> ## Documentation Index
> Fetch the complete documentation index at: https://docs.pulsedive.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Integrate with Microsoft Sentinel

> Import scored, deduplicated Pulsedive threat intelligence into Microsoft Sentinel over TAXII 2.1 to power detection, alerting, and investigation.

Microsoft Sentinel is a cloud-native SIEM and SOAR platform that security teams use to collect, detect, investigate, and respond to threats across their environment.
With this integration, Pulsedive acts as a TAXII 2.1 server and Microsoft Sentinel connects as a TAXII client, polling Pulsedive on a schedule and importing indicators in STIX format into its threat intelligence store.
Because Pulsedive scores and deduplicates indicators before export, your analysts spend less time triaging noise and more time acting on what matters.

## Prerequisites

Before you connect Microsoft Sentinel to Pulsedive, make sure you have:

* A Pulsedive account and API key.
  Find your API key on your [Pulsedive account page](https://pulsedive.com/account).
* A Pulsedive Pro or Feed plan to access the Indicator and Threat collections.
  The free Test collection works with any account, so you can evaluate the integration first.

In Microsoft Sentinel, make sure you have:

* An active Microsoft Sentinel workspace.
* Permission to install content from the Content hub and to manage data connectors, plus read and write access to the workspace so it can store threat indicators.

## Connecting Microsoft Sentinel to Pulsedive

Follow these steps to connect Microsoft Sentinel to Pulsedive's TAXII 2.1 server.
The connector lives in different places depending on whether you use the Azure portal or the Defender portal, so for current navigation, visit [Microsoft's TAXII connector documentation](https://learn.microsoft.com/en-us/azure/sentinel/connect-threat-intelligence-taxii).

1. Install the Threat Intelligence solution from the Content hub if it isn't already installed.
2. Open the **Data connectors** menu, select the **Threat Intelligence - TAXII** connector, then select **Open connector page**.
3. Enter details for the connector:
   | Field Name | Description |
   | - | - |
   | **Friendly name** | Human-readable name that identifies the collection (for example, `Pulsedive Indicators`). |
   | **API root URL** | Use `https://pulsedive.com/taxii2/api/` |
   | **Collection ID** | ID of the collection you want to import. Available collections include:<br /><ul><li>Indicators: <code>a5cffbfe-c0ff-4842-a235-cb3a7a040a37</code></li><li>Threats: <code>dc9ecfa5-7769-4cf3-b699-38a9776b431d</code></li><li>Test: <code>981c4916-ebb2-4567-aece-54ae970c4230</code><br />(live sample data, free with any API key)</li></ul><Note>Microsoft Sentinel's TAXII connector accepts one Collection ID per connection. To import both indicators and threats, configure the connector once for each collection.</Note> |
   | **Username** | Use `taxii2` |
   | **Password** | Your Pulsedive API key. |
4. Set a polling frequency (for example, once a day).
5. Select **Add** to save and enable the connector.

To import another collection, repeat these steps with the next Collection ID.

To review the full TAXII reference, visit [STIX/TAXII Reference](/taxii/overview).

## Verifying the Connection

Confirm that Pulsedive indicators are flowing into Microsoft Sentinel before you build them into detection rules.

Microsoft Sentinel completes its first poll within a few minutes to a few hours, depending on your polling frequency.
Once it does, open your threat intelligence view and filter by source to confirm that Pulsedive indicators are arriving.
You can also query the `ThreatIntelligenceIndicator` table directly to confirm ingestion.

## Using Pulsedive Data in Microsoft Sentinel

Once Pulsedive indicators are in your workspace, you can match them against your logs, visualize coverage, and hunt across your data.

* Enable the built-in analytics rule templates whose names begin with `TI map` to match Pulsedive indicators against your event data and raise alerts.
* Build or customize a workbook to visualize the threats and sources the integration covers.
* Query the `ThreatIntelligenceIndicator` table to hunt for specific indicators.

To enable and tune analytics rules, visit [Microsoft's TAXII connector documentation](https://learn.microsoft.com/en-us/azure/sentinel/connect-threat-intelligence-taxii).

To review the vendor-agnostic setup, visit [Quick Setup](/taxii/quick-setup).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.