↳ GitHub sourceSolution

Legacy IOC based Threat Protection

Description

Microsoft Security Research, based on ongoing trends and exploits creates content that help identify existence of known IOCs based on known prevalent attacks and threat actor tactics/techniques, such as Nobelium, Gallium, Solorigate, etc. This solution contains packaged content written on some legacy IOCs that have been prevalent in the past but may still be relevant. **Pre-requisites:** This is a [domain solution](https://learn.microsoft.com/azure/sentinel/sentinel-solutions-catalog#domain-solutions) and does not include any data connectors. The content in this solution supports the connectors listed below. Install one or more of the listed solutions, to unlock the value provided by this solution. 1. Squid Proxy 2. Windows Server DNS 3. Cisco ASA 4. Palo Alto Networks 5. Microsoft Defender XDR 6. Azure Firewall 7. ZScaler Internet Access 8. Infoblox NIOS 9. Google Cloud Platform DNS 10. NXLog DNS 11. Cisco Umbrella 12. Corelight 13. Amazon Web Services 14. Windows Forwarded Events 15. Sysmon for Linux 16. Microsoft 365 17. Windows Security Events 18. Microsoft Entra ID 19. Azure Activity 20. F5 Advanced WAF 21. Fortinet FortiGate 22. Check Point 23. Common Event Format 24. Windows Firewall
Version
3.0.5
Declared author / publisher
Microsoft - support@microsoft.com
Support tier
Microsoft

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
azure-sentinel-solution-ioclegacy
Additional source files 2Solutions/Legacy IOC based Threat Protection/Data/Solution_Legacy IOC based Threat Protection.jsonsolution-manifest ↗Solutions/Legacy IOC based Threat Protection/SolutionMetadata.jsonsolution-metadata ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.