Azure AD Connect Health Feed
Use the Microsoft Azure AD Connect Health Feed integration to get indicators from the feed.
Data Enrichment & Threat Intelligence · Microsoft Azure AD Connect Health Feed · Feed
Details
| ID | Azure AD Connect Health Feed |
|---|---|
| Provider | Microsoft |
| Category | Data Enrichment & Threat Intelligence |
| From Version | 5.5.0 |
| Docker Image | demisto/btfl-soup:1.0.1.10120494 |
| Supported Modules | Agentix XSIAM |
README
Use the Microsoft Azure AD Connect Health Feed integration to get indicators from the feed.
This integration was integrated and tested with version 1 of Azure AD Connect Health Feed
Configure Azure AD Connect Health Feed in Cortex
| Parameter | Description | Required | ||||
|---|---|---|---|---|---|---|
| feed | Fetch indicators | False | ||||
| feedReputation | Indicator Reputation | False | ||||
| feedReliability | Source Reliability | True | ||||
| tlp_color | The Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed. More information about the protocol can be found at https://us-cert.cisa.gov/tlp | False | feedExpirationPolicy | False | ||
| feedExpirationInterval | False | |||||
| feedFetchInterval | Feed Fetch Interval | False | ||||
| url | The Microsoft Azure endpoint URL | True | ||||
| feedTags | Tags | False | ||||
| feedBypassExclusionList | Bypass exclusion list | False | ||||
| insecure | Trust any certificate (not secure) | False | ||||
| proxy | Use system proxy settings | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
azure-ad-health-get-indicators
Gets indicators from the feed.
Base Command
azure-ad-health-get-indicators
Input
| Argument Name | Description | Required |
|---|---|---|
| limit | The maximum number of results to return. The default value is 10. | Optional |
Context Output
There is no context output for this command.
Command Example
#### Context Example
{}
```
Human Readable Output
Indicators from Microsoft Azure Feed
value type https://login.microsoftonline.com URL https://secure.aadcdn.microsoftonline-p.com URL https://login.windows.net URL
Configuration parameters
feed— Fetch indicatorsfeedReputation— Indicator ReputationfeedReliability— Source Reliability (required)tlp_color— Traffic Light Protocol ColorfeedExpirationPolicy—feedExpirationInterval—feedFetchInterval— Feed Fetch Intervalurl— The Microsoft Azure endpoint URL (required)feedTags— TagsfeedBypassExclusionList— Bypass exclusion listinsecure— Trust any certificate (not secure)proxy— Use system proxy settings
Commands (1)
-
azure-ad-health-get-indicatorsGets indicators from the feed.