Microsoft Sentinel threat intelligence
Microsoft Sentinel threat intelligence correlates your events with known-bad indicators, so the SOC spends less time hunting through a sea of logs.
- 2,500+Intelligence sources
- 20 minUpdate interval
- 5 minTo full integration
- 100%Made in Europe
What is the Q-Feeds and Microsoft Sentinel integration?
The Q-Feeds integration streams curated cyber threat intelligence into Microsoft Sentinel through the native Threat Intelligence data connector over the open TAXII/STIX 2.1 standard. Indicators of compromise land in Sentinel's ThreatIntelligenceIndicator table, ready to use across analytics rules, hunting queries and workbooks.
Analytics rules then match those indicators against your Microsoft 365, Azure and network logs, raising incidents when known-malicious IPs, domains or URLs appear in your environment, so your team responds with context, faster.
Q-Feeds combines commercial, OSINT and governmental sources, refreshed every 20 minutes, to enrich Microsoft Sentinel with independent, multi-source coverage.
The Multi-Eyed Principle
The Multi-Eyed Principle emphasises using multiple sources of threat intelligence to strengthen the security and effectiveness of your existing firewall. By combining diverse feeds you achieve a more comprehensive, robust defence against cyber threats.
Multiple sources of IOCs
Commercial, OSINT and governmental intelligence combined in one firewall.
Simple 4-step implementation
Implementation is fast and easy with our 4-step manuals, and a proof of concept is completely free.
Integration process overview
Initial setup
Open your Microsoft Sentinel dashboard and navigate to the data connectors section to add a new data connector.
Configure Q-Feeds
Enter your API key and select the threat intelligence feeds you want to integrate, aligned with your security requirements.
Enable data flow
Enable the data flow between Q-Feeds and Microsoft Sentinel to import real-time threat intelligence into your environment.
What we offer
Always ahead
Intelligence that updates every 20 minutes, so you are always ahead of the attackers.
Automatic response
Trust automated response actions and reduce the manual work needed to stop the latest threats.
Categories
Focus on what matters most, phishing, botnets, dark web and more crafted categories.
Knowledge
Knowledge is power when fighting threats. We take the knowledge part off your hands.
Easy implementation
You never did an implementation this easy. Follow our concise implementation guide and you are good to go.
Fewer false positives
We filter out false positives, so you never waste valuable resources chasing noise.
Explore other SIEM integrations
Threat intelligence feeds
Curated IP, URL and domain feeds for your whole stack.
Splunk
Without the right threat intelligence, Splunk is just a log server.
Other SIEMs
Many SIEM vendors support 3rd party threat intelligence.
Enrich my SIEM
Elevate the power of your SIEM solution by adding our intelligence.
Frequently asked questions about the Microsoft Sentinel integration
How does Q-Feeds integrate with Microsoft Sentinel?
Q-Feeds connects through Microsoft Sentinel's Threat Intelligence data connector over the open TAXII/STIX 2.1 standard, so indicators of compromise are imported automatically into your workspace.
Where do the indicators appear in Sentinel?
Imported indicators land in the ThreatIntelligenceIndicator table, where you can use them in analytics rules, hunting queries and workbooks to detect matches in your logs.
Which indicators can I ingest?
You can ingest malicious IP addresses, domains and URLs across categories such as phishing, botnets, malware and dark web threats.
How often is the intelligence updated?
The feeds refresh every 20 minutes, so Microsoft Sentinel always matches your events against current threat intelligence.
Is there a free version?
Yes. The free Community edition lets you test the Microsoft Sentinel integration before upgrading to Plus or Premium for faster, premium intelligence.
Evaluate our intelligence today!
Simplify your security operations, start your free Q-Feeds trial and experience the difference.
Activate free access