Microsoft Sentinel

Microsoft Sentinel threat intelligence

Microsoft Sentinel threat intelligence correlates your events with known-bad indicators, so the SOC spends less time hunting through a sea of logs.

  • 2,500+Intelligence sources
  • 20 minUpdate interval
  • 5 minTo full integration
  • 100%Made in Europe
What it is

What is the Q-Feeds and Microsoft Sentinel integration?

The Q-Feeds integration streams curated cyber threat intelligence into Microsoft Sentinel through the native Threat Intelligence data connector over the open TAXII/STIX 2.1 standard. Indicators of compromise land in Sentinel's ThreatIntelligenceIndicator table, ready to use across analytics rules, hunting queries and workbooks.

Analytics rules then match those indicators against your Microsoft 365, Azure and network logs, raising incidents when known-malicious IPs, domains or URLs appear in your environment, so your team responds with context, faster.

Q-Feeds combines commercial, OSINT and governmental sources, refreshed every 20 minutes, to enrich Microsoft Sentinel with independent, multi-source coverage.

How it works

The Multi-Eyed Principle

The Multi-Eyed Principle emphasises using multiple sources of threat intelligence to strengthen the security and effectiveness of your existing firewall. By combining diverse feeds you achieve a more comprehensive, robust defence against cyber threats.

Multiple sources of IOCs

Commercial, OSINT and governmental intelligence combined in one firewall.

Simple 4-step implementation

Implementation is fast and easy with our 4-step manuals, and a proof of concept is completely free.

Integration process

Integration process overview

  1. Initial setup

    Open your Microsoft Sentinel dashboard and navigate to the data connectors section to add a new data connector.

  2. Configure Q-Feeds

    Enter your API key and select the threat intelligence feeds you want to integrate, aligned with your security requirements.

  3. Enable data flow

    Enable the data flow between Q-Feeds and Microsoft Sentinel to import real-time threat intelligence into your environment.

Features

What we offer

Always ahead

Intelligence that updates every 20 minutes, so you are always ahead of the attackers.

Automatic response

Trust automated response actions and reduce the manual work needed to stop the latest threats.

Categories

Focus on what matters most, phishing, botnets, dark web and more crafted categories.

Knowledge

Knowledge is power when fighting threats. We take the knowledge part off your hands.

Easy implementation

You never did an implementation this easy. Follow our concise implementation guide and you are good to go.

Fewer false positives

We filter out false positives, so you never waste valuable resources chasing noise.

FAQ

Frequently asked questions about the Microsoft Sentinel integration

How does Q-Feeds integrate with Microsoft Sentinel?

Q-Feeds connects through Microsoft Sentinel's Threat Intelligence data connector over the open TAXII/STIX 2.1 standard, so indicators of compromise are imported automatically into your workspace.

Where do the indicators appear in Sentinel?

Imported indicators land in the ThreatIntelligenceIndicator table, where you can use them in analytics rules, hunting queries and workbooks to detect matches in your logs.

Which indicators can I ingest?

You can ingest malicious IP addresses, domains and URLs across categories such as phishing, botnets, malware and dark web threats.

How often is the intelligence updated?

The feeds refresh every 20 minutes, so Microsoft Sentinel always matches your events against current threat intelligence.

Is there a free version?

Yes. The free Community edition lets you test the Microsoft Sentinel integration before upgrading to Plus or Premium for faster, premium intelligence.

Evaluate our intelligence today!

Simplify your security operations, start your free Q-Feeds trial and experience the difference.

Activate free access