ThreatIntelObjects
ThreatIntelObjects stores generic STIX objects imported into Microsoft Sentinel threat intelligence, such as attack patterns, threat actors, identities, and relationships.
tablesCurrent
Relationships
Schema
| Field | Type | Description | Copy |
|---|---|---|---|
AdditionalFields | dynamic | Type-specific fields that Sentinel adds, including TLP level. | |
AzureTenantId | string | Tenant that submitted the STIX object. | |
_BilledSize | real | Record size in bytes. | |
Data | dynamic | All object properties formatted according to the STIX specification. | |
Id | string | Unique identifier for the STIX object, usable with Sentinel APIs. | |
_IsBillable | string | Specifies whether ingestion is billable. | |
IsDeleted | bool | Indicates whether the object was deleted from Sentinel. | |
LastUpdateMethod | string | Component that last updated the record. | |
_ResourceId | string | Unique identifier for the resource associated with the record. | |
SourceSystem | string | Type of agent or source system that collected the event. | |
StixType | string | Name of the STIX object type. | |
_SubscriptionId | string | Subscription associated with the record. | |
TenantId | string | Log Analytics workspace ID. | |
TimeGenerated | datetime | Time of STIX object ingestion. | |
Type | string | Name of the table. | |
WorkspaceId | string | Workspace that submitted the STIX object. |