Latest Version: beta - Release Date:
- Microsoft Sentinel.
- VMRay Analyzer, VMRay FinalVerdict, VMRay TotalInsight.
- Microsoft Azure
- Azure functions with Flex Consumption plan. Reference: https://learn.microsoft.com/en-us/azure/azure-functions/flex-consumption-plan
- Azure Logic App with Cunsumption plan. Reference: https://learn.microsoft.com/en-us/azure/logic-apps/logic-apps-pricing#consumption-multitenant
- Azure storage with Standard general-purpose v2.
-
In VMRay Console, you must create a Connector API key.Create it by following the steps below:
- Create a user dedicated for this API key (to avoid that the API key is deleted if an employee leaves)
- Create a role that allows to "View shared submission, analysis and sample" and "Submit sample, manage own jobs, reanalyse old analyses and regenerate analysis reports".
- Assign this role to the created user
- Login as this user and create an API key by opening Settings > Analysis > API Keys.
- Please save the keys, which will be used in confiring the Azure Function.
- Open https://portal.azure.com/ and search
Microsoft Entra ID
service.
- Click
Add->App registration
.
- Enter the name of application and select supported account types and click on
Register
.
- In the application overview you can see
Application Name
,Application ID
andTenant ID
.
- We need secrets to access programmatically. For creating secrets
- Click
Manage->Certificates & secrets
tab - Click
Client secrets
tab - Click
New client secret
button - Enter description and set expiration date for secret
- Click
- Use Secret
Value
to configure connector.
- Open https://portal.azure.com/ and search
Microsoft Sentinel
service. - Goto
Settings
->Workspace Setting
- Goto
Access Control(IAM)
->Add
- Search for
Microsoft Sentinel Contributor
and clickNext
- Select
User,group or service principle
and click onselect members
. - Search for the app name created above and click on
select
. - Click on
Next
- Click on
Review + assign
-
Click on below button to deploy VMRay Sentinel Feed app:
-
Please provide the values accordingly.
Fields | Description |
---|---|
Subscription | Select the appropriate Azure Subscription |
Resource Group | Select the appropriate Resource Group |
Region | Based on Resource Group this will be uto populated |
Function Name | Please provide a function name if needed to change the default value |
Vmray Base URL | VMRay Base URL |
Vmray API Key | VMRay API Key |
Azure Client ID | Enter the Azure Client ID created in the App Registration Step |
Azure Client Secret | Enter the Azure Client Secret created in the App Registration Step |
Azure Tenant ID | Enter the Azure Tenant ID of the App Registration |
Azure Workspacse ID | Enter the Azure Workspacse ID |
App Insights Workspace Resource ID | Go to Log Analytics workspace -> Settings -> Properties , Copy Resource ID and paste here |
- Once you provide the above values, please click on
Review + create
button.
- Download the zip package from the
VMRayThreatIntelligence
folder. - Open https://portal.azure.com/ and search
Storage accounts
service.
- Open the storage account, the name starts with
vmraystorage
. - Go to
Storage Browser
->Blob Containers
, click on container, the name starts withvmraycontainer
. - Click on
Switch to Access key
.
- Upload the downloaded zip package to the container.
-
Click on below button to deploy VMRay Sentinel Feed app:
-
Please provide the values accordingly
Fields | Description |
---|---|
Subscription | Select the appropriate Azure Subscription |
Resource Group | Select the appropriate Resource Group |
Region | Based on Resource Group this will be uto populated |
Function Name | Please provide a function name if needed to change the default value |
Vmray Base URL | VMRay Base URL |
Vmray API Key | VMRay API Key |
Resubmit | If true file will be resubmitted to VMRay |
App Insights Workspace Resource ID | Go to Log Analytics workspace -> Settings -> Properties , Copy Resource ID and paste here |
- Once you provide the above values, please click on
Review + create
button.
- Click on below button
- It will redirect to configuration page
- please click on
Review + create
button
- Click on below button
- It will redirect to configuration page
- please click on
Review + create
button
- Open https://portal.azure.com/ and search
Microsoft Sentinel
service. - Goto
Settings
->Workspace Setting
- Goto
Access Control(IAM)
->Add
- Search for
Microsoft Sentinel Contributor
and clickNext
- Select
User,group or service principle
and click onselect members
. - Search for the Logic app name deployed above and click on
select
. - Click on
Next
- Click on
Review + assign