-
Notifications
You must be signed in to change notification settings - Fork 3.5k
Solution: TacitRed SentinelOne IOC Automation (Official) #13267
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
|
Hi @mazamizo21, |
9a78d60 to
4895423
Compare
|
Hi @v-shukore, Thank you for the feedback! We've reviewed the Azure Sentinel Solutions repository and found 20+ approved production solutions that are playbook-only without data connector folders. Examples of Approved Playbook-Only SolutionsPure playbook solutions (no data connectors):
Our Solution StructureTacitRed SentinelOne IOC Automation follows the same pattern:
QuestionBased on these 20+ approved playbook-only solutions in the repository, can you confirm that data connector folders are not required for automation-only solutions? Our solution structure is identical to HYAS and other approved playbook-only solutions. Thank you for your guidance! Data443 Risk Mitigation, Inc. |
|
Hi @mazamizo21, the solution now appears well-organized with the appropriate files included. I will review it and inform you if any updates are required. Thank you. |
1f9e4b5 to
9cb6018
Compare
|
Hi @mazamizo21, Please remove the Also, remove the Additionally, create a folder named Image inside the Playbook folder and add all running playbook images into it. Please also correct the format of the Thanks! |
Update: All Requested Changes AppliedHi Microsoft Team, Thank you for your feedback. We have addressed all the requested changes: ✅ 1. Removed 1.0.2 zip package
✅ 2. Moved packageMetadata.json and deploymentParameters.json outside Package folder
✅ 3. Created Images folder in Playbooks with running playbook screenshots
✅ 4. Fixed ReleaseNotes.md format
Thank you! Data443 Risk Mitigation, Inc. |
|
Hi @mazamizo21, could you please grant me the branch access so I can make the necessary changes and commit them. Thanks!! |
|
Hi,
I granted you access. Please accept the invitation here: https://github.com/Data443/Azure-Sentinel/invitations
Thanks for your support, I really appreciate it. I’m hoping we can get the five PRs released soon. I also granted you access to all five PRs for Data443.
The 5 Active PRs
PR
Solution
Source Branch
#13266
TacitRed Defender TI
Data443:feature/tacitred-defender-ti
#13267
TacitRed SentinelOne
Data443:feature/tacitred-sentinelone-v1
#13268
TacitRed CCF
Data443:feature/tacitred-ccf-hub-v2
#13269
TacitRed CrowdStrike
Data443:feature/tacitred-crowdstrike-ioc
#13278
Cyren TI
Data443:feature/cyren-threat-intelligence
Thanks
Taz Jack
…________________________________
From: v-shukore ***@***.***>
Sent: Tuesday, December 30, 2025 7:27 PM
To: Azure/Azure-Sentinel ***@***.***>
Cc: mazamizo21 ***@***.***>; Mention ***@***.***>
Subject: Re: [Azure/Azure-Sentinel] Solution: TacitRed SentinelOne IOC Automation (Official) (PR #13267)
[https://avatars.githubusercontent.com/u/159111145?s=20&v=4]v-shukore left a comment (Azure/Azure-Sentinel#13267)<#13267 (comment)>
Hi @mazamizo21<https://github.com/mazamizo21>, could you please grant me the branch access so I can make the necessary changes and commit them. Thanks!!
—
Reply to this email directly, view it on GitHub<#13267 (comment)>, or unsubscribe<https://github.com/notifications/unsubscribe-auth/A45BJJV2BNM67RSKFA37GPT4ENNC5AVCNFSM6AAAAACONE6L46VHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZTOMBRGQ3TKOJVGI>.
You are receiving this because you were mentioned.Message ID: ***@***.***>
|
|
Verified: This solution does not contain any broken tacitred.com or cyren.com documentation URLs. The only TacitRed references are API endpoints (app.tacitred.com) which are functional and required for the connector to work. |
|
Hi @mazamizo21, we deployed the maintemplate in our Microsoft Sentinel workspace and checked, but the playbook isn't showing or loading, so we're unable to test it. Could you check in your workspace and share a screenshot here? Thanks! |
|
Hi @v-shukore, Thank you for testing the solution! I've identified and fixed the issue with the playbook not showing/loading. Root CauseThe Fix Applied (commit 02582c3)
The playbook should now properly appear in Content Hub after deployment. Please redeploy and let me know if you can see and test the playbook now. Thanks! |
59a4da3 to
abf9afd
Compare
aec9a39 to
831026f
Compare
- Dynamic 7-day lookback matching CCF polling window for cost reduction
- Uses date_from=@{formatDateTime(addDays(utcNow(), -7), 'yyyy-MM-dd')}
- Clean branch with only TacitRed-SentinelOne solution files
8381800 to
9cd6f8b
Compare

Official Data443 Submission
This is the official submission from the Data443 organization for the TacitRed SentinelOne IOC Automation solution.
Changes
This PR supersedes and replaces PR #13243.
Please close #13243 in favor of this one.