SpyCloud Enterprise Threat Protection for Sentinel
by SpyCloud, Inc.
Easily leverage your SpyCloud Enterprise Protection data in Microsoft Sentinel
Stolen credentials and malware-infected devices are the entry point for the majority of account takeover and ransomware attacks. SpyCloud Enterprise Threat Protection closes that gap by feeding recaptured darknet and criminal-source exposure data directly into Microsoft Sentinel, then automating the response so your team can act on it in minutes instead of days.
What this solution does
• Data Connector — Ingests SpyCloud Watchlist data into your Log Analytics workspace via the Codeless Connector Framework, including compromised credential records and infected machine data tied to your monitored users, domains, and assets, plus an optional SpyCloud Compass daily feed. Breach catalog metadata is included for context and correlation, so analysts can immediately see where and when an exposure originated.
• Built-in Parsers & Analytics — Normalizes ingested data into Sentinel-native tables with two KQL parsers, and includes three analytic rule templates that automatically surface high-severity exposures as incidents. Rules are graded by severity — breached users, malware-infected devices, and identity access records — so your team triages the most urgent exposures first.
• Conditional Access Playbook — Automatically notifies affected users, forces a password reset on next sign-in, disables the account, adds the user to a designated Conditional Access group, and revokes active sessions — configurable per severity.
• Microsoft Defender Playbook — Isolates compromised or infected machines, pushes indicators of compromise (IOCs) into Microsoft Defender, and creates a corresponding Sentinel incident with full context and email notification.
• Session Revoke Playbook — Automatically revokes all active Microsoft Entra sign-in sessions for users named in an identity access record exposure: stolen session cookies, OAuth tokens, and SSO credentials that grant account access without a password and therefore survive a password reset.
Requirements
• Active Microsoft Sentinel workspace
• SpyCloud Enterprise Protection API key
• Microsoft Sentinel Contributor role for connector deployment
• Azure App Registration with appropriate permissions for the Conditional Access, Microsoft Defender, and Session Revoke playbooks
• Microsoft Sentinel Responder role for the playbook managed identities, and Microsoft Sentinel Automation Contributor granted to the Azure Security Insights service principal on the target resource group (required for playbooks that create their own automation rules)
• Data collection rule immutable ID and data collection endpoint URL for playbook execution logging, with Monitoring Metrics Publisher assigned to the App Registration
Support
SpyCloud — integrations@spycloud.com | https://portal.spycloud.com