↳ GitHub sourceSolution

PRODAFT USTA - IoC Threat Intelligence

Description

The **PRODAFT USTA - IoC Threat Intelligence** solution ingests indicators of compromise (malicious URLs, malware hashes, and phishing sites) from the PRODAFT USTA platform into Microsoft Sentinel **Threat Intelligence** as STIX 2.1 indicators via the Upload STIX Objects API. Ingestion is performed by import playbooks (one per IoC feed) using a system-assigned managed identity; resolved `ip_addresses` on a record are added to the same indicator as `ipv4-addr`/`ipv6-addr` observables; indicators appear in the Threat Intelligence blade and the `ThreatIntelIndicators` table under a per-feed `SourceSystem` (`PRODAFT USTA - Malicious URLs`, `PRODAFT USTA - Malware Hashes`, `PRODAFT USTA - Phishing Sites`), so `SourceSystem startswith 'PRODAFT USTA'` selects them all. Includes three TI-map analytic rules that match ingested indicators against your logs, an overview workbook, and an on-demand backfill playbook for loading historical indicators.
Version
3.0.0
Declared author / publisher
PRODAFT - integration@prodaft.com
Support tier
Partner

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
azure-sentinel-solution-prodaft-usta-ioc
Additional source files 2Solutions/PRODAFT USTA - IoC Threat Intelligence/Data/Solution_PRODAFTUstaIoC.jsonsolution-manifest ↗Solutions/PRODAFT USTA - IoC Threat Intelligence/SolutionMetadata.jsonsolution-metadata ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.