Integration
High-confidence threat intelligence your Sentinel detections can trust
Curated, high-confidence indicators delivered into Sentinel's threat intelligence, each carrying the malware, C2 and phishing context your analysts need to triage a match fast.
Curated indicators, native in Sentinel TI
Connect PrecisionSec through Sentinel's Threat Intelligence TAXII data connector, and curated indicators flow straight into your workspace's threat intelligence, continuously updated as we publish them.
CSV import is also supported for point-in-time uploads, though the TAXII connector is the recommended path for continuous, automatic updates.
From there they're available to your Analytics rules and hunting queries like any other Sentinel TI, matched against your logs to surface the activity that matters, with malware, C2 and phishing context attached to every hit.

Incidents worth investigating, not false-positive noise
When PrecisionSec indicators match activity in your logs, Sentinel raises incidents automatically. Because the indicators are curated and high-confidence, the incidents that fire are ones worth an analyst's time, not false-positive noise.
Generated incidents use Microsoft Sentinel's Alerts feature and appear under the Incidents subcategory of Threat Management, where your team can kick off playbooks or automation rules.
What you get with the Microsoft Sentinel integration
Thousands of IOCs per day
Curated indicators delivered into your workspace's threat intelligence through Sentinel's TAXII data connector.
High-signal incidents
Curated, high-confidence indicators mean the matches your Analytics rules raise are worth investigating, not false-positive noise.
Context that speeds triage
Each indicator carries malware family, C2 and phishing details (domains, URLs and IPs) and campaign or botnet IDs.
PrecisionSec also provides high-fidelity identification and classification of precursor malware and C2 frameworks such as Cobalt Strike, helping analysts quickly spot clients that have connected to malicious IPs or resolved malicious or phishing domain names.
Get started
Start a Microsoft Sentinel evaluation
Tell us about your Sentinel workspace and detection goals. We'll help you evaluate live, curated PrecisionSec indicators in Microsoft Sentinel with guidance for threat intelligence ingestion, Analytics rules and incident workflows.