Implementing TI connectors
Microsoft Sentinel provides a data connector specifically for integration with TIP solutions (both commercial and open source). This section will provide walk-through guidance for the steps required to ingest TI data into Microsoft Sentinel, using MineMeld as an example:
- Enabling the data connector for TIPs
- Registering app permission in Azure Active Directory (AD)
- Configuring the TI feed (MineMeld)
- Confirming that the TI feed data is visible
Note
At the time of writing, this feature is still in public preview. You can enable this solution in your Microsoft Sentinel workspace to gain access to these features; however, you should expect it to change as it is developed.
Let's discuss each of these steps in detail in the following sections.
Enabling the data connector
Use the following steps to enable the data connector for TIPs within Microsoft Sentinel:
- Navigate to the Microsoft Sentinel portal and go to the Data...