Prerequisites
Before you connect Microsoft Sentinel to Pulsedive, make sure you have:- A Pulsedive account and API key. Find your API key on your Pulsedive account page.
- A Pulsedive Pro or Feed plan to access the Indicator and Threat collections. The free Test collection works with any account, so you can evaluate the integration first.
- An active Microsoft Sentinel workspace.
- Permission to install content from the Content hub and to manage data connectors, plus read and write access to the workspace so it can store threat indicators.
Connecting Microsoft Sentinel to Pulsedive
Follow these steps to connect Microsoft Sentinel to Pulsedive’s TAXII 2.1 server. The connector lives in different places depending on whether you use the Azure portal or the Defender portal, so for current navigation, visit Microsoft’s TAXII connector documentation.- Install the Threat Intelligence solution from the Content hub if it isn’t already installed.
- Open the Data connectors menu, select the Threat Intelligence - TAXII connector, then select Open connector page.
- Enter details for the connector:
- Set a polling frequency (for example, once a day).
- Select Add to save and enable the connector.
Verifying the Connection
Confirm that Pulsedive indicators are flowing into Microsoft Sentinel before you build them into detection rules. Microsoft Sentinel completes its first poll within a few minutes to a few hours, depending on your polling frequency. Once it does, open your threat intelligence view and filter by source to confirm that Pulsedive indicators are arriving. You can also query theThreatIntelligenceIndicator table directly to confirm ingestion.
Using Pulsedive Data in Microsoft Sentinel
Once Pulsedive indicators are in your workspace, you can match them against your logs, visualize coverage, and hunt across your data.- Enable the built-in analytics rule templates whose names begin with
TI mapto match Pulsedive indicators against your event data and raise alerts. - Build or customize a workbook to visualize the threats and sources the integration covers.
- Query the
ThreatIntelligenceIndicatortable to hunt for specific indicators.