Skip to content

Patch 1 ThreatIntelIndicator Table Evolution#15

Open
Elleinshar wants to merge 5 commits intoSlimKQL:mainfrom
Elleinshar:patch-1
Open

Patch 1 ThreatIntelIndicator Table Evolution#15
Elleinshar wants to merge 5 commits intoSlimKQL:mainfrom
Elleinshar:patch-1

Conversation

@Elleinshar
Copy link
Copy Markdown

Hi Steven,
Just a quick propositio for some of your rules based around ThreatIntelligence onboarded inside Sentinel.
They will change the table soon according to this documentation : https://learn.microsoft.com/en-us/azure/sentinel/work-with-stix-objects-indicators

I Added a second Query with just the change to the table ThreatIntelligenceIndicator + some enhancement with filtering on stix type

Hope that helps your work
Thanks

@Elleinshar Elleinshar changed the title Patch 1 Patch 1 ThreatIntelIndicator Table Evolution Aug 9, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant