The Arbala Security Multi-tool is an extension that allows you to submit IOCs directly from your web browser into your Azure Sentinel environment. Simply copy and paste a block of text from a tweet, an email, or an news article containing the IOCs into the tool. It will extract the valid IOC values and send them into your Azure Sentinel Threat Indicator Table! The tool is currently in alpha and will allow you submit multiple domain names, IPv4 addresses, and MD5/SHA256 file hashes. Your submission can also include a custom description for the IOCs, TLP level, confidence score, and any number of tags separated by comma or whitespace.
We will be updating the tool frequently to bring exciting new features. Our package is open source and we welcome suggestions!
Our most recent addition has been added support for requests containing more than 100 IOCs, which is Azure Sentinel's current API limit. The Arbala Security Multi-tool will now chunk these larger requests and send these as batches, allowing you to submit as many IOCs at one time as you need.
Please visit our Github page at https://github.com/Arbala-Security/Multitool-Extension for instructions on configuring the App Registration to allow the extension API access to your Sentinel Threat Indicator table. The link is also available in the Configuration section of the extension.
Change Log
0.0.4.1- Patch to input parsing on the Azure Sentinel IOC Submission page.
0.0.4.0 - Submission of requests larger than 100 items, tag fields, and encryption of local storage has been added.
0.0.3.0 - Submission of IPv4 addresses, and MD5/SHA256 hashes has been added.
0.0.2.1 - Submission of multiple Domains at once along with Confidence Scores and TLP indicators has been added!
Extore is a team of professionals who are passionate about creating extensions for web browsers. This devotion also gives us opportunity to appreciate work of other people. We get inspired by useful, open source extensions made by developers all over the world. Our strong belief is that one should share helpful add-ons with others. That’s why we’d like to present you our ever-growing list of favourite extensions that have inspired us. Moreover, as you probably have already learned, sometimes struggling for the best brings an end to the good. Talking about add-ons it often turns out that an upgrade is worse then previous version. Also it can become really tricky to get back to the beloved version of your favourite extension. That’s why we’re going to make not only the latest, but all versions of our favourite (and we hope yours too) add-ons available for download. No more compromises, just stick to the version you really like!