Skip to content

Latest commit

 

History

History

MDTI-Data-HostInfo

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
 
 
 
 

MDTI-DATA-HOSTINFO

Overview

This playbook uses the Microsoft Defender Threat Intelligence Reputation data as well as the HOst API endpoint to automatically enrich incidents generated by Microsoft Sentinel. Indicators from an incident will be evaluated with MDTI Reputation data.

Prerequisites

  1. This playbook inherits API connections created and established within a base playbook. Ensure you have deployed MDTI-Base this playbook. If you have trouble accessing your account or your credentials contact your account representative or reach out to discussMDTI[@]microsoft.com.
  2. This playbook requires "Microsoft Sentinel Contributor" role to update Incidents.

Deployment

Post-Deployment Instructions

After deploying the playbook, you must authorize the connections leveraged.

  1. Visit the playbook resource.
  2. Under "Development Tools" (located on the left), click "API Connections".
  3. Ensure each connection has been authorized.

Note: If you've deployed the MDTI-Base playbook, you will only need to authorize the Microsoft Sentinel connection.