↳ GitHub sourceSolution

ContraForce

Description

The [ContraForce](https://www.contraforce.com) solution for Microsoft Sentinel ingests security service delivery events from your ContraForce workspace: incident detections from every connected security platform, administrative access changes (role and member changes), machine credential activity, and destructive workspace actions. The packaged analytic rules create Microsoft Sentinel incidents for privileged access changes, machine credential activity, and destructive workspace actions, so you can monitor the security operations ContraForce performs on your workspace from inside your own Microsoft Sentinel.
Version
3.0.0
Declared author / publisher
ContraForce - support@contraforce.com
Support tier
Partner

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
azure-sentinel-solution-contraforce
Additional source files 2Solutions/ContraForce/Data/Solution_ContraForce.jsonsolution-manifest ↗Solutions/ContraForce/SolutionMetadata.jsonsolution-metadata ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.