Microsoft Sentinel
Modified on: Thu, 21 Dec, 2023 at 5:03 PM
Overview
Microsoft Sentinel delivers intelligent security analytics and threat intelligence across the enterprise.
The Microsoft Sentinel integration for Maltego allows users to import incidents and make deep dives into them using powerful link analysis capabilities and multiple data sources.
Microsoft Sentinel is a scalable, cloud-native solution that provides:
- Security information and event management (SIEM)
- Security orchestration, automation, and response (SOAR) It delivers intelligent security analytics and threat intelligence across the enterprise.
The Microsoft Sentinel integration for Maltego allows users to import incidents and make deep dives into them using link powerful analysis capabilities and multiple data sources.
Microsoft Sentinel: Jinxpy Sentinel Transforms
Import Incident By URL [Sentinel]
Description
Search for related phone numbers.
maltego.jinxpy_sentinel.global.global#CLIENT_ID | Azure Enterprise App ID | string | None | True | True | False |
maltego.jinxpy_sentinel.global.global#CLIENT_SECRET | Azure Enterprise App Secret | string | None | True | True | False |
maltego.jinxpy_sentinel.global.global#RESOURCE_GROUP | Azure Resource Group | string | None | True | True | False |
maltego.jinxpy_sentinel.global.global#SUBSCRIPTION_ID | Azure Subscription ID | string | None | True | True | False |
maltego.jinxpy_sentinel.global.global#TENANT_ID | Azure Tenant ID | string | None | True | True | False |
maltego.jinxpy_sentinel.global.global#WORKSPACE_NAME | Sentinel Workspace Name | string | None | True | True | False |
Display Name | Import Incident By URL [Sentinel] |
Owner | Maltego Technologies GmbH |
Author | Maltego Technologies GmbH |
Data Source | Sentinel |
Transform Name | maltego.jinxpy_sentinel.url_to_incidents |
Short Description | Search for related phone numbers. |
Input Entities | maltego.URL |
Output Entities | maltego.sentinel.Incident |
Description
Extract labels from this Incident.
Display Name | Extract Labels [Sentinel] |
Owner | Maltego Technologies GmbH |
Author | Maltego Technologies GmbH |
Data Source | Sentinel |
Transform Name | maltego.jinxpy_sentinel.extract_incident_labels |
Short Description | Extract labels from this Incident. |
Input Entities | maltego.sentinel.Incident |
Output Entities | maltego.Tag |
Description
Extract Alert Product names from this Incident.
Display Name | Extract Alert Product Names [Sentinel] |
Owner | Maltego Technologies GmbH |
Author | Maltego Technologies GmbH |
Data Source | Sentinel |
Transform Name | maltego.jinxpy_sentinel.extract_alert_product_names |
Short Description | Extract Alert Product names from this Incident. |
Input Entities | maltego.sentinel.Incident |
Output Entities | maltego.Phrase |
Annotate Incident [Sentinel]
Description
Get details of the Incident.
maltego.jinxpy_sentinel.global.global#CLIENT_ID | Azure Enterprise App ID | string | None | True | True | False |
maltego.jinxpy_sentinel.global.global#CLIENT_SECRET | Azure Enterprise App Secret | string | None | True | True | False |
maltego.jinxpy_sentinel.global.global#RESOURCE_GROUP | Azure Resource Group | string | None | True | True | False |
maltego.jinxpy_sentinel.global.global#SUBSCRIPTION_ID | Azure Subscription ID | string | None | True | True | False |
maltego.jinxpy_sentinel.global.global#TENANT_ID | Azure Tenant ID | string | None | True | True | False |
maltego.jinxpy_sentinel.global.global#WORKSPACE_NAME | Sentinel Workspace Name | string | None | True | True | False |
Display Name | Annotate Incident [Sentinel] |
Owner | Maltego Technologies GmbH |
Author | Maltego Technologies GmbH |
Data Source | Sentinel |
Transform Name | maltego.jinxpy_sentinel.annotate_incident |
Short Description | Get details of the Incident. |
Input Entities | maltego.sentinel.Incident |
Output Entities | maltego.sentinel.Incident |
To Entities [Sentinel]
maltego.jinxpy_sentinel.global.global#CLIENT_ID | Azure Enterprise App ID | string | None | True | True | False |
maltego.jinxpy_sentinel.global.global#CLIENT_SECRET | Azure Enterprise App Secret | string | None | True | True | False |
maltego.jinxpy_sentinel.global.global#RESOURCE_GROUP | Azure Resource Group | string | None | True | True | False |
maltego.jinxpy_sentinel.global.global#SUBSCRIPTION_ID | Azure Subscription ID | string | None | True | True | False |
maltego.jinxpy_sentinel.global.global#TENANT_ID | Azure Tenant ID | string | None | True | True | False |
maltego.jinxpy_sentinel.global.global#WORKSPACE_NAME | Sentinel Workspace Name | string | None | True | True | False |
Display Name | To Entities [Sentinel] |
Owner | Maltego Technologies GmbH |
Author | Maltego Technologies GmbH |
Data Source | Sentinel |
Transform Name | maltego.jinxpy_sentinel.incident_to_entities |
Short Description | |
Input Entities | maltego.sentinel.Incident |
Output Entities | maltego.DNSName, maltego.File, maltego.Hash, maltego.IPv4Address, maltego.IPv6Address, maltego.EmailAddress, maltego.Malware, maltego.URL, maltego.sentinel.Object |
To Security Alert [Sentinel]
Description
Extract the Security Alert associated with this Incident.
maltego.jinxpy_sentinel.global.global#CLIENT_ID | Azure Enterprise App ID | string | None | True | True | False |
maltego.jinxpy_sentinel.global.global#CLIENT_SECRET | Azure Enterprise App Secret | string | None | True | True | False |
maltego.jinxpy_sentinel.global.global#RESOURCE_GROUP | Azure Resource Group | string | None | True | True | False |
maltego.jinxpy_sentinel.global.global#SUBSCRIPTION_ID | Azure Subscription ID | string | None | True | True | False |
maltego.jinxpy_sentinel.global.global#TENANT_ID | Azure Tenant ID | string | None | True | True | False |
maltego.jinxpy_sentinel.global.global#WORKSPACE_NAME | Sentinel Workspace Name | string | None | True | True | False |
Display Name | To Security Alert [Sentinel] |
Owner | Maltego Technologies GmbH |
Author | Maltego Technologies GmbH |
Data Source | Sentinel |
Transform Name | maltego.jinxpy_sentinel.incident_to_security_alert |
Short Description | Extract the Security Alert associated with this Incident. |
Input Entities | maltego.sentinel.Incident |
Output Entities | maltego.sentinel.SecurityAlert |
To Malware [Sentinel]
Description
Extract Malware.
Display Name | To Malware [Sentinel] |
Owner | Maltego Technologies GmbH |
Author | Maltego Technologies GmbH |
Data Source | Sentinel |
Transform Name | maltego.jinxpy_sentinel.mail_custer_to_malware |
Short Description | Extract Malware. |
Input Entities | maltego.sentinel.MailCluster |
Output Entities | maltego.Malware |
Description
Extracts the sender’s email.
Display Name | Extract Sender [Sentinel] |
Owner | Maltego Technologies GmbH |
Author | Maltego Technologies GmbH |
Data Source | Sentinel |
Short Description | Extracts the sender’s email. |
Output Entities | maltego.EmailAddress |
Variants
maltego.jinxpy_sentinel.extract_sender_0 | maltego.sentinel.MailMessage |
maltego.jinxpy_sentinel.extract_sender_1 | maltego.sentinel.SubmissionMail |
Description
Extracts the recipient’s email.
Display Name | Extract Recipient [Sentinel] |
Owner | Maltego Technologies GmbH |
Author | Maltego Technologies GmbH |
Data Source | Sentinel |
Short Description | Extracts the recipient’s email. |
Output Entities | maltego.EmailAddress |
Variants
maltego.jinxpy_sentinel.extract_recipient_0 | maltego.sentinel.MailMessage |
maltego.jinxpy_sentinel.extract_recipient_1 | maltego.sentinel.SubmissionMail |
Description
Extracts the Attack Tactics Associated with the given Incident.
Display Name | Extract Attack Tactics [Sentinel] |
Owner | Maltego Technologies GmbH |
Author | Maltego Technologies GmbH |
Data Source | Sentinel |
Short Description | Extracts the Attack Tactics Associated with the given Incident. |
Output Entities | maltego.sentinel.AttackTactic |
Variants
maltego.jinxpy_sentinel.extract_attack_tactics_0 | maltego.sentinel.Incident |
maltego.jinxpy_sentinel.extract_attack_tactics_1 | maltego.sentinel.SecurityAlert |
Import Incidents [Sentinel]
Description
Imports all Sentinel Incidents
maltego.jinxpy_sentinel.global.global#CLIENT_ID | Azure Enterprise App ID | string | None | True | True | False |
maltego.jinxpy_sentinel.global.global#CLIENT_SECRET | Azure Enterprise App Secret | string | None | True | True | False |
maltego.jinxpy_sentinel.global.global#RESOURCE_GROUP | Azure Resource Group | string | None | True | True | False |
maltego.jinxpy_sentinel.global.global#SUBSCRIPTION_ID | Azure Subscription ID | string | None | True | True | False |
maltego.jinxpy_sentinel.global.global#TENANT_ID | Azure Tenant ID | string | None | True | True | False |
maltego.jinxpy_sentinel.global.global#WORKSPACE_NAME | Sentinel Workspace Name | string | None | True | True | False |
maltego.jinxpy_sentinel.import_incidents.INCIDENT_CREATED_BETWEEN | Incident Created Between | daterange | None | True | True | False |
maltego.jinxpy_sentinel.import_incidents.INCIDENT_SEVERITY | Incident Severity | string | None | True | True | False |
maltego.jinxpy_sentinel.import_incidents.INCIDENT_STATUS | Incident Status | string | None | True | True | False |
Display Name | Import Incidents [Sentinel] |
Owner | Maltego Technologies GmbH |
Author | Maltego Technologies GmbH |
Data Source | Sentinel |
Transform Name | maltego.jinxpy_sentinel.import_incidents |
Short Description | Imports all Sentinel Incidents |
Input Entities | maltego.sentinel.Instance |
Output Entities | maltego.sentinel.Incident |