UiPath Documentation
activities
latest
false

Integration Service activities

Last updated May 22, 2026

Microsoft Sentinel Threat Intelligence how-to guides

This page includes guides and resources that can help you learn how to create automations using Microsoft Sentinel Threat Intelligence activities.

Workflow examples

End-to-end automation solutions that showcase how Microsoft Sentinel Threat Intelligence activities integrate into security operations workflows.

Workflow exampleDescriptionActivities
SOAR – File Threat Detection and ResponseEnd-to-end SOAR solution that scans supplier files from email, OneDrive, and SharePoint using Azure Defender and AI Agent, then automatically quarantines threats and triggers full security response.Create New Indicator

Studio Web templates

Reusable Studio Web templates that combine Microsoft Sentinel Threat Intelligence with file scanning and incident response. Each template accepts a file from a different source, uploads it for malware analysis, and uses Threat Intelligence activities to enrich the findings before supporting response in Sentinel.

TemplateFile sourceDescriptionActivities
SOAR Threat Analysis – Scan Local FilesLocal file systemUpload a local file to Azure Blob Storage, trigger malware scanning with Microsoft Defender for Cloud, enrich findings with Microsoft Sentinel Threat Intelligence, and support incident response in Microsoft Azure Sentinel.Create New Indicator
SOAR Threat Analysis – Scan Files from Google DriveGoogle DriveRetrieve files from Google Drive, upload them to Azure Blob Storage, trigger malware scanning with Microsoft Defender for Cloud, enrich findings with Microsoft Sentinel Threat Intelligence, and support incident response in Microsoft Azure Sentinel.Create New Indicator
SOAR Threat Analysis – Scan Files from Gmail AttachmentsGmailDownload Gmail attachments, upload them to Azure Blob Storage, trigger malware scanning with Microsoft Defender for Cloud, enrich findings with Microsoft Sentinel Threat Intelligence, and support incident response in Microsoft Azure Sentinel.Create New Indicator
SOAR Threat Analysis – Scan Files from OneDriveMicrosoft OneDriveRetrieve files from OneDrive, upload them to Azure Blob Storage, trigger malware scanning with Microsoft Defender for Cloud, enrich findings with Microsoft Sentinel Threat Intelligence, and support incident response in Microsoft Azure Sentinel.Create New Indicator
SOAR Threat Analysis – Scan Files from Outlook AttachmentsMicrosoft OutlookDownload Outlook email attachments, upload them to Azure Blob Storage, trigger malware scanning with Microsoft Defender for Cloud, enrich findings with Microsoft Sentinel Threat Intelligence, and support incident response in Microsoft Azure Sentinel.Create New Indicator
  • Workflow examples
  • Studio Web templates

Was this page helpful?

Connect

Need help? Support

Want to learn? UiPath Academy

Have questions? UiPath Forum

Stay updated