Skip to content

Commit

Permalink
Updated README with tags
Browse files Browse the repository at this point in the history
  • Loading branch information
eepstain committed Jul 11, 2024
1 parent 2d87a6c commit 3b20842
Showing 1 changed file with 6 additions and 1 deletion.
7 changes: 6 additions & 1 deletion Packs/MicrosoftGraphSecurity/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,14 +3,18 @@ This pack includes XSIAM content.
<~XSIAM>
* Pay attention: Timestamp parsing is available for UTC timezone, using the **yyyy-mm-ssTHH:MM:SS.3msZ** format.

<details>
<summary>Collecting Alerts</summary>
Use the Microsoft Graph integration to fetch and manage alerts from various Microsoft security sources, such as:
- Microsoft 365 Defender unified alerts API
- Microsoft Defender for Endpoint
- Microsoft Defender for Office 365
- Microsoft Defender for Identity
- Microsoft Defender for Cloud Apps
- Microsoft Purview Data Loss Prevention (including any future new signals integrated into M365D).

</details>
<details>
<summary>Graph Security Log collection</summary>
## What does this pack do?
- This content XDM mappings are based on the Office 365 integration, in the Graph API section enable **alertv2** [Doc](https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-Administrator-Guide/Ingest-Logs-from-Microsoft-Office-365).
- Unify and standardize alert tracking
Expand All @@ -19,6 +23,7 @@ Use the Microsoft Graph integration to fetch and manage alerts from various Micr
- Unlock security context to drive investigation
- Automate security workflows and reporting
- Get deep insights to train security solutions
- </details>
</~XSIAM>

<~XSOAR>
Expand Down

0 comments on commit 3b20842

Please sign in to comment.