- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
on 04-24-2019 04:20 AM - edited on 10-28-2019 10:58 AM by Retired Member
MineMeld can be used to aggregate multiple threat intelligence feeds and extend to your Microsoft Security products via the Microsoft Graph Security API. Azure Sentinel is one of the first Microsoft Security products to ingest IOCs from the Graph Security API for use in alerting and hunting.
The Microsoft Graph Security API supports the following types of Indicators of Compromise (IOCs):
There are three steps to connecting MineMeld to the Microsoft Graph Security API:
Please note, the Application ID and Object ID will be used to configure both the threat feed in your Microsoft Graph Security API tenant and the MineMeld extension.
Azure Sentinel can be used to validate this is setup correctly. Please review these instructions for turning on Threat Intelligence in Azure Sentinel. NOTE: The MineMeld extension currently specifies the Azure Sentinel service, so that is already done for you.
Once you have this setup, you can review the indicators in the logs section:
@Lorenzobaesso Are you sure you followed the previous steps correctly? Are you sure your Minemeld box has access to GitHub? Is there anything doing SSL inspection that might prevent this? Also, have you tried restarting the MineMeld engine under the System tab or made sure you don't have any pending "commits" on the Config page?
Feel free to PM me
Jon Bub
@JonBub Thank you for your reply. Restarting the VM itself did the trick; I guess restarting the engine wasn't enough in my case.
I am happy to confirm that I could test the integration end-to-end without any other issues! 🙂
Additionally I would like to share the configuration I currently have for MS Graph API:
Link to the configuration file: MineMeld_config.txt
Thank you all for the great work
Lorenzo
Hello
I have setup Minemeld as per your the above instructions. It worked for a day and i started the Threat Intel information in Azure Sentinel. But after a day, it stopped working and I can't see any new threat intel in the Sentinel. I have rebooted Minemeld server few times, changed the config few times, nothing seems to be working. Any help to diagnose the issue would be much appreciated.
Thanks
Malli
I don't think you did anything wrong to make it stop working. I think on the evening of the 2nd of July the SecGraphAPI in Sentinel/Azure got a bug. The indicators are being send over succesfully but they do NOT show up in the threatintelligenceindicator logs. I thought I was going crazy, too. I opened a thread in the Azure community and hopefully it's not just me.
Does this information in the link below line up with the issue you are having?
@IsaacKuf I configured the extension last week for the first time and did not encounter any specific issue. Did you check your outgoing firewall rules ? Registered application privileges ? Conditionnal access rules ?