EN
Request a demo
EN
See all integrations

Microsoft Entra ID

Microsoft Entra ID (formerly Azure Active Directory) is an enterprise identity and access management platform that provides user authentication data, sign-in logs, and security insights to investigate account compromises, suspicious access patterns, and identity-based attacks
Identity & Access Management
4 Analyzers
5 Responders
www.microsoft.com GitHub

Analyzers (4)

MSEntraID GetDirectoryAuditLogs v1.0

Pull Microsoft Entra ID directory audit logs for a user within the specified timeframe.

  • Author: Fabien Bloume, StrangeBee
  • License: AGPL-V3
  • Data Types: mail

MSEntraID GetSignIns v1.0

Pull all Microsoft Entra ID sign ins for a user within the specified amount of time.

  • Author: @jahamilto
  • License: AGPL-V3
  • Data Types: mail

MSEntraID GetUserInfo v1.0

Get information about the user from Microsoft Entra ID, using mail or user identifier (UPN/sAMAccountName/employeeId)

  • Author: Fabien Bloume, StrangeBee
  • License: AGPL-V3
  • Data Types: mail, other, user, username

MSEntraID GetManagedDevicesInfo v1.0

Get Microsoft Intune Managed Device(s) Details from hostname or mail

  • Author: Fabien Bloume, StrangeBee
  • License: AGPL-V3
  • Data Types: mail, hostname

Responders (5)

MSEntraID enableUser v1.0

Enable user in Microsoft Entra ID for a User Principal Name. (mail)

  • Author: nusatanra-self, StrangeBee
  • License: AGPL-V3
  • Data Types: thehive:case_artifact

MSEntraID disableUser v1.0

Disable user in Microsoft Entra ID for a User Principal Name. (mail)

  • Author: nusatanra-self, StrangeBee
  • License: AGPL-V3
  • Data Types: thehive:case_artifact

MSEntraID ForcePasswordReset v1.0

Force password reset at next login for a User Principal Name. (mail)

  • Author: nusatanra-self, StrangeBee
  • License: AGPL-V3
  • Data Types: thehive:case_artifact

MSEntraID revokeSignInSessions v1.1

Invalidates all the refresh tokens issued to applications for a Microsoft Entra ID user (as well as session cookies in a user's browser)

  • Author: Daniel Weiner @dmweiner; revised by @jahamilto; Fabien Bloume, StrangeBee
  • License: AGPL-V3
  • Data Types: thehive:case_artifact

MSEntraID ForcePasswordResetWithMFA v1.0

Force password reset at next login with MFA verification before password change for a User Principal Name. (mail)

  • Author: nusatanra-self, StrangeBee
  • License: AGPL-V3
  • Data Types: thehive:case_artifact
CrowdStrike Falcon
Splunk
VirusTotal
Microsoft Defender for Endpoint
MISP
Google Threat Intelligence
Recorded Future
Microsoft Defender for Office 365
Proofpoint
Shodan
Slack
AbuseIPDB
Cloudflare
URLScan.io
URLhaus
ONYPHE
YARA
CAPA
Telegram
Airtable
AnyRun
Autofocus
AWSLambda
AWX
Axur
BackscatterIO
BinalyzeAIR
Censys
CERTatPassiveDNS
ChainAbuse
CheckPhish
CheckPoint
CiscoUmbrella
CISMCAP
ClamAV
Cluster25
ClusterHawk
Crtsh
CuckooSandbox
CyberChef
Cyberprotect
Cylance
DNS-RPZ
DNSDB
DNSdumpster
DNSLookingglass
DNSSinkhole
DomainTools
DShield
Duo Security
EchoTrail
EclecticIQ
EmergingThreats
EmlParser
FileInfo
FireHOLBlocklists
FoxIO
Gatewatcher CTI
Gmail
GoogleDNS
GRR
HarfangLab
Hashdd
Inoitsu
IntezerCommunity
Investigate
IP-API
IPVoid
isMalicious
IVRE
JAMFProtect
JIRA
Jupyter
KnowBe4
LdapQuery
Lookyloo
LupovisProwl
Mailer
MailIncidentStatus
Malpedia
MalwareClustering
Malwares
MetaDefender
MsgParser
NERD
Nessus
Netcraft
NSRL
Okta
ONYPHEActiveScan
OpenCTI
OrionMalware
PassiveTotal
Patrowl
PhishingInitiative
Pulsedive
QrDecode
Redmine
Robtex
RT4
SecurityTrails
SendGrid
SentinelOne
SinkDB
SophosIntelix
SpamAssassin
SpamhausDBL
StamusNetworks
StopForumSpam
ThreatGrid
ThreatMiner
ThreatResponse
Thunderstorm
TorBlutmagie
TorProject
Triage
UnshortenLink
urlDNA.io
Valhalla
ValidateObservable
Verifalia
VMRay
Vulners
Watcher
Wazuh
WOT
Yeti
ZEROFOX
Zscaler
Abuse Finder
AIL Onion-Lookup
AlienVault OTX
CIRCL Hash Lookup
CIRCL Passive DNS
CIRCL Passive SSL
CIRCL Vulnerability-Lookup
Cisco Secure Endpoint (Formerly AMP for Endpoints)
CrowdSec
Domain Mail SPF DMARC
DomainTools Iris
Elasticsearch
EmailRep
FireEye iSIGHT
Forcepoint WebsensePing
Google Safe Browsing
Google Vision API
GreyNoise
Have I Been Pwned
Hunter.io
Hybrid Analysis
IBM QRadar
IBM X-Force
IPinfo
Joe Sandbox
Kaspersky TIP
Maltiverse
MalwareBazaar
Malware Hash Registry (MHR)
MaxMind
MISP Warning Lists
Mnemonic Passive DNS
n8n
PAN Cortex XDR
PAN Cortex XSOAR
PAN Next Generation Firewall
PAN WildFire
PhishTank
Rapid7 InsightConnect
SEKOIA Intelligence Center
Shuffle
ThreatConnect
Tines
Velociraptor
VirusShare
See how TheHive can help your team
Thousands of analysts worldwide rely on our platform to manage security incidents more efficiently than ever.
See what the buzz is about: