تخطي إلى المحتوى الرئيسي
Microsoft
separator
https://catalogartifact.azureedge.net/publicartifacts/cayosoftinc.cayosoft_guardian_solution-bbdd46ee-7357-4009-8dd8-25d22cb16cdb/image3_cayosofticoncirclefilled.png

Cayosoft Guardian for Sentinel

بواسطة Cayosoft Inc.

See and stop hybrid identity threats faster with Cayosoft Guardian alerts in Microsoft Sentinel.

Identity threat alerts from Cayosoft Guardian, inside Microsoft Sentinel

Cayosoft Guardian monitors hybrid Active Directory and Microsoft Entra ID environments for identity-specific threats — unauthorized changes, privilege escalation, suspicious authentication activity — across on-premises AD, Entra ID, and cloud applications. These are attack paths that endpoint- and network-focused detections don't typically cover. Without a direct feed, triaging Guardian's alerts requires switching to its own console, separate from an analyst's other telemetry.

Cayosoft Guardian connector for Microsoft Sentinel streams Guardian's identity threat alerts directly into your Sentinel workspace, alongside the rest of your security telemetry, so analysts can detect, investigate, and respond to identity threats without leaving Sentinel.

What you get

  • Real-time hybrid identity visibility. Guardian threat alerts land in Sentinel automatically, so identity risk is never a blind spot in your SOC's view.
  • Faster detection and response. Two pre-built analytic rules automatically convert Guardian alerts into Sentinel incidents — one for core AD/Entra ID identity and infrastructure threats, one for cloud application and service principal threats — each mapped to the right entities (Account, Host, SecurityGroup, DNS, CloudApplication) so investigation starts with context, not a blank screen.
  • One dashboard, not a second console. The included Incidents Dashboard workbook shows severity breakdowns, alert trends, and affected systems at a glance, so analysts get the picture without pivoting away from Sentinel.
  • A clear path to remediation. Every incident links back to the Cayosoft Threat Directory, giving analysts the "what to do next" guidance most SIEM alerts don't include.

What's included

  • Data Connectors: 1 — Cayosoft Guardian Threat Alerts
  • Workbooks: 1 — Cayosoft Guardian Incidents Dashboard
  • Analytic Rules: 2 — Core Identity and Infrastructure Threats; Cloud Application Security Threats


How it connects: Guardian writes threat alerts to the Windows Event Log; the Azure Monitor Agent, via a Data Collection Rule, streams them into a custom Log Analytics table so Sentinel can act on them immediately.

For full setup instructions, see the Cayosoft's Threat Alerts documentation and Release Notes.

Learn more about Microsoft Sentinel

لمحة سريعة

https://catalogartifact.azureedge.net/publicartifacts/cayosoftinc.cayosoft_guardian_solution-bbdd46ee-7357-4009-8dd8-25d22cb16cdb/image1_Sentinel2.png
https://catalogartifact.azureedge.net/publicartifacts/cayosoftinc.cayosoft_guardian_solution-bbdd46ee-7357-4009-8dd8-25d22cb16cdb/image4_Sentinel1.png
العربية (ليبيا)
أيقونة إلغاء الاشتراك في اختيارات خصوصيتك خيارات خصوصيتك
خصوصية صحة المستهلك خريطة الموقع اتصل بنا الخصوصية وملفات تعريف الارتباط شروط الاستخدام حول إعلاناتنا إدارة ملفات تعريف الارتباط