Azure Firewall Threat Intelligence Alert

azure

Classification:

threat-intel

Set up the azure integration.

Goal

Detect when an Azure firewall threat intelligence alert is received.

Strategy

Monitor Azure Network Diagnostic logs and detect when @evt.name is equal to AzureFirewallThreatIntelLog.

Triage and response

  1. Inspect the threat intelligence log.
  2. Investigate the activity from this IP address.
PREVIEWING: joe.farro/djm/djm-732-rm-dd-api-ips-databricks-docs