Kubernetes Audit Logs
Kubernetes is an open-source container orchestration system for automating software deployment, scaling and management.
LocateRisk Cyber Risk Analysis
LocateRisk Cyberrisk Analysis is an automated, non-invasive assessment tool that evaluates an organization’s external IT infrastructure from an outside perspective.
LockSelf LockPass / LockTransfer / LockFiles
LockSelf is a complete digital vault that enables organizations to secure password management, protect data exchanges, and confidently share with stakeholders.
Lookout Mobile Endpoint Security
Lookout Mobile Endpoint Security is a robust solution designed to protect devices from threats and data breaches in real time.
ManageEngine ADAudit Plus
ManageEngine ADAudit Plus is a robust Active Directory auditing and compliance solution, empowering organizations to track and monitor changes, detect security threats, and ensure regulatory compliance.
Mandrill playbooks
Mandrill is a transactional email platform from Mailchimp.
Mattermost playbooks
Mattermost is a secure, open and flexible collaboration platform.
Microsoft 365 / Office 365
Microsoft Office 365 is an online service, providing the Microsoft Office Products.
Microsoft 365 / Office 365 Message Trace
Microsoft 365 Message trace follows email messages as they travel through your Exchange Online organization.
Microsoft 365 / Office 365 Message Trace (via Graph API)
Microsoft 365 Message trace follows email messages as they travel through your Exchange Online organization.
Microsoft Active Directory - Asset connector (Users)
Microsoft Active Directory (AD) is a directory service developed by Microsoft for Windows domain networks.
Microsoft Active Directory playbooks
Microsoft Active Directory (Microsoft AD), is a directory service developed by Microsoft for Windows domain networks.
Microsoft Always On VPN
This guide will explain how to forward Network Policy Server (NPS) logs to Sekoia.io.
Microsoft Defender XDR
Microsoft Defender XDR (formerly Microsoft 365 Defender) is a unified pre- and post-breach enterprise defense suite that natively coordinates detection, prevention, investigation, and response across endpoints, identities, email, and applications.
Microsoft Defender XDR - Asset connector (devices)
Microsoft Defender is a entreprise defense suite that coordinates detection, prevention, investigation, and response across endpoints, identities, email, and cloud applications.
Microsoft Defender XDR Incidents - Graph API
Microsoft Defender is a entreprise defense suite that coordinates detection, prevention, investigation, and response across endpoints, identities, email, and cloud applications.
Microsoft Defender XDR playbooks
Microsoft Defender for Endpoint is an Endpoint Detection and Response (EDR) product that monitors the security of endpoints.
Microsoft Entra ID - Asset connector (Users)
Microsoft Entra ID (formerly Azure Active Directory) is a cloud-based identity and access management service that provides secure authentication, authorization, and user management services.
Microsoft Entra ID - Event Hubs
Microsoft Entra ID (Azure AD) is a cloud-based Identity and Rights management service.
Microsoft Entra ID - GraphAPI
Microsoft Entra ID (Graph API) is a cloud-based Identity and Rights management service developed and managed by Microsoft Corp.
Microsoft Entra ID - playbooks
Microsoft Entra ID (Azure AD) is an enterprise identity service that provides single sign-on, multifactor authentication, and conditional access to guard against 99.9 percent of cybersecurity attacks.
Microsoft IIS
This setup guide will show you how to forward your Microsoft IIS logs to Sekoia.io by means of a syslog transport channel.
Microsoft Intune
Microsoft Intune helps you protect your workforce's corporate data by managing devices and apps.
Microsoft Remote Server playbooks
To enable this module, please make sure you have properly configured WinRM on remote server.
Microsoft Sentinel (CTI integration)
Microsoft Sentinel is a cloud-native, security information and event management (SIEM) and security orchestration, automation, and response (SOAR) solution.
Microsoft Sentinel (XDR integration)
Microsoft Sentinel is a cloud-native security information and event management (SIEM) service that provides intelligent security analytics for your entire enterprise at cloud scale.
Microsoft Teams playbooks
In Microsoft Teams, playbooks are a set of structured guides and automated workflows designed to help teams handle specific scenarios consistently.
Mimecast Email Security
A secure email gateway to block spam, viruses, and malware.
MISP
The default feed is available as a MISP feed. It can be added to an existing MISP instance by following MISP's documentation.
M&NTIS
M&NTIS is an Adversary Emulation and Cyber Range platform primarily used to test and validate a company's cybersecurity defenses.