ThreatIntelObjects

ThreatIntelObjects Schema #

Table description #

TableSection TableType TableSectionName Description
Usx Regular Microsoft Sentinel Threat Intelligence Generic STIX Object Table.

Table retention #

HotDays ColdDays TotalInteractiveDays
14 76 90

Schema #

Name Description Type
_BilledSize Double
_IsBillable String
_ResourceId A unique identifier for the resource that the record is associated with String
_SubscriptionId A unique identifier for the subscription that the record is associated with String
AdditionalFields The type specifc fields that Sentinel adds. Contains the TLPLevel: white, green, amber, or red. Object
AzureTenantId The tenant that submitted the STIX object. String
Data All object properties, formatted according to STIX specification (https://docs.oasis-open.org/cti/stix/v2.1/os/stix-v2.1-os.pdf). Object
Id A value that uniquely identifies the STIX object. This value is usable with Sentinel APIs. String
IsDeleted A value that indicates whether the data was deleted from Sentinel or not. Boolean
LastUpdateMethod The component that last updated the record. String
Source The name of the source. String
SourceSystem String
StixType The name of this STIX Object. String
TenantId String
TimeGenerated The time of STIX object ingestion. DateTime
Type The name of the table String
WorkspaceId The workspace that submitted the STIX object. String

Schema changes #

Date Action
2024-10-18 Table added to tracking