Forum Discussion

SocInABox's avatar
SocInABox
Iron Contributor
May 24, 2023

ThreatIntelligenceIndicator - correlating with other log feeds in sentinel using kql

Hi there, Has anyone tried using kql to map threat feeds to the entities (or whatever) in the existing alerts in Sentinel?   For example, if I start with this, I get a list of source IPs that matc...

Resources