Description
The **PRODAFT USTA - IoC Threat Intelligence** solution ingests indicators of compromise (malicious URLs, malware hashes, and phishing sites) from the PRODAFT USTA platform into Microsoft Sentinel **Threat Intelligence** as STIX 2.1 indicators via the Upload STIX Objects API. Ingestion is performed by import playbooks (one per IoC feed) using a system-assigned managed identity; resolved `ip_addresses` on a record are added to the same indicator as `ipv4-addr`/`ipv6-addr` observables; indicators appear in the Threat Intelligence blade and the `ThreatIntelIndicators` table under a per-feed `SourceSystem` (`PRODAFT USTA - Malicious URLs`, `PRODAFT USTA - Malware Hashes`, `PRODAFT USTA - Phishing Sites`), so `SourceSystem startswith 'PRODAFT USTA'` selects them all. Includes three TI-map analytic rules that match ingested indicators against your logs, an overview workbook, and an on-demand backfill playbook for loading historical indicators.
- Version
- 3.0.0
- Declared author / publisher
- PRODAFT - integration@prodaft.com
- Support tier
- Partner
Related content
Links established from declared identifiers and solution manifests.
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
9800e51↗- Source identifier
azure-sentinel-solution-prodaft-usta-ioc
GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC