Description
The [ContraForce](https://www.contraforce.com) solution for Microsoft Sentinel ingests security service delivery events from your ContraForce workspace: incident detections from every connected security platform, administrative access changes (role and member changes), machine credential activity, and destructive workspace actions. The packaged analytic rules create Microsoft Sentinel incidents for privileged access changes, machine credential activity, and destructive workspace actions, so you can monitor the security operations ContraForce performs on your workspace from inside your own Microsoft Sentinel.
- Version
- 3.0.0
- Declared author / publisher
- ContraForce - support@contraforce.com
- Support tier
- Partner
Related content
Links established from declared identifiers and solution manifests.
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
9800e51↗- Source identifier
azure-sentinel-solution-contraforce
GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC