table

ThreatIntelObjects

ThreatIntelObjects stores generic STIX objects imported into Microsoft Sentinel threat intelligence, such as attack patterns, threat actors, identities, and relationships.

tablesCurrent

Relationships

Schema

FieldTypeDescriptionCopy
AdditionalFieldsdynamicType-specific fields that Sentinel adds, including TLP level.
AzureTenantIdstringTenant that submitted the STIX object.
_BilledSizerealRecord size in bytes.
DatadynamicAll object properties formatted according to the STIX specification.
IdstringUnique identifier for the STIX object, usable with Sentinel APIs.
_IsBillablestringSpecifies whether ingestion is billable.
IsDeletedboolIndicates whether the object was deleted from Sentinel.
LastUpdateMethodstringComponent that last updated the record.
_ResourceIdstringUnique identifier for the resource associated with the record.
SourceSystemstringType of agent or source system that collected the event.
StixTypestringName of the STIX object type.
_SubscriptionIdstringSubscription associated with the record.
TenantIdstringLog Analytics workspace ID.
TimeGenerateddatetimeTime of STIX object ingestion.
TypestringName of the table.
WorkspaceIdstringWorkspace that submitted the STIX object.