↳ GitHub sourceSolution

SpyCloud Enterprise Protection CCF

Description

The [SpyCloud Enterprise Threat Protection](https://spycloud.com/) solution for Microsoft Sentinel ingests SpyCloud breach watchlist and catalog data via the Codeless Connector Framework (CCF), including an optional Compass daily feed. The solution includes three built-in analytic rules, two KQL parsers, and three automation playbooks covering Microsoft Defender for Endpoint response, Azure AD / Entra ID Conditional Access enforcement, and sign-in session revocation. **Underlying Microsoft Technologies used:** This solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs: a. [Codeless Connector Framework (CCF)](https://learn.microsoft.com/en-us/azure/sentinel/create-codeless-connector) b. [Azure Logic Apps](https://azure.microsoft.com/services/logic-apps/) c. [Microsoft Defender for Endpoint](https://www.microsoft.com/en-us/security/business/endpoint-security/microsoft-defender-endpoint)
Version
3.0.1
Declared author / publisher
SpyCloud - integrations@spycloud.com
Support tier
Partner

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
azure-sentinel-solution-spycloud-enterprise-protection
Additional source files 2Solutions/SpyCloud Enterprise Protection CCF/Data/Solution_SpyCloudEnterpriseProtection.jsonsolution-manifest ↗Solutions/SpyCloud Enterprise Protection CCF/SolutionMetadata.jsonsolution-metadata ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.