How to use SEKOIA.IO indicators in Microsoft Sentinel ?
ID: aae65287-1e94-57aa-9f24-bc9e97aa8fe9
STIX ID: report--aae65287-1e94-57aa-9f24-bc9e97aa8fe9
Feed Name: Sekoia.com
This blogpost explains how to integrate Sekoia threat intelligence into Microsoft Sentinel via the Threat intelligence — TAXII data connector, how analytics rules surface matched indicators into incidents (using IndicatorId and ExternalIndicatorId), and how to implement a Sentinel playbook that queries ThreatIntelligenceIndicator to add direct links to Sekoia Intelligence Center in incident comments for richer context and investigation. It also outlines enhancements and caveats (duplicate entries, multiple TI sources, optional API enrichment) and shows how automation rules can run the playbook automatically.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
