Azure.ResourceManager.SecurityInsights.Models Namespace

Classes

AadCheckRequirements

Represents AADIP (Azure Active Directory Identity Protection) requirements check request.

AatpCheckRequirements

Represents AATP (Azure Advanced Threat Protection) requirements check request.

ActivityCustomEntityQuery

Represents Activity entity query.

ActivityEntityQuery

Represents Activity entity query.

ActivityEntityQueryDefinition

The Activity query definitions.

ActivityEntityQueryTemplate

Represents Activity entity query.

ActivityTimelineItem

Represents Activity timeline item.

AddIncidentTaskActionProperties

The AddIncidentTaskActionProperties.

AlertRuleTemplateDataSource

alert rule template data sources.

AnalyticsRuleRunTrigger

Analytics Rule Run Trigger request.

AnomalySecurityMLAnalyticsSettings

Represents Anomaly Security ML Analytics Settings.

AnomalyTimelineItem

Represents anomaly timeline item.

ArmSecurityInsightsModelFactory

Model factory for models.

AscCheckRequirements

Represents ASC (Azure Security Center) requirements check request.

AutomationRuleAddIncidentTaskAction

Describes an automation rule action to add a task to an incident.

AutomationRuleBooleanCondition

The AutomationRuleBooleanCondition.

AutomationRuleModifyPropertiesAction

Describes an automation rule action to modify an object's properties.

AutomationRulePropertyArrayChangedValuesCondition

The AutomationRulePropertyArrayChangedValuesCondition.

AutomationRulePropertyArrayValuesCondition

The AutomationRulePropertyArrayValuesCondition.

AutomationRulePropertyValuesChangedCondition

The AutomationRulePropertyValuesChangedCondition.

AutomationRulePropertyValuesCondition

The AutomationRulePropertyValuesCondition.

AutomationRuleRunPlaybookAction

Describes an automation rule action to run a playbook.

AutomationRuleRunPlaybookActionProperties

The AutomationRuleRunPlaybookActionProperties.

AwsAuthModel

Model for API authentication with AWS.

AwsCloudTrailCheckRequirements

Amazon Web Services CloudTrail requirements check request.

AwsS3CheckRequirements

Amazon Web Services S3 requirements check request.

AwsS3DataConnector

Represents Amazon Web Services S3 data connector.

AzureDevOpsResourceInfo

Resources created in Azure DevOps repository.

BasicAuthModel

Model for API authentication with basic flow - user name + password.

BookmarkConnectedEntity

Expansion result connected entities.

BookmarkEntityMappings

Describes the entity mappings of a single entity.

BookmarkExpandContent

The parameters required to execute an expand operation on the given bookmark.

BookmarkExpandResponseValue

The expansion result values.

BookmarkExpandResult

The entity expansion result operation response.

BookmarkTimelineItem

Represents bookmark timeline item.

BooleanConditionProperties

Describes an automation rule condition that applies a boolean operator (e.g AND, OR) to conditions.

CcpAuthConfig

Base Model for API authentication. Please note CcpAuthConfig is the base class. According to the scenario, a derived class of the base class might need to be assigned here, or this property needs to be casted to one of the possible derived classes. The available derived classes include SecurityInsightsApiKeyAuthModel, AwsAuthModel, BasicAuthModel, GcpAuthModel, GitHubAuthModel, JwtAuthModel, NoneAuthModel, OAuthModel, OracleAuthModel, GenericBlobSbsAuthModel and SessionAuthModel.

CcpResponseConfig

A custom response configuration for a rule.

CodelessApiPollingDataConnector

Represents Codeless API Polling data connector.

CodelessConnectorPollingAuthProperties

Describe the authentication properties needed to successfully authenticate with the server.

CodelessConnectorPollingConfigProperties

Config to describe the polling config for API poller connector.

CodelessConnectorPollingPagingProperties

Describe the properties needed to make a pagination call.

CodelessConnectorPollingRequestProperties

Describe the request properties needed to successfully pull from the server.

CodelessConnectorPollingResponseProperties

Describes the response from the external server.

CodelessUiConnectorConfigProperties

Config to describe the instructions blade.

CodelessUiDataConnector

Represents Codeless UI data connector.

ConnectorAvailability

Connector Availability Status.

ConnectorConnectivityCriteria

Setting for the connector check connectivity.

ConnectorConnectivityCriterion

The criteria by which we determine whether the connector is connected or not. For Example, use a KQL query to check if the expected data type is flowing).

ConnectorCustoms

Customs permissions required for the connector.

ConnectorCustomsPermission

Customs permissions required for the connector.

ConnectorDataType

The data type which is created by the connector, including a query indicated when was the last time that data type was received in the workspace.

ConnectorDefinitionsAvailability

The exposure status of the connector to the customers.

ConnectorDefinitionsPermissions

The required Permissions for the connector.

ConnectorDefinitionsResourceProvider

The resource provider details include the required permissions for the user to create connections. The user should have the required permissions(Read\Write, ..) in the specified scope ProviderPermissionsScope against the specified resource provider.

ConnectorGraphQueries

The graph query to show the current data status.

ConnectorGraphQuery

The graph query to show the volume of data arriving into the workspace over time.

ConnectorInstructionModelBase

Instruction step details.

ConnectorPermissions

Permissions required for the connector.

ConnectorRequiredPermissions

Required permissions for the connector.

ConnectorResourceProvider

Resource provider permissions required for the connector.

ConnectorResourceProviderRequiredPermissions

Required permissions for the connector resource provider that define in ResourceProviders. For more information about the permissions see <see href="https://docs.microsoft.com/en-us/azure/role-based-access-control/role-definitions#actions-format">here</see>.

CustomizableConnectionsConfig

The UiConfig for 'Customizable' connector definition kind.

CustomizableConnectorDefinitionData

Connector definition for kind 'Customizable'.

CustomizableConnectorUiConfig

The UiConfig for 'Customizable' connector definition kind.

CustomPermissionDetails

The Custom permissions required for the connector.

DataConnectorConnectContent

Represents Codeless API Polling data connector.

DataConnectorDataTypeCommon

Common field for data type in data connectors.

DataConnectorRequirementsState

Data connector requirements status.

DataConnectorsCheckRequirements

Data connector requirements properties. Please note DataConnectorsCheckRequirements is the base class. According to the scenario, a derived class of the base class might need to be assigned here, or this property needs to be casted to one of the possible derived classes. The available derived classes include AwsCloudTrailCheckRequirements, AwsS3CheckRequirements, AadCheckRequirements, AatpCheckRequirements, AscCheckRequirements, Dynamics365CheckRequirements, IotCheckRequirements, McasCheckRequirements, MdatpCheckRequirements, MicrosoftPurviewInformationProtectionCheckRequirements, MstiCheckRequirements, MtpCheckRequirements, Office365ProjectCheckRequirements, OfficeAtpCheckRequirements, OfficeIrmCheckRequirements, OfficePowerBICheckRequirements, ThreatIntelligenceCheckRequirements and ThreatIntelligenceTaxiiCheckRequirements.

DataTypeDefinitions

The data type definition.

DcrConfiguration

The configuration of the destination of the data.

Dynamics365CheckRequirements

Represents Dynamics365 requirements check request.

Dynamics365DataConnector

Represents Dynamics365 data connector.

EnrichmentDomainContent

Domain name to be enriched.

EnrichmentDomainWhois

Whois information for a given domain and associated metadata.

EnrichmentDomainWhoisContact

An individual contact associated with this domain.

EnrichmentDomainWhoisContacts

The set of contacts associated with this domain.

EnrichmentDomainWhoisDetails

The whois record for a given domain.

EnrichmentDomainWhoisRegistrarDetails

The registrar associated with this domain.

EnrichmentIPAddressContent

IP address (v4 or v6) to be enriched.

EnrichmentIPGeodata

Geodata information for a given IP address.

EntityAnalytics

Settings with single toggle.

EntityEdges

The edge that connects the entity to the other entity.

EntityExpandContent

The parameters required to execute an expand operation on the given entity.

EntityExpandResponseValue

The expansion result values.

EntityExpandResult

The entity expansion result operation response.

EntityFieldMapping

Map identifiers of a single entity.

EntityGetInsightsContent

The parameters required to execute insights operation on the given entity.

EntityInsightItem

Entity insight Item.

EntityInsightItemQueryTimeInterval

The Time interval that the query actually executed on.

EntityManualTriggerRequestContent

Describes the request body for triggering a playbook on an entity.

EntityQueryItem

An abstract Query item for entity Please note EntityQueryItem is the base class. According to the scenario, a derived class of the base class might need to be assigned here, or this property needs to be casted to one of the possible derived classes. The available derived classes include InsightQueryItem.

EntityQueryItemProperties

An properties abstract Query item for entity.

EntityQueryItemPropertiesDataTypesItem

The EntityQueryItemPropertiesDataTypesItem.

EntityTimelineContent

The parameters required to execute s timeline operation on the given entity.

EntityTimelineItem

Entity timeline Item. Please note EntityTimelineItem is the base class. According to the scenario, a derived class of the base class might need to be assigned here, or this property needs to be casted to one of the possible derived classes. The available derived classes include ActivityTimelineItem, AnomalyTimelineItem, BookmarkTimelineItem and SecurityAlertTimelineItem.

ExpansionEntityQuery

Represents Expansion entity query.

ExpansionResultAggregation

Information of a specific aggregation in the expansion result.

FusionScenarioExclusionPattern

Represents a Fusion scenario exclusion patterns in Fusion detection.

FusionSourceSettings

Represents a supported source signal configuration in Fusion detection.

FusionSourceSubTypeSetting

Represents a supported source subtype configuration under a source signal in Fusion detection.

FusionSubTypeSeverityFilter

Represents severity configuration for a source subtype consumed in Fusion detection.

FusionSubTypeSeverityFiltersItem

Represents a Severity filter setting for a given source subtype consumed in Fusion detection.

FusionTemplateSourceSetting

Represents a source signal consumed in Fusion detection.

FusionTemplateSourceSubType

Represents a source subtype under a source signal consumed in Fusion detection.

FusionTemplateSubTypeSeverityFilter

Represents severity configurations available for a source subtype consumed in Fusion detection.

GcpAuthModel

Model for API authentication for all GCP kind connectors.

GcpAuthProperties

Google Cloud Platform auth section properties.

GcpDataConnector

Represents Google Cloud Platform data connector.

GcpRequestProperties

Google Cloud Platform request section properties.

GenericBlobSbsAuthModel

Model for API authentication for working with service bus or storage account.

GitHubAuthModel

Model for API authentication for GitHub. For this authentication first we need to approve the Router app (Microsoft Security DevOps) to access the GitHub account, Then we only need the InstallationId to get the access token from https://api.github.com/app/installations/{installId}/access_tokens.

IndicatorObservablesItem

An observable of this indicator.

InsightQueryItem

Represents Insight Query.

InsightQueryItemProperties

Represents Insight Query.

InsightQueryItemPropertiesAdditionalQuery

The activity query definitions.

InsightQueryItemPropertiesDefaultTimeRange

The insight chart query.

InsightQueryItemPropertiesTableQuery

The insight table query.

InsightQueryItemPropertiesTableQueryColumnsDefinitionsItem

The InsightQueryItemPropertiesTableQueryColumnsDefinitionsItem.

InsightQueryItemPropertiesTableQueryQueriesDefinitionsItem

The InsightQueryItemPropertiesTableQueryQueriesDefinitionsItem.

InsightQueryItemPropertiesTableQueryQueriesDefinitionsPropertiesItemsItem

The InsightQueryItemPropertiesTableQueryQueriesDefinitionsPropertiesItemsItem.

InsightsTableResult

Query results for table insights query.

InsightsTableResultColumnsItem

The InsightsTableResultColumnsItem.

InstructionStep

Instruction steps to enable the connector.

InstructionStepDetails

Instruction step details, to be displayed in the Instructions steps section in the connector's page in Sentinel Portal.

InstructionSteps

Instruction steps to enable the connector.

IotCheckRequirements

Represents IoT requirements check request.

IotDataConnector

Represents IoT data connector.

JobItem

An entity describing the publish status of a content item.

JwtAuthModel

Model for API authentication with JWT. Simple exchange between user name + password to access token.

LastDataReceivedDataType

Data type for last data received.

ManualTriggerRequestBody

The ManualTriggerRequestBody.

McasCheckRequirements

Represents MCAS (Microsoft Cloud App Security) requirements check request.

McasDataConnector

Represents MCAS (Microsoft Cloud App Security) data connector.

McasDataConnectorDataTypes

The available data types for MCAS (Microsoft Cloud App Security) data connector.

MdatpCheckRequirements

Represents MDATP (Microsoft Defender Advanced Threat Protection) requirements check request.

MdatpDataConnector

Represents MDATP (Microsoft Defender Advanced Threat Protection) data connector.

MicrosoftPurviewInformationProtectionCheckRequirements

Represents MicrosoftPurviewInformationProtection requirements check request.

MicrosoftPurviewInformationProtectionDataConnector

Represents Microsoft Purview Information Protection data connector.

MicrosoftSecurityIncidentCreationAlertRule

Represents MicrosoftSecurityIncidentCreation rule.

MicrosoftSecurityIncidentCreationAlertRuleTemplate

Represents MicrosoftSecurityIncidentCreation rule template.

MLBehaviorAnalyticsAlertRule

Represents MLBehaviorAnalytics alert rule.

MLBehaviorAnalyticsAlertRuleTemplate

Represents MLBehaviorAnalytics alert rule template.

MstiCheckRequirements

Represents Microsoft Threat Intelligence requirements check request.

MstiDataConnector

Represents Microsoft Threat Intelligence data connector.

MtpCheckRequirements

Represents MTP (Microsoft Threat Protection) requirements check request.

MtpDataConnector

Represents MTP (Microsoft Threat Protection) data connector.

NicEntity

Represents an network interface entity.

NoneAuthModel

Model for API authentication with no authentication method - public API.

NrtAlertRule

Represents NRT alert rule.

NrtAlertRuleTemplate

Represents NRT alert rule template.

OAuthModel

Model for API authentication with OAuth2.

Office365ProjectCheckRequirements

Represents Office365 Project requirements check request.

Office365ProjectDataConnector

Represents Office Microsoft Project data connector.

OfficeAtpCheckRequirements

Represents OfficeATP (Office 365 Advanced Threat Protection) requirements check request.

OfficeAtpDataConnector

Represents OfficeATP (Office 365 Advanced Threat Protection) data connector.

OfficeIrmCheckRequirements

Represents OfficeIRM (Microsoft Insider Risk Management) requirements check request.

OfficeIrmDataConnector

Represents OfficeIRM (Microsoft Insider Risk Management) data connector.

OfficePowerBICheckRequirements

Represents Office PowerBI requirements check request.

OfficePowerBIDataConnector

Represents Office Microsoft PowerBI data connector.

OracleAuthModel

Model for API authentication for Oracle.

PropertyArrayConditionProperties

Describes an automation rule condition that evaluates an array property's value.

PublicationFailedError

The error description for why a publication failed.

PullRequestInfo

Information regarding pull request for protected branches.

RecommendedSuggestion

What suggestions should be taken to complete the recommendation.

ReevaluateResult

Reevaluate response object.

RelationshipHint

An object used to help follow relationships from this object to other STIX objects.

RepositoryAccess

Credentials to access repository.

RepositoryAccessProperties

Credentials to access repository.

RepositoryResourceInfo

Resources created in user's repository for the source-control.

RestApiPollerDataConnector

Represents Rest Api Poller data connector.

RestApiPollerRequestConfig

The request configuration.

RestApiPollerRequestPagingConfig

The request paging configuration.

SapSolutionUsageStatistic

Billing statistic about the Microsoft Sentinel solution for SAP Usage.

ScheduledAlertRuleTemplate

Represents scheduled alert rule template.

SecurityAlertTimelineItem

Represents security alert timeline item.

SecurityInsightsAadDataConnector

Represents AADIP (Azure Active Directory Identity Protection) data connector.

SecurityInsightsAatpDataConnector

Represents AATP (Azure Advanced Threat Protection) data connector.

SecurityInsightsAccountEntity

Represents an account entity.

SecurityInsightsAlert

Represents a security alert entity.

SecurityInsightsAlertConfidenceReason

confidence reason item.

SecurityInsightsAlertDetailsOverride

Settings for how to dynamically override alert static details.

SecurityInsightsAlertPropertyMapping

A single alert property mapping to override.

SecurityInsightsAlertRuleActionCreateOrUpdateContent

Action for alert rule.

SecurityInsightsAlertRuleEntityMapping

Single entity mapping for the alert rule.

SecurityInsightsAlertsDataTypeOfDataConnector

Alerts data type for data connectors.

SecurityInsightsApiKeyAuthModel

Model for authentication with the API Key. Will result in additional header on the request (default behavior) to the remote server: 'ApiKeyName: ApiKeyIdentifier ApiKey'. If 'IsApiKeyInPostPayload' is true it will send it in the body of the request and not the header.

SecurityInsightsAscDataConnector

Represents ASC (Azure Security Center) data connector.

SecurityInsightsAutomationRuleAction

Describes an automation rule action. Please note SecurityInsightsAutomationRuleAction is the base class. According to the scenario, a derived class of the base class might need to be assigned here, or this property needs to be casted to one of the possible derived classes. The available derived classes include AutomationRuleAddIncidentTaskAction, AutomationRuleModifyPropertiesAction and AutomationRuleRunPlaybookAction.

SecurityInsightsAutomationRuleCondition

Describes an automation rule condition. Please note SecurityInsightsAutomationRuleCondition is the base class. According to the scenario, a derived class of the base class might need to be assigned here, or this property needs to be casted to one of the possible derived classes. The available derived classes include BooleanConditionProperties, SecurityInsightsPropertyConditionProperties, PropertyArrayConditionProperties, SecurityInsightsPropertyArrayChangedConditionProperties and SecurityInsightsPropertyChangedConditionProperties.

SecurityInsightsAutomationRuleTriggeringLogic

Describes automation rule triggering logic.

SecurityInsightsAwsCloudTrailDataConnector

Represents Amazon Web Services CloudTrail data connector.

SecurityInsightsAzureResourceEntity

Represents an azure resource entity.

SecurityInsightsBookmarkIncidentInfo

Describes related incident information for the bookmark.

SecurityInsightsClientInfo

Information on the client (user or application) that made some action.

SecurityInsightsCloudApplicationEntity

Represents a cloud application entity.

SecurityInsightsDnsEntity

Represents a dns entity.

SecurityInsightsEntity

A class representing the SecurityInsightsEntity data model. Specific entity. Please note SecurityInsightsEntity is the base class. According to the scenario, a derived class of the base class might need to be assigned here, or this property needs to be casted to one of the possible derived classes. The available derived classes include SecurityInsightsAccountEntity, SecurityInsightsAzureResourceEntity, SecurityInsightsHuntingBookmark, SecurityInsightsCloudApplicationEntity, SecurityInsightsDnsEntity, SecurityInsightsFileEntity, SecurityInsightsFileHashEntity, SecurityInsightsHostEntity, SecurityInsightsIotDeviceEntity, SecurityInsightsIPEntity, SecurityInsightsMailboxEntity, SecurityInsightsMailClusterEntity, SecurityInsightsMailMessageEntity, SecurityInsightsMalwareEntity, NicEntity, SecurityInsightsProcessEntity, SecurityInsightsRegistryKeyEntity, SecurityInsightsRegistryValueEntity, SecurityInsightsAlert, SecurityInsightsGroupEntity, SecurityInsightsSubmissionMailEntity and SecurityInsightsUriEntity.

SecurityInsightsEntityQueryCreateOrUpdateContent

Specific entity query that supports put requests. Please note SecurityInsightsEntityQueryCreateOrUpdateContent is the base class. According to the scenario, a derived class of the base class might need to be assigned here, or this property needs to be casted to one of the possible derived classes. The available derived classes include ActivityCustomEntityQuery.

SecurityInsightsEyesOn

Settings with single toggle.

SecurityInsightsFieldMapping

A single field mapping of the mapped entity.

SecurityInsightsFileEntity

Represents a file entity.

SecurityInsightsFileHashEntity

Represents a file hash entity.

SecurityInsightsFileMetadata

Represents a file.

SecurityInsightsFileValidationError

Describes an error encountered in the file during validation.

SecurityInsightsFusionAlertRule

Represents Fusion alert rule.

SecurityInsightsFusionAlertRuleTemplate

Represents Fusion alert rule template.

SecurityInsightsGroupEntity

Represents a security group entity.

SecurityInsightsGroupingConfiguration

Grouping configuration property bag.

SecurityInsightsHostEntity

Represents a host entity.

SecurityInsightsHuntingBookmark

Represents a Hunting bookmark entity.

SecurityInsightsHuntOwner

Describes a user that the hunt is assigned to.

SecurityInsightsIncidentActionConfiguration

The SecurityInsightsIncidentActionConfiguration.

SecurityInsightsIncidentAdditionalInfo

Incident additional data property bag.

SecurityInsightsIncidentConfiguration

Incident Configuration property bag.

SecurityInsightsIncidentEntitiesMetadata

Information of a specific aggregation in the incident related entities result.

SecurityInsightsIncidentEntitiesResult

The incident related entities response.

SecurityInsightsIncidentLabel

Represents an incident label.

SecurityInsightsIncidentOwnerInfo

Information on the user an incident is assigned to.

SecurityInsightsIotDeviceEntity

Represents an IoT device entity.

SecurityInsightsIPEntity

Represents an ip entity.

SecurityInsightsIPEntityGeoLocation

The geo-location context attached to the ip entity.

SecurityInsightsMailboxEntity

Represents a mailbox entity.

SecurityInsightsMailClusterEntity

Represents a mail cluster entity.

SecurityInsightsMailMessageEntity

Represents a mail message entity.

SecurityInsightsMalwareEntity

Represents a malware entity.

SecurityInsightsMetadataAuthor

Publisher or creator of the content item.

SecurityInsightsMetadataCategories

ies for the solution content item.

SecurityInsightsMetadataDependencies

Dependencies for the content item, what other content items it requires to work. Can describe more complex dependencies using a recursive/nested structure. For a single dependency an id/kind/version can be supplied or operator/criteria for complex dependencies.

SecurityInsightsMetadataPatch

Metadata patch request body.

SecurityInsightsMetadataSource

The original source of the content item, where it comes from.

SecurityInsightsMetadataSupport

Support information for the content item.

SecurityInsightsOfficeDataConnector

Represents office data connector.

SecurityInsightsOfficeDataConnectorDataTypes

The available data types for office data connector.

SecurityInsightsPackageCollectionGetAllOptions

The SecurityInsightsPackageCollectionGetAllOptions.

SecurityInsightsProcessEntity

Represents a process entity.

SecurityInsightsProductTemplateCollectionGetAllOptions

The SecurityInsightsProductTemplateCollectionGetAllOptions.

SecurityInsightsPropertyArrayChangedConditionProperties

Describes an automation rule condition that evaluates an array property's value change.

SecurityInsightsPropertyChangedConditionProperties

Describes an automation rule condition that evaluates a property's value change.

SecurityInsightsPropertyConditionProperties

Describes an automation rule condition that evaluates a property's value.

SecurityInsightsRecommendationPatch

Recommendation Fields to update.

SecurityInsightsRegistryKeyEntity

Represents a registry key entity.

SecurityInsightsRegistryValueEntity

Represents a registry value entity.

SecurityInsightsScheduledAlertRule

Represents scheduled alert rule.

SecurityInsightsSettingAnomaliesKind

Settings with single toggle.

SecurityInsightsSubmissionMailEntity

Represents a submission mail entity.

SecurityInsightsTemplateCollectionGetAllOptions

The SecurityInsightsTemplateCollectionGetAllOptions.

SecurityInsightsThreatIntelligence

ThreatIntelligence property bag.

SecurityInsightsThreatIntelligenceIndicatorData

Threat intelligence indicator entity.

SecurityInsightsTIDataConnector

Represents threat intelligence data connector.

SecurityInsightsUriEntity

Represents a url entity.

SecurityInsightsUserInfo

User information that made some action.

SecurityMLAnalyticsSettingsDataSource

security ml analytics settings data sources.

SentinelEntityMapping

A single sentinel entity mapping.

SessionAuthModel

Model for API authentication with session cookie.

SourceControlDeployment

Description about a deployment.

SourceControlDeploymentInfo

Information regarding a deployment.

SourceControlOperationWarning

Warning response structure.

SourceControlOperationWarningBody

Warning details.

SourceControlRepo

Represents a repository.

SourceControlRepository

metadata of a repository.

SourceControlSampleQueries

The sample queries for the connector.

SourceControlServicePrincipal

Service principal metadata.

SourceControlWebhook

Detail about the webhook object.

TeamInformation

Describes team information.

TemplateBaseProperties

Template property bag.

TemplateProperties

Template property bag.

ThreatIntelligenceAlertRule

Represents Threat Intelligence alert rule.

ThreatIntelligenceAlertRuleTemplate

Represents Threat Intelligence alert rule template.

ThreatIntelligenceAppendTags

Array of tags to be appended to the threat intelligence indicator.

ThreatIntelligenceAttackPattern

Represents an attack pattern in Azure Security Insights.

ThreatIntelligenceCheckRequirements

Threat Intelligence Platforms data connector check requirements.

ThreatIntelligenceCount

Count of all the threat intelligence objects on the workspace that match the provided query.

ThreatIntelligenceCountQuery

Represents a query to run on the TI objects in the workspace.

ThreatIntelligenceExternalReference

Describes external reference.

ThreatIntelligenceFilteringCriteria

Filtering criteria for querying threat intelligence indicators.

ThreatIntelligenceGranularMarkingEntity

Describes threat granular marking model entity.

ThreatIntelligenceIdentity

Represents an identity in Azure Security Insights.

ThreatIntelligenceIndicator

Represents an indicator in Azure Security Insights.

ThreatIntelligenceKillChainPhase

Describes threat kill chain phase entity.

ThreatIntelligenceMetric

Describes threat intelligence metric.

ThreatIntelligenceMetricEntity

Describes threat intelligence metric entity.

ThreatIntelligenceMetrics

Threat intelligence metrics.

ThreatIntelligenceObject

Represents a threat intelligence object in Azure Security Insights. Please note ThreatIntelligenceObject is the base class. According to the scenario, a derived class of the base class might need to be assigned here, or this property needs to be casted to one of the possible derived classes. The available derived classes include ThreatIntelligenceAttackPattern, ThreatIntelligenceIdentity, ThreatIntelligenceIndicator, ThreatIntelligenceRelationship and ThreatIntelligenceThreatActor.

ThreatIntelligenceParsedPattern

Describes parsed pattern entity.

ThreatIntelligenceParsedPatternTypeValue

Describes threat kill chain phase entity.

ThreatIntelligenceQuery

Represents a query to run on the TI objects in the workspace.

ThreatIntelligenceQueryCondition

Represents a condition used to query for TI objects.

ThreatIntelligenceQueryConditionClause

Represents a single clause to be evaluated by a NormalizedCondition.

ThreatIntelligenceQueryConditionProperties

Represents a condition used to query for TI objects.

ThreatIntelligenceQuerySortBy

Specifies how to sort the query results.

ThreatIntelligenceRelationship

Represents a relationship in Azure Security Insights.

ThreatIntelligenceSortingCriteria

List of available columns for sorting.

ThreatIntelligenceTaxiiCheckRequirements

Threat Intelligence TAXII data connector check requirements.

ThreatIntelligenceTaxiiDataConnector

Data connector to pull Threat intelligence data from TAXII 2.0/2.1 server.

ThreatIntelligenceThreatActor

Represents a threat actor in Azure Security Insights.

ThreatIntelligenceUserInfo

Data about a user or client application.

UebaSettings

Settings with single toggle.

WorkspaceEnrichmentIPGeodata

Geodata information for a given IP address.

WorkspaceManagerAssignmentItem

An entity describing a content item.

Structs

AnomalySecurityMLAnalyticsSettingsStatus

The anomaly SecurityMLAnalyticsSettings status.

AntispamMailDirection

The directionality of this mail message.

AutomationRuleBooleanConditionSupportedOperator

The AutomationRuleBooleanConditionSupportedOperator.

AutomationRulePropertyArrayChangedConditionSupportedArrayType

The AutomationRulePropertyArrayChangedConditionSupportedArrayType.

AutomationRulePropertyArrayChangedConditionSupportedChangeType

The AutomationRulePropertyArrayChangedConditionSupportedChangeType.

AutomationRulePropertyArrayConditionSupportedArrayConditionType

The AutomationRulePropertyArrayConditionSupportedArrayConditionType.

AutomationRulePropertyArrayConditionSupportedArrayType

The AutomationRulePropertyArrayConditionSupportedArrayType.

AutomationRulePropertyChangedConditionSupportedChangedType

The AutomationRulePropertyChangedConditionSupportedChangedType.

AutomationRulePropertyChangedConditionSupportedPropertyType

The AutomationRulePropertyChangedConditionSupportedPropertyType.

AutomationRulePropertyConditionSupportedOperator

The AutomationRulePropertyConditionSupportedOperator.

AutomationRulePropertyConditionSupportedProperty

The property to evaluate in an automation rule property condition.

ConnectAuthKind

The authentication kind used to poll the data.

ConnectorAvailabilityStatus

The connector Availability Status.

ConnectorConnectivityType

type of connectivity.

ConnectorHttpMethodVerb

The HTTP method, default value GET.

ConnectorProviderName

Provider name.

ConnectorSettingType

The kind of the setting.

DataConnectorAuthorizationState

Describes the state of user's authorization for a connector kind.

DataConnectorLicenseState

Describes the state of user's license for a connector kind.

DeviceImportance

Device importance, determines if the device classified as 'crown jewel'.

EnrichmentType

The EnrichmentType.

EntityItemQueryKind

The EntityItemQueryKind.

EntityProvider

The entity provider that is synced.

EntityQueryKind

The EntityQueryKind.

EntityTemplateQueryKind

The EntityTemplateQueryKind.

EntityTimelineKind

The entity query kind.

EventGroupingAggregationKind

The event grouping aggregation kinds.

HuntStatus

The status of the hunt.

HypothesisStatus

The hypothesis status of the hunt.

IncidentTaskStatus

The IncidentTaskStatus.

IngestionMode

Describes how to ingest the records in the file.

InsightsColumnOutputType

Insights Column type.

MicrosoftSecurityProductName

The alerts' productName on which the cases will be generated.

MtpProvider

The available data providers.

PermissionProviderScope

Permission provider scope.

PollingFrequency

The polling frequency for the TAXII server.

ProviderPermissionsScope

The scope on which the user should have permissions, in order to be able to create connections.

PublicationStatus

Status of the item publication.

RecommendationState

State of recommendation.

RepositoryAccessKind

The kind of repository access credentials.

RestApiPollerRequestPagingKind

Type of paging.

SecurityInsightsAlertConfidenceLevel

The confidence level of this alert.

SecurityInsightsAlertConfidenceScoreStatus

The confidence score calculation status, i.e. indicating if score calculation is pending for this alert, not applicable or final.

SecurityInsightsAlertDetail

Alert detail.

SecurityInsightsAlertProperty

The V3 alert property.

SecurityInsightsAlertRuleEntityMappingType

The V3 type of the mapped entity.

SecurityInsightsAlertRuleTemplateStatus

The alert rule template status.

SecurityInsightsAlertSeverity

The severity of the alert.

SecurityInsightsAlertStatus

The lifecycle status of the alert.

SecurityInsightsAttackTactic

The severity for alerts created by this alert rule.

SecurityInsightsDataTypeConnectionState

Describe whether this data type connection is enabled or not.

SecurityInsightsEntityKind

The kind of the entity.

SecurityInsightsEntityType

The type of the entity.

SecurityInsightsFileDeleteStatus

Indicates whether the file was deleted from the storage account.

SecurityInsightsFileFormat

The format of the file.

SecurityInsightsFileHashAlgorithm

The hash algorithm type.

SecurityInsightsFileImportContentType

The content type of this file.

SecurityInsightsFileImportState

The state of the file import.

SecurityInsightsGroupingMatchingMethod

Grouping matching method. When method is Selected at least one of groupByEntities, groupByAlertDetails, groupByCustomDetails must be provided and not empty.

SecurityInsightsIncidentClassification

The reason the incident was closed.

SecurityInsightsIncidentClassificationReason

The classification reason the incident was closed with.

SecurityInsightsIncidentLabelType

The type of the label.

SecurityInsightsIncidentOwnerType

The type of the owner the hunt is assigned to.

SecurityInsightsIncidentSeverity

The severity of the incident.

SecurityInsightsIncidentStatus

The status of the incident.

SecurityInsightsKillChainIntent

The intent of the alert.

SecurityInsightsKind

The kind of content the metadata is for.

SecurityInsightsMetadataFlag

The boolean value the metadata is for.

SecurityInsightsMetadataPackageKind

The package kind.

SecurityInsightsRegistryHive

the hive that holds the registry key.

SecurityInsightsRegistryValueKind

Specifies the data types to use when storing values in the registry, or identifies the data type of a value in the registry.

SecurityInsightsSourceKind

Source type of the content.

SecurityInsightsSupportTier

Type of support for content item.

Source

The source of the watchlist.

SourceControlContentType

The content type of a source control path.

SourceControlDeploymentFetchStatus

Status while trying to fetch the deployment information.

SourceControlDeploymentResult

Status while trying to fetch the deployment information.

SourceControlDeploymentState

The current state of the deployment.

SourceControlOperationWarningCode

The type of repository.

SourceControlRepoType

The type of repository.

SourceControlVersion

The version of the source control.

ThreatIntelligenceQueryConnective

Represents boolean connectives used to join clauses in conditions.

ThreatIntelligenceQueryOperator

Represents an operator in a ConditionClause.

ThreatIntelligenceQuerySortingDirection

The direction to sort the results by.

ThreatIntelligenceSortingOrder

Sorting order (ascending/descending/unsorted).

ThreatIntelligenceType

The ThreatIntelligenceType.

TriggeredAnalyticsRuleRunProvisioningState

The triggered analytics rule run provisioning state.

TriggersOn

The TriggersOn.

TriggersWhen

The TriggersWhen.

UebaDataSource

The data source that enriched by ueba.

WatchlistSourceType

The sourceType of the watchlist.

WorkspaceManagerConfigurationMode

The current mode of the workspace manager configuration.

Enums

SecurityInsightsAlertRuleTriggerOperator

The operation against the threshold that triggers alert rule.

SecurityInsightsHostOSFamily

The operating system type.

SecurityInsightsMailMessageDeliveryAction

The delivery action of this mail message like Delivered, Blocked, Replaced etc.

SecurityInsightsMailMessageDeliveryLocation

The delivery location of this mail message like Inbox, JunkFolder etc.

SecurityInsightsProcessElevationToken

The elevation token associated with the process.