SIEM & Log Sources
On the roadmapAI incident investigation for Microsoft Sentinel
Cloud-native SIEM and SOAR on Azure.
Visit Microsoft Sentinel ↗How Jutsu works with Microsoft Sentinel
Sync Microsoft Sentinel incidents into Jutsu so agents investigate, enrich, and recommend response, bidirectionally.
What you can do
- Two-way incident sync with Sentinel
- Automated enrichment and root-cause analysis
- Status and verdict written back to Sentinel
How it will connect
Connect in minutes
Authenticate with your existing credentials: no agents to deploy, no data to migrate.
Jutsu investigates
AI SOC agents triage, enrich, and correlate every signal automatically, around the clock.
Act with confidence
Get analyst-grade verdicts and one-click response, with humans always in control.
What the Microsoft Sentinel connector will do
The Sentinel connector is on Jutsu's roadmap and isn't available yet. It's designed as a two-way incident sync:
Incidents in. Microsoft Sentinel incidents are synced into Jutsu as they're created.
Investigation. AI agents enrich each incident and run root-cause analysis to work out what happened.
Results out. Status and verdict are written back to the Sentinel incident, so the record in Azure stays current.
How Jutsu would investigate a Sentinel incident
Synced incidents would go through the same pipeline Jutsu runs on every source today.
- 1
Enrich. Every IP, hash, and domain is checked against nine threat-intel providers, plus your asset inventory and identity data.
- 2
Score. Jutsu assigns a 0–100 risk score, a verdict, and a confidence level, and maps the activity to MITRE ATT&CK techniques.
- 3
Correlate. Related alerts from Sentinel and your other sources are grouped into one incident with a full attack timeline.
- 4
Decide. Benign activity closes, confident detections can run a response playbook, and uncertain ones become cases for your analysts.
Response on Azure today
AgentSOAR, Jutsu's built-in response engine, already runs actions against Microsoft Azure, AWS, and Google Cloud, such as blocking an attacker's IP. Every run is logged and can be reverted from the Containment page.
Microsoft Sentinel integration FAQ
Subscribe to our newsletter
Get the latest security tips, product updates, and news delivered to your inbox.