Forum Discussion

scrappy67's avatar
scrappy67
Copper Contributor
Nov 29, 2020

Developer Question - Build own agents to use Sentinel intelligence?

I have a developer that would like to create a niche product to utilize information within the Sentinel intelligence feeds such as match urls to bad or malicious sources. 

something like Malwarebytes or what Microsoft does with ATP Defender.

 

it is again selective purpose but can we use the Security Graph API for this and if so is it allowed, costs?

We are new to developing with Microsoft cloud security services.

 

is there a bad reason or simply too expensive ... need some help in finding answers if it is a viable solution for us?

Cheers

  • scrappy67's avatar
    scrappy67
    Copper Contributor

    scrappy67 

    To simplify the question even more:

    Can we develop our own agents to send telemetry data to Sentinel and how do we go about calculating costs?

    lastly, is this permitted as we would like to develop our own security agent for a particular purpose but utilize Microsoft Security intelligence?

     

    • GaryBushey's avatar
      GaryBushey
      Bronze Contributor

      scrappy67 You can send your own information into Azure Sentinel but keep in mind that the data will show up in a custom table.  You can populate one of the non-custom tables like SecurityEvents.  The costs would be based on how much data is ingested, just like any other feed.

       

      AFAIK there is no reason you cannot utilize Microsoft Security Intelligence although I don't work for Microsoft and I am by no means a licensing expert.

Resources