↳ Source GitHubConnecteur

PRODAFT USTA - IoC Threat Intelligence

Description

The PRODAFT USTA IoC Threat Intelligence connector ingests indicators of compromise (malicious URLs, malware hashes, and phishing sites) from the PRODAFT USTA platform into Microsoft Sentinel's Threat Intelligence as STIX indicators via the Upload STIX Objects API. Ingestion is performed by the import playbooks shipped with this solution (one per IoC feed); where a record carries resolved `ip_addresses`, those addresses are added to the same indicator's pattern as `ipv4-addr`/`ipv6-addr` observables; indicators appear in the Threat Intelligence blade and in the `ThreatIntelIndicators` table under a per-feed `SourceSystem` — `PRODAFT USTA - Malicious URLs`, `PRODAFT USTA - Malware Hashes` and `PRODAFT USTA - Phishing Sites` — so `SourceSystem startswith 'PRODAFT USTA'` selects every USTA indicator. After installing the solution, deploy and authorize the import playbooks by following the guidance in the Manage solution view.
Statut déclaré
1
Auteur / éditeur déclaré
PRODAFT

Sources déclarées

Métadonnées du fichier source. Aucune dépendance déduite du KQL.

Types de données

Permissions déclarées

read and write permissions on the workspace are required.
Workspace
Workspace
Workspace role assignments for the playbooks
Every import and backfill playbook uses a system-assigned managed identity, which needs the **Microsoft Sentinel Contributor** role on the workspace to call the Upload STIX Objects API. The three **import** playbooks additionally read their ingestion watermark from the `ThreatIntelIndicators` table and therefore also need **Log Analytics Reader** on the workspace — Microsoft Sentinel Contributor does not cover the `Microsoft.OperationalInsights/workspaces/read` action that read performs.
PRODAFT USTA API key
A long-lived PRODAFT USTA API key with access to the Security Intelligence IoC endpoints is required.

Instructions du connecteur

Contenu publié dans le dépôt. Consultez le fichier original pour l’ensemble des paramètres.

1. Install the core Threat Intelligence solution
This connector lands indicators in the `ThreatIntelIndicators` table and the Threat Intelligence blade. Install the Microsoft **Threat Intelligence** solution from the Content hub first, so the blade and the source-agnostic TI-map analytic rules are available.
2. Deploy the PRODAFT USTA import playbooks
This solution ships three hourly import playbooks — **PRODAFTUstaIoC-ImportMaliciousUrls**, **PRODAFTUstaIoC-ImportMalwareHashes**, and **PRODAFTUstaIoC-ImportPhishingSites** — plus a matching on-demand backfill playbook per feed (**PRODAFTUstaIoC-BackfillMaliciousUrls**, **-BackfillMalwareHashes**, **-BackfillPhishingSites**) for loading history. Deploy them from the Manage solution view (or the Automation blade), supplying your USTA base URL, USTA API key, and the name of your Microsoft Sentinel workspace.
3. Authorize the playbooks' managed identity
Each playbook uses a system-assigned managed identity. On the **Log Analytics workspace** → Access control (IAM) → Add role assignment — open IAM on the workspace, **not** on the Logic App, or the assignment is scoped to the playbook and grants no workspace access — grant that identity **Microsoft Sentinel Contributor** (needed by every playbook, for the Upload STIX Objects call) and, for the three **import** playbooks, also **Log Analytics Reader** (needed for the watermark query — without it the run fails with `AuthorizationFailed` on `Microsoft.OperationalInsights/workspaces/read`). Once granted, the playbooks poll USTA hourly and push new indicators; the connector shows **Connected** after the first indicators arrive.

Contenus associés

Liens établis à partir des identifiants déclarés et des manifests des solutions.

Traçabilité de la source

GitHub

Les valeurs affichées proviennent des fichiers du dépôt Azure/Azure-Sentinel. Elles décrivent le modèle publié, pas la configuration de votre workspace.

Identifiant source
PRODAFTUstaIoCUploadIndicators
Autres fichiers source 2Solutions/PRODAFT USTA - IoC Threat Intelligence/Data Connectors/PRODAFTUstaIoC_UploadIndicatorsAPI.jsonsource ↗Solutions/PRODAFT USTA - IoC Threat Intelligence/Data/Solution_PRODAFTUstaIoC.jsonsolution-membership ↗
GSTEP / SUIVI DU CATALOGUE

Ajouté au catalogue : 16 sept. 2026 · 05:49 UTC
Dernier changement observé : 16 sept. 2026 · 05:49 UTC

Dates de synchronisation GSTEP, distinctes des dates de publication du contenu source.