FileWall® for Microsoft 365 — Microsoft Sentinel Connector
seuraavan mukaan: odix
Ingest FileWall® events into Microsoft Sentinel across Exchange, SharePoint, OneDrive & Teams
Bring FileWall®'s file-threat telemetry directly into your SIEM — no infrastructure required.
FileWall® for Microsoft 365 protects organizations from malicious files and email attachments using patented CDR (Content Disarm & Reconstruction) technology. This Microsoft Sentinel connector closes the visibility gap by streaming FileWall®'s blocking and sanitization events into Sentinel, so SOC teams can correlate file-threat activity with the rest of their security data — without managing any additional compute or custom code.
How it works
Paste a single FileWall® API key and the connector auto-creates four polling connections — one for each Microsoft 365 surface (Exchange, SharePoint, OneDrive, Teams). Sentinel's built-in REST API Poller pulls events every five minutes using a codeless connector framework (CCF/CCP), writing them into two custom log tables:
· FilewallExchange_CL — email events, including per-attachment detail
· FilewallFile_CL — file events across SharePoint, OneDrive, and Teams
What's included out of the box
✅ One-click connection — paste API key, click Connect, done.
✅ Two ASIM-aligned parsers that normalize raw logs into standard schemas:
· FilewallM365ExchangeEvent (Alert schema)
· FilewallM365FileEvent (FileEvent schema)
✅ Two High-severity analytic rules, running every 5 minutes and auto-creating incidents:
· FileWall® – Blocked emails (Exchange threats blocked)
· FileWall® – Blocked files (SharePoint / OneDrive / Teams)
· Both mapped to MITRE ATT&CK T1048 (Exfiltration)
✅ Overview workbook — events by platform, events over time, top senders with blocked emails, and detailed attachment/file tables with file-size parsing, SHA1/SHA256 hashes, and block reasons.
✅ Rich event detail — block reasons, policy name/ID, admin-release tracking (who released a file, when, and why), and original vs. sanitized file hashes that signal CDR reconstruction activity.
Key use cases
· Detection & incident response on malicious or policy-violating attachments and files across M365
· Threat hunting & forensics — query who sent/received blocked content, pivot on file hashes as IOCs
· CDR activity monitoring — track files FileWall® neutralized (original vs. new hash confirms content was disarmed)
· Unified M365 visibility — single pane of glass across Exchange + SharePoint + OneDrive + Teams
Why codeless matters
Unlike Azure Function–based connectors, there is nothing to host, patch, or pay compute for. The connector runs entirely on Sentinel's infrastructure, resulting in lower TCO and zero maintenance overhead.
Requirements
· Microsoft 365 subscription with FileWall® deployed
· Microsoft Sentinel workspace (Read + Write permissions)
· FileWall® API key (available from the FileWall® admin portal)