Skip to content

Conversation

@dxniro
Copy link

@dxniro dxniro commented Dec 31, 2025

Change(s):

  • Added a new Microsoft Sentinel Content Hub solution for blacklens.io
  • Includes infrastructure for webhook-based log ingestion using Logic Apps and DCR/DCE
  • Adds a custom Log Analytics table (blacklens_CL)
  • Includes an analytics rule for alert-to-incident creation

Reason for Change(s):

  • Introduces a new partner solution to integrate blacklens.io attack surface monitoring alerts into Microsoft Sentinel

Version Updated:

  • Not applicable (new solution submission)

Testing Completed:

  • Yes
  • Deployed using the included mainTemplate.json
  • Verified successful ingestion into blacklens_CL
  • Confirmed analytics rule creates incidents in Microsoft Sentinel

Checked that the validations are passing and have addressed any issues that are present:

  • Yes

@dxniro dxniro requested review from a team as code owners December 31, 2025 15:32
@dxniro
Copy link
Author

dxniro commented Dec 31, 2025

@microsoft-github-policy-service agree company="snapSEC GmbH"

@v-shukore v-shukore self-assigned this Jan 2, 2026
@v-shukore v-shukore added the New Solution For new Solutions which are new to Microsoft Sentinel label Jan 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

New Solution For new Solutions which are new to Microsoft Sentinel

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants