ThreatIntelObjects

ThreatIntelObjects Schema #

Table description #

TableSection TableType TableSectionName Description
Usx Regular Microsoft Sentinel Threat Intelligence Generic STIX Object Table.

Table retention #

HotDays ColdDays TotalInteractiveDays
14 16 30

Schema #

Name Description Type
_BilledSize Double
_IsBillable String
_ResourceId A unique identifier for the resource that the record is associated with String
_SubscriptionId A unique identifier for the subscription that the record is associated with String
AdditionalFields The type specifc fields that Sentinel adds. Contains the TLPLevel: white, green, amber, or red. Object
AzureTenantId The tenant that submitted the STIX object. String
Data All object properties, formatted according to STIX specification (https://docs.oasis-open.org/cti/stix/v2.1/os/stix-v2.1-os.pdf). Object
Id A value that uniquely identifies the STIX object. This value is usable with Sentinel APIs. String
IsDeleted A value that indicates whether the data was deleted from Sentinel or not. Boolean
LastUpdateMethod The component that last updated the record. String
SourceSystem The name of the source. String
StixType The name of this STIX Object. String
TenantId Unique identifier of the tenant into which the data connector ingests data. String
TimeGenerated The time of STIX object ingestion. DateTime
Type The name of the table String
WorkspaceId The workspace that submitted the STIX object. String

Schema changes #

Date Action
2026-01-02 Column Source removed
2024-10-18 Table added to tracking