Skip to main content
Ingest Reyhford ICS/OT indicators into Microsoft Sentinel using the built-in TAXII data connector.

Prerequisites

  • Microsoft Sentinel workspace with Threat Intelligence permissions
  • API key from reyhford.com/portal

Add TAXII connector

  1. In Azure Portal, open Microsoft Sentinel → Configuration → Data connectors.
  2. Search for Threat Intelligence - TAXII and select Open connector page.
  3. Click Add connector and configure:
  1. Save and verify the connector shows Connected.

Workbook and hunting

Imported indicators appear under Threat intelligence → All indicators. Use KQL to hunt ICS-specific activity:

REST API alternative

For custom Logic Apps or Azure Functions, use the Indicators Search API with WorkOS JWT authentication.