Key Features
- Expert-authored rule library organized by data source and MITRE ATT&CK mapping
- Toggle-based activation — enable or disable rules with a click
- CalVer versioning with auto-update capability
- Multi-workspace deployment — push rules to multiple Sentinel workspaces
- No KQL required for basic operations
Requirements
XDR + SIEM module deployed (CMS is not available with XDR-only)
Content Admin or Admin workspace role
Getting Started
- Navigate to the Content Management System from the main navigation
- Browse the rule library by data source or MITRE technique
- Toggle rules on to deploy them to your connected Sentinel workspace
- Monitor rule performance through incident correlation