🖥️
Endpoint Telemetry
Windows / Linux / macOS agents via MDE & AMA
MDESysmonAMA
📖 Deploy MDE
🌩️
Cloud Services
Azure, AWS, GCP logs via Diagnostic Settings & connectors
M365Azure AD
📖 Connect Cloud
🔥
Network Security
Firewall, IDS/IPS, NSG flow logs, NetFlow/IPFIX
CEFSyslog
📖 CEF / Syslog Ref
📱
SaaS & Apps
Salesforce, ServiceNow, GitHub, custom REST APIs
RESTOAuth
📖 SaaS Connectors
🌍
Threat Intel
MISP, TAXII/STIX feeds, MS Threat Intel Platform
STIXTAXII
📖 Threat Intel