la configuration de votre workspace.

Identifiant source
CybleThreatIntel
Autres fichiers source 1DataConnectors/CybleLogicApp/Connector_LogicApp_Cyble.jsonsource ↗
GSTEP / SUIVI DU CATALOGUE

Ajouté au catalogue : 16 sept. 2026 · 05:49 UTC
Dernier changement observé : 16 sept. 2026 · 05:49 UTC

Dates de synchronisation GSTEP, distinctes des dates de publication du contenu source.