↳ GitHub sourceSolution

NordStellar

Description

The [NordStellar](https://nordlayer.com/intelligence/) solution for Microsoft Sentinel pushes real-time threat intelligence and exposure events from NordStellar's Leaked Data, Dark Web Monitoring, Domain Squatting, and Attack Surface modules into a unified `NordStellar_CL` table using the Codeless Connector Framework (CCF) Push pattern. **Underlying Microsoft Technologies used:** This solution takes a dependency on the following technologies, and some may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or result in additional ingestion or operational costs: a. [Azure Monitor Logs Ingestion API](https://learn.microsoft.com/azure/azure-monitor/logs/logs-ingestion-api-overview) b. [Data Collection Rules](https://learn.microsoft.com/azure/azure-monitor/essentials/data-collection-rule-overview) c. [Microsoft Entra application registrations](https://learn.microsoft.com/entra/identity-platform/quickstart-register-app)
Version
3.0.1
Declared author / publisher
Nord Security Inc. - support@nordstellar.com
Support tier
Partner

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
azure-sentinel-solution-nordstellar
Additional source files 2Solutions/NordStellar/Data/Solution_NordStellar.jsonsolution-manifest ↗Solutions/NordStellar/SolutionMetadata.jsonsolution-metadata ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.