↳ Source GitHubSolution

PRODAFT USTA - IoC Threat Intelligence

Description

The **PRODAFT USTA - IoC Threat Intelligence** solution ingests indicators of compromise (malicious URLs, malware hashes, and phishing sites) from the PRODAFT USTA platform into Microsoft Sentinel **Threat Intelligence** as STIX 2.1 indicators via the Upload STIX Objects API. Ingestion is performed by import playbooks (one per IoC feed) using a system-assigned managed identity; resolved `ip_addresses` on a record are added to the same indicator as `ipv4-addr`/`ipv6-addr` observables; indicators appear in the Threat Intelligence blade and the `ThreatIntelIndicators` table under a per-feed `SourceSystem` (`PRODAFT USTA - Malicious URLs`, `PRODAFT USTA - Malware Hashes`, `PRODAFT USTA - Phishing Sites`), so `SourceSystem startswith 'PRODAFT USTA'` selects them all. Includes three TI-map analytic rules that match ingested indicators against your logs, an overview workbook, and an on-demand backfill playbook for loading historical indicators.
Version
3.0.0
Auteur / éditeur déclaré
PRODAFT - integration@prodaft.com
Niveau de support
Partner

Contenus associés

Liens établis à partir des identifiants déclarés et des manifests des solutions.

Traçabilité de la source

GitHub

Les valeurs affichées proviennent des fichiers du dépôt Azure/Azure-Sentinel. Elles décrivent le modèle publié, pas la configuration de votre workspace.

Identifiant source
azure-sentinel-solution-prodaft-usta-ioc
Autres fichiers source 2Solutions/PRODAFT USTA - IoC Threat Intelligence/Data/Solution_PRODAFTUstaIoC.jsonsolution-manifest ↗Solutions/PRODAFT USTA - IoC Threat Intelligence/SolutionMetadata.jsonsolution-metadata ↗
GSTEP / SUIVI DU CATALOGUE

Ajouté au catalogue : 16 sept. 2026 · 05:49 UTC
Dernier changement observé : 16 sept. 2026 · 05:49 UTC

Dates de synchronisation GSTEP, distinctes des dates de publication du contenu source.