↳ GitHub sourceConnector

Cyble Threat Intel

Description

The Cyble Threat Intel Alerts API connector pushes real-time alerts from Cyble to Microsoft Sentinel and is designed to be used with the Cyble Solution for Sentinel. The connector writes logs to a table titled **SecurityIncident**.
Declared status
1
Declared author / publisher
Cyble

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

read and write permissions on the workspace are required.
Workspace
Workspace
Microsoft.Web/sites permissions
Read and write permissions to Azure Logic App to create a Azure Logic App is required. [See the documentation to learn more about Azure Logic App](https://learn.microsoft.com/azure/logic-apps/).
Cyble Alerts API Credentials and Endpoint
**Cyble Access Token**, **Cyble Endpoint** is required for Cyble Threat Intel Connector.
 Follow the instructions in [Cyble Vision Application](https://cyble.ai) to obtain them.

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

>**NOTE:** This connector operates to establish a connection with the Cyble Alerts API, enabling the retrieval of its logs for Microsoft Sentinel workspace. Pulling logs into Sentinel via logic app could lead to extra charges related to data ingestion. For a detailed understanding of these potential costs, it's advisable to consult the Azure logic app pricing page. Check the [Azure Logic App pricing page](https://azure.microsoft.com/pricing/details/logic-apps/) for details.
**STEP 1 - Configuration steps for the Cyble Threat Intel Connector** Follow the instructions in [Cyble Vision Application](https://cyble.ai) to obtain the Cyble Alerts API credentials.
**STEP 2 - Launch Azure Resource Manager (ARM) Template** Use this method for automated deployment of the Logic App using an ARM Template. Click the **Deploy to Azure** button below. [![Deploy To Azure](https://aka.ms/deploytoazurebutton)](https://aka.ms/sentinel-CybleLogicApp-playbook)
**STEP 3 - Fill the following information**
Enter the subscription name under which you intend to deploy the resources.
Subscription Name
Specify the resource group. If necessary, you can create a new resource group at this point. >**NOTE:** Within the same resource group, you can't mix Windows and Linux apps in the same region. Select existing resource group without Windows apps in it or create new resource group.
Resource Group
Specify the region where your resources will be located.
Region
Assign a name for the workflow.
Workflow Name
Specify the name for the organization's **Sentinel Log Analytics** workspace.
Workspace Name
Provide your unique access token for authentication.
Cyble Access Token
Specify the endpoint to establish the correct API endpoint.
Cyble Endpoint
Determine how often the workflow should run.
Frequency Minutes
**STEP 4 - Deploy your Resources** Mark the checkbox labeled **I agree to the terms and conditions stated above**. Click **Purchase** to deploy.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
CybleThreatIntel
Additional source files 1DataConnectors/CybleLogicApp/Connector_LogicApp_Cyble.jsonsource ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.