Events
May 19, 6 PM - May 23, 12 AM
Calling all developers, creators, and AI innovators to join us in Seattle @Microsoft Build May 19-22.
Register todayThis browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Microsoft Sentinel gives you a few ways to use threat intelligence feeds to enhance your security analysts' ability to detect and prioritize known threats:
Tip
If you have multiple workspaces in the same tenant, such as for Managed Security Service Providers (MSSPs), it might be more cost effective to connect threat indicators only to the centralized workspace.
When you have the same set of threat indicators imported into each separate workspace, you can run cross-workspace queries to aggregate threat indicators across your workspaces. Correlate them within your MSSP incident detection, investigation, and hunting experience.
To connect to TAXII threat intelligence feeds, follow the instructions to connect Microsoft Sentinel to STIX/TAXII threat intelligence feeds, together with the data supplied by each vendor. You might need to contact the vendor directly to obtain the necessary data to use with the connector.
One component of Cyware's TIP, CTIX, is to make intel actionable with a TAXII feed for your security information and event management. For Microsoft Sentinel, follow the instructions here:
To connect to TIP feeds, see Connect threat intelligence platforms to Microsoft Sentinel. See the following solutions to learn what other information is needed.
Besides being used to import threat indicators, threat intelligence feeds can also serve as a source to enrich the information in your incidents and provide more context to your investigations. The following feeds serve this purpose and provide Logic Apps playbooks to use in your automated incident response. Find these enrichment sources in the Content hub.
For more information about how to find and manage the solutions, see Discover and deploy out-of-the-box content.
Enrich-Sentinel-Incident-HYAS-Insight-
.RecordedFuture_
.Get-VTURL
.In this article, you learned how to connect your threat intelligence provider to Microsoft Sentinel. To learn more about Microsoft Sentinel, see the following articles:
Events
May 19, 6 PM - May 23, 12 AM
Calling all developers, creators, and AI innovators to join us in Seattle @Microsoft Build May 19-22.
Register today