Skip to content

Commit 31c3570

Browse files
committed
Adding customer intents - Austin's files
1 parent ef533b7 commit 31c3570

35 files changed

+140
-0
lines changed

articles/sentinel/billing.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,10 @@ appliesto:
1212
- Microsoft Sentinel in the Azure portal
1313
- Microsoft Sentinel in the Microsoft Defender portal
1414
#Customer intent: As a SOC manager, plan Microsoft Sentinel costs so I can understand and optimize the costs of my SIEM.
15+
16+
17+
#Customer intent: [AI]As a financial planner for cloud security solutions, I want to understand Microsoft Sentinel's pricing and billing models so that I can optimize costs and accurately forecast expenses.
18+
1519
---
1620

1721
# Plan costs and understand Microsoft Sentinel pricing and billing

articles/sentinel/bookmarks.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,10 @@ ms.collection: usx-security
99
appliesto:
1010
- Microsoft Sentinel in the Azure portal
1111
- Microsoft Sentinel in the Microsoft Defender portal
12+
13+
14+
#Customer intent: [AI]As a security analyst, I want to create and manage hunting bookmarks so that I can preserve and collaborate on relevant threat investigation data.
15+
1216
---
1317

1418
# Keep track of data during hunting with Microsoft Sentinel

articles/sentinel/ci-cd-custom-content.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,10 @@ ms.topic: conceptual
99
ms.date: 8/24/2022
1010
ms.custom: template-concept
1111
#Customer intent: As a SOC collaborator or MSSP analyst, I want to manage dynamic Sentinel workspace content based on source control repositories for continuous integration and continuous delivery (CI/CD). Specifically as an MSSP content manager, I want to deploy one solution to many customer workspaces and still be able to tailor custom content for their environments.
12+
13+
14+
#Customer intent: [AI]As a security operations engineer, I want to manage and deploy Microsoft Sentinel content as code using CI/CD pipelines so that I can automate updates and ensure consistent configurations across workspaces.
15+
1216
---
1317

1418
# Manage custom content with Microsoft Sentinel repositories (public preview)

articles/sentinel/ci-cd-custom-deploy.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,10 @@ ms.topic: how-to
77
ms.date: 3/13/2024
88
ms.author: austinmc
99
#Customer intent: As a SOC collaborator or MSSP analyst, I want to know how to optimize my source control repositories for continuous integration and continuous delivery (CI/CD). Specifically as an MSSP content manager, I want to know how to deploy one solution to many customer workspaces and still be able to tailor custom content for their environments.
10+
11+
12+
#Customer intent: [AI]As a DevOps engineer, I want to customize repository deployment workflows and pipelines so that I can control deployment triggers, paths, and parameter mappings for efficient and tailored content deployment to cloud workspaces.
13+
1014
---
1115

1216
# Customize repository deployments (Public Preview)

articles/sentinel/ci-cd.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,10 @@ appliesto:
1111
- Microsoft Sentinel in the Microsoft Defender portal
1212
ms.collection: usx-security
1313
#Customer intent: As a SOC collaborator or MSSP analyst, I want to know how to connect my source control repositories for continuous integration and continuous delivery (CI/CD). Specifically as an MSSP content manager, I want to know how to deploy one solution to many customer workspaces and still be able to tailor custom content for their environments.
14+
15+
16+
#Customer intent: [AI]As a security operations analyst, I want to deploy and manage custom content from my source control repository to my SIEM platform so that I can streamline updates and maintain consistency across my security monitoring environment.
17+
1418
---
1519

1620
# Deploy custom content from your repository (Public preview)

articles/sentinel/connect-mdti-data-connector.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,10 @@ appliesto:
1212
- Microsoft Sentinel in the Microsoft Defender portal
1313
ms.collection: usx-security
1414
#customer intent: As a SOC admin, I want to utilize the best threat intelligence from Microsoft, so I can generate high fidelity alerts and incidents.
15+
16+
17+
#Customer intent: [AI]As a security analyst, I want to enable the data connector for Microsoft Defender Threat Intelligence so that I can ingest high fidelity indicators of compromise into my Microsoft Sentinel workspace for enhanced threat monitoring and response.
18+
1519
---
1620

1721
# Enable data connector for Microsoft Defender Threat Intelligence

articles/sentinel/connect-threat-intelligence-taxii.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,10 @@ appliesto:
1111
- Microsoft Sentinel in the Microsoft Defender portal
1212
ms.collection: usx-security
1313
#customer intent: As a SOC admin, I want to connect Microsoft Sentinel to a STIX/TAXII feed to ingest threat intelligence, so I can generate alerts incidents.
14+
15+
16+
#Customer intent: [AI]As a security analyst, I want to integrate STIX/TAXII threat intelligence feeds into my SIEM platform so that I can enhance threat detection and response capabilities.
17+
1418
---
1519

1620
# Connect Microsoft Sentinel to STIX/TAXII threat intelligence feeds

articles/sentinel/connect-threat-intelligence-tip.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,10 @@ appliesto:
1111
- Microsoft Sentinel in the Microsoft Defender portal
1212
ms.collection: usx-security
1313
#customer intent: As a SOC admin, I want to use a Threat Intelligence Platform solution to ingest threat intelligence, so I can generate alerts incidents.
14+
15+
16+
#Customer intent: [AI]As a security analyst, I want to integrate my threat intelligence platform with a SIEM solution so that I can centralize and enhance threat detection and response.
17+
1418
---
1519

1620
# Connect your threat intelligence platform to Microsoft Sentinel

articles/sentinel/connect-threat-intelligence-upload-api.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,10 @@ appliesto:
1111
- Microsoft Sentinel in the Microsoft Defender portal
1212
ms.collection: usx-security
1313
#customer intent: As a SOC admin, I want to connect my Threat Intelligence Platform with the upload indicators API to ingest threat intelligence, so I can utilize the benefits of this updated API.
14+
15+
16+
#Customer intent: [AI]As a security analyst, I want to integrate my threat intelligence platform with a SIEM solution so that I can centralize and enhance threat detection and response capabilities.
17+
1418
---
1519

1620
# Connect your threat intelligence platform to Microsoft Sentinel with the upload indicators API

articles/sentinel/create-codeless-connector-legacy.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,10 @@ author: austinmccollum
55
ms.author: austinmc
66
ms.topic: how-to
77
ms.date: 11/22/2023
8+
9+
10+
#Customer intent: [AI]As a developer, I want to create and deploy a custom data connector for a cloud-based security information and event management (SIEM) system so that I can ingest and monitor data from various sources without writing code.
11+
812
---
913
# Create a legacy codeless connector for Microsoft Sentinel
1014

0 commit comments

Comments
 (0)