Skip to main content
Microsoft Sentinel is a cloud-native SIEM and SOAR platform that security teams use to collect, detect, investigate, and respond to threats across their environment. With this integration, Pulsedive acts as a TAXII 2.1 server and Microsoft Sentinel connects as a TAXII client, polling Pulsedive on a schedule and importing indicators in STIX format into its threat intelligence store. Because Pulsedive scores and deduplicates indicators before export, your analysts spend less time triaging noise and more time acting on what matters.

Prerequisites

Before you connect Microsoft Sentinel to Pulsedive, make sure you have:
  • A Pulsedive account and API key. Find your API key on your Pulsedive account page.
  • A Pulsedive Pro or Feed plan to access the Indicator and Threat collections. The free Test collection works with any account, so you can evaluate the integration first.
In Microsoft Sentinel, make sure you have:
  • An active Microsoft Sentinel workspace.
  • Permission to install content from the Content hub and to manage data connectors, plus read and write access to the workspace so it can store threat indicators.

Connecting Microsoft Sentinel to Pulsedive

Follow these steps to connect Microsoft Sentinel to Pulsedive’s TAXII 2.1 server. The connector lives in different places depending on whether you use the Azure portal or the Defender portal, so for current navigation, visit Microsoft’s TAXII connector documentation.
  1. Install the Threat Intelligence solution from the Content hub if it isn’t already installed.
  2. Open the Data connectors menu, select the Threat Intelligence - TAXII connector, then select Open connector page.
  3. Enter details for the connector:
  4. Set a polling frequency (for example, once a day).
  5. Select Add to save and enable the connector.
To import another collection, repeat these steps with the next Collection ID. To review the full TAXII reference, visit STIX/TAXII Reference.

Verifying the Connection

Confirm that Pulsedive indicators are flowing into Microsoft Sentinel before you build them into detection rules. Microsoft Sentinel completes its first poll within a few minutes to a few hours, depending on your polling frequency. Once it does, open your threat intelligence view and filter by source to confirm that Pulsedive indicators are arriving. You can also query the ThreatIntelligenceIndicator table directly to confirm ingestion.

Using Pulsedive Data in Microsoft Sentinel

Once Pulsedive indicators are in your workspace, you can match them against your logs, visualize coverage, and hunt across your data.
  • Enable the built-in analytics rule templates whose names begin with TI map to match Pulsedive indicators against your event data and raise alerts.
  • Build or customize a workbook to visualize the threats and sources the integration covers.
  • Query the ThreatIntelligenceIndicator table to hunt for specific indicators.
To enable and tune analytics rules, visit Microsoft’s TAXII connector documentation. To review the vendor-agnostic setup, visit Quick Setup.