Microsoft Graph Security (v2.6.1)
Unified gateway to security insights - all from a unified Microsoft Graph Security API.
- Author
- Cortex XSOAR
- Support
- xsoar
- URL
- https://www.paloaltonetworks.com/cortex
- Categories
- Analytics & SIEM
Incident fields (7)
- Microsoft Graph Security Alert Determination
- Microsoft Graph Security Alert Evidence
- Microsoft Graph Security Comment
- Microsoft Graph Security Detector Id
- Microsoft Graph Security Id
- Microsoft Graph Security Recommended Action
- Microsoft Graph Security Service Source
Integrations (1)
- Microsoft Graph Security
Modeling rules (1)
- Microsoft Graph Security Modeling Rules
Parsing rules (1)
- Microsoft Graph Security Parsing Rules
Playbooks (1)
- Search And Delete Emails - Microsoft Graph Security
README
Microsoft Graph Security
This pack includes XSIAM content.
<~XSIAM>
- Pay attention: Timestamp parsing is available for UTC timezone, using the yyyy-mm-ssTHH:MM:SS.3msZ format.
Use the Microsoft Graph integration to fetch and manage alerts from various Microsoft security sources, such as:
- Microsoft 365 Defender unified alerts API
- Microsoft Defender for Endpoint
- Microsoft Defender for Office 365
- Microsoft Defender for Identity
- Microsoft Defender for Cloud Apps
- Microsoft Purview Data Loss Prevention (including any future new signals integrated into M365D).
What does this pack do?
- This content XDM mappings are based on the Office 365 integration, in the Graph API section enable alertv2 Doc.
- Unify and standardize alert tracking
- Correlate security alerts to improve threat protection and response
- Update alert tags, status, and assignments
- Unlock security context to drive investigation
- Automate security workflows and reporting
- Get deep insights to train security solutions
</~XSIAM>
<~XSOAR>
Use the Microsoft Graph integration to fetch and manage alerts from various Microsoft security sources, such as:
- Azure ATP
- Azure Security Center
- Microsoft CAS
- Azure Active Directory Identity Protection
- Azure Sentinel
- Microsoft Defender for Endpoint (ATP)
What does this pack do?
- Unify and standardize alert tracking
- Correlate security alerts to improve threat protection and response
- Update alert tags, status, and assignments
- Unlock security context to drive investigation
- Automate security workflows and reporting
- Get deep insights to train security solutions
</~XSOAR>