Microsoft Sentinel integration
Threat Intelligence Security Center for Microsoft Sentinel offers several capabilities, including importing observables from TISC to Sentinel, enriching Sentinel incidents with details of related observables, and also allow exporting observables from Sentinel to TISC.
Note: On Microsoft Sentinel, observables are referred as entities.
Prerequisites
Dependencies
The Threat Intelligence solution from Microsoft Sentinel Content Hub must be installed.
| Application | Roles and Permissions | Description |
|---|---|---|
| Microsoft Sentinel-specific roles | 1. Logic App Contributor 2. Microsoft Sentinel Contributor | 1. To install the required playbooks on a Resource Group level. 2. Interact with Microsoft Sentinel playbooks. For more information, see Roles and Permissions in Microsoft Sentinel. |
| Threat Intelligence Security Center | sn\_sec\_tisc.api\_azure\_sentinel\_solution | User configured in the TISC Custom Connector should have this role to allow access to TISC APIs. |
- TISC playbook templates
This section describes the playbook templates that are shipped with TISC Sentinel solution.
Parent Topic:TISC Security Tools integrations