↳ GitHub sourceConnector

CYFIRMA Cyber Intelligence

Description

The CYFIRMA Cyber Intelligence data connector enables seamless log ingestion from the DeCYFIR API into Microsoft Sentinel. Built on the Microsoft Sentinel Codeless Connector Platform, it leverages the DeCYFIR Alerts API to retrieve logs. Additionally, it supports DCR-based [ingestion time transformations](https://docs.microsoft.com/azure/azure-monitor/logs/custom-logs-overview), which parse security data into a custom table during ingestion. This eliminates the need for query-time parsing, enhancing performance and efficiency.
Declared status
1
Declared author / publisher
Microsoft

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

Read and Write permissions are required.
Workspace
Workspace

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

CYFIRMA Cyber Intelligence
This connector provides the Indicators, Threat actors, Malware and Campaigns logs from CYFIRMA Cyber Intelligence. The connector uses the DeCYFIR API to retrieve logs and supports DCR-based ingestion time transformations, parsing security data into a custom table during ingestion. This eliminates the need for query-time parsing, enhancing performance and efficiency.
CYFIRMA API URL
CYFIRMA API Key
Pull all IoC's Or Tailored IoC's
Set to true to pull all IoC's, set to false to pull tailoried IoC's
API Delta
Setting it to true returns only data added since the last API call, while false returns data from the last 24 hours.
Recommended Actions
Recommended Action can be any one of:All/Monitor/Block
Threat Actor Associated
Is any Threat Actor Associated with the IoC's

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
CyfirmaCyberIntelligenceDC
Additional source files 2Solutions/Cyfirma Cyber Intelligence/Data Connectors/CyfirmaCyberIntelligence_ccp/CyfirmaCyberIntel_DataConnectorDefinition.jsonsource ↗Solutions/Cyfirma Cyber Intelligence/Data/Solution_CyfirmaCyberIntel.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.