Evidence tier Source Confirmed · 8 captures on record
What the publisher says
As described on Microsoft Marketplace.
Data Leak Agent investigates a
user-provided incident to determine whether it indicates data leak, data
Show the rest of the publisher’s description (43 more lines)
exfiltration, or related suspicious data exposure activity. The agent
automatically correlates evidence across Microsoft Sentinel, Microsoft Defender
XDR, and Microsoft Purview to produce a single, evidence-based assessment.
It retrieves incident context,
related entities, and supporting telemetry from both Sentinel and Defender XDR,
then enriches the investigation with Purview insights such as DLP alerts, data
risk summaries, and user risk activity within the selected lookback window. The
result is a structured investigation report that helps analysts quickly
understand whether the incident is likely associated with data leakage or
exfiltration, what evidence supports that conclusion, and what follow-up
actions are recommended.
This agent is designed to:
- Automatically investigate the incident across
both Microsoft Sentinel and Microsoft Defender XDR
- Correlate incident-related users, devices,
files, alerts, and activities
- Enrich the investigation with Microsoft Purview
risk and DLP signals
- Distinguish between confirmed indicators,
suspicious signals, benign activity, and inconclusive findings
- Deliver a clear, investigation-ready summary
with confidence level, supporting evidence, gaps, and recommended next steps
Typical use cases include
- Investigating possible data exfiltration
incidents
- Assessing whether suspicious user activity led
to sensitive data exposure
- Triaging DLP-related incidents with
cross-platform context
- Supporting analysts during data security
incident response and validation
Estimated Security Compute Unit (SCU) consumption:
Actual consumption may vary depending on incident complexity, number of related
entities, amount of telemetry, lookback period, and available integrations.
- Small environments: ~1.2 SCUs per
investigation
- Medium environments: ~1.8 to 2.5 SCUs
per investigation
- Enterprise environments: ~2.8 to 4.5
SCUs per investigation
These estimates assume the agent is enriching incidents
across Sentinel, Defender XDR, and Purview, and that environments with more
entities, alerts, and historical activity will naturally require more compute.
Preview
3 imagesAgent build and provenance
Sign in to see the provenance.
The evidence, the layer-by-layer tracing, the risk basis, and the cross-marketplace links are open to signed-in accounts.
Sign inCompliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment · as of 2026-08-29
Plans and pricing as listed
1 listedSources
Publisher resources
3 linksEvidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.




