↳ Source GitHubSolution

HoneyLabs

Description

The [HoneyLabs](https://honeylabs.net) solution for Microsoft Sentinel ingests threat intelligence generated by internet-facing honeypot sensors: source IPs observed running exploit or loader commands, and the malware infrastructure (loader and C2 URLs) extracted from the captured payloads. Indicators are evidence-backed rather than scan-derived, exclude known research scanners (Shadowserver, Censys and similar), and expire automatically as activity stops. Ingestion uses Microsoft Sentinel's built-in **Threat Intelligence - TAXII** data connector against the HoneyLabs TAXII 2.1 server; a free HoneyLabs API key is the only prerequisite. The solution also includes analytic rules that match the indicators against your own logs and a playbook that enriches incidents with the full HoneyLabs report for any IP entity. [Get a free API key](https://honeylabs.net/dashboard?src=sentinel) | [Integration guide](https://honeylabs.net/integrations/sentinel) | [Methodology](https://honeylabs.net/methodology)
Version
3.0.0
Auteur / éditeur déclaré
HoneyLabs - info@honeylabs.net
Niveau de support
Community

Contenus associés

Liens établis à partir des identifiants déclarés et des manifests des solutions.

Traçabilité de la source

GitHub

Les valeurs affichées proviennent des fichiers du dépôt Azure/Azure-Sentinel. Elles décrivent le modèle publié, pas la configuration de votre workspace.

Identifiant source
azure-sentinel-solution-honeylabs
Autres fichiers source 2Solutions/HoneyLabs/Data/Solution_HoneyLabs.jsonsolution-manifest ↗Solutions/HoneyLabs/SolutionMetadata.jsonsolution-metadata ↗
GSTEP / SUIVI DU CATALOGUE

Ajouté au catalogue : 16 sept. 2026 · 05:49 UTC
Dernier changement observé : 16 sept. 2026 · 05:49 UTC

Dates de synchronisation GSTEP, distinctes des dates de publication du contenu source.