Skip to main content

Azure Sentinel and Google SecOps (SOAR) integration

  • September 20, 2024
  • 2 replies
  • 176 views

Forum|alt.badge.img+1

Hello Community Members,

I Need encryption details for API connection between Google SecOps SOAR and Azure Sentinel when we integrate these two platform. It would be a great help if someone can share the relevant or supporting documents.  I want to ensure  to that the connectivity can't be tampered by attacks like MITM (Man in the middle attack). 

2 replies

vaskenh
Staff
Forum|alt.badge.img+13
  • Staff
  • September 23, 2024

Hi @dhirajtec .  I've provided a link here to our SecOps integration documentation for Azure Sentinel.  In this documentation, you can find more information about the authentication and authorization parameters including the IAM role granting process, key generation, and further details related to implementing authentication.

https://cloud.google.com/chronicle/docs/soar/marketplace-integrations/microsoft-azure-sentinel


SoarAndy
Staff
Forum|alt.badge.img+12
  • Staff
  • September 27, 2024

In this scenario SecOps is the client, and must adhere to all controls put in place by the platform offering the service, i.e. Sentinel

To understand the API security methods I would suggest studying Sentinel docs (as that is what we comply to)